Director, Governance & Policy (ISO 27001 & GRC)

riot-platforms-careers

United States

On-site

USD 180,000 - 280,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Bonus
Equity grant
401(k) match
Health coverage
Gym membership
Pet insurance
Childcare discounts

Job summary

Riot Platforms is seeking a Director, Governance to build and scale a comprehensive GRC program across policy, compliance, and vendor risk. You will own the ISO 27001:2022 documentation framework, drive attestation programs, and shepherd governance through executive sponsorship.

You will coordinate with Legal, Procurement, HR, and Operations to map policies to SOC 2, ISO 27001, and NIST CSF, while enabling proactive risk management across critical infrastructure and digital assets.

Qualifications

  • 8–12+ years of progressive GRC, policy management, regulatory affairs, or governance program experience at a publicly traded or highly regulated company.
  • ISO 27001 Lead Implementer certification — required.
  • Demonstrated experience building a policy library from a minimal baseline — governance model design, framework mapping, attestation program rollout, and cross-functional adoption.
  • Experience standing up or operating a Contracts Management program with Legal co-ownership — contract risk review, DPA requirements, and GRC-Legal governance models.
  • Working knowledge of TPRM frameworks and vendor risk program design — tiering models, due diligence questionnaires, and ongoing monitoring processes.
  • Proven regulatory horizon scanning capability across critical infrastructure, digital assets, and data privacy (CISA, FinCEN, state privacy laws, DORA, NIS2 familiarity).
  • Experience mapping a policy library to multiple frameworks simultaneously (SOC 2, ISO 27001, NIST CSF) to support a unified audit and control program.
  • Strong cross-functional communication and influence: ability to drive policy adoption and contracts governance across Legal, Procurement, HR, and Operations without direct authority.
  • Preferred: CISM, CGEIT, CRISC, or CIPP/US certification; experience in critical infrastructure, energy, data center, or digital asset environments.

Responsibilities

  • Build and own the ISO 27001:2022 documentation framework: identify and produce all mandatory policies, procedures, and records required for certification, map them to Annex A controls, and drive adoption through executive sponsorship and attestation programs — this is the Year 1 priority with a contractually fixed delivery timeline.
  • Build and operate the Riot policy and standards library from near-zero baseline: establish the governance model (drafting, review routing, approval gates, versioning, renewal cadences), and extend scope beyond ISO 27001 to cover SOC 2, SOX, and enterprise policy requirements.
  • Own the regulatory horizon scanning program: monitor developments across critical infrastructure, digital assets, data privacy, and financial services; translate regulatory signals into GRC program actions; and deliver regular briefings to the Sr. Director and executive leadership.
  • Stand up the Contracts Management program in co-ownership with Legal: design the intake-to-repository workflow, establish GRC risk flagging criteria (data processing, liability, security, regulatory), and implement the Legal sign-off gate — Legal approves, GRC operates.
  • Own the Third-Party Risk Management (TPRM) and vendor risk program: build the vendor tiering model, define due diligence requirements by tier, partner with Procurement on intake integration, and establish ongoing monitoring cadences for critical and colocation vendors.
  • Manage the GRC framework lifecycle: maintain Riot's mapping of policies and controls to SOC 2 Trust Services Criteria, ISO 27001, NIST CSF, and applicable regulatory frameworks — keeping the library current as the regulatory and audit environment evolves.
  • Engage critical operations to ensure site-level operational policies, physical security standards, and environmental procedures are captured within the governance framework and aligned to enterprise GRC standards.

Job description

Riot Platforms is seeking a Director, Governance to build and scale a comprehensive GRC program across policy, compliance, and vendor risk. You will own the ISO 27001:2022 documentation framework, drive attestation programs, and shepherd governance through executive sponsorship.

You will coordinate with Legal, Procurement, HR, and Operations to map policies to SOC 2, ISO 27001, and NIST CSF, while enabling proactive risk management across critical infrastructure and digital assets.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Governance
Director, Governance

riot-platforms-careers • United States

On-site
USD 180,000 - 280,000
Bonus
Equity grant
401(k) match
+4
Director, GRC & Audit Strategy
Director, GRC & Audit Strategy

Riot Platforms, Inc. • United States

On-site
USD 180,000 - 280,000
401(k) match
Equity grant
Health coverage
+2
Director, Risk & Compliance — SOC/ISO Readiness
Director, Risk & Compliance — SOC/ISO Readiness

riot-platforms-careers • United States

On-site
USD 150,000 - 190,000
Bonus and equity grant
Equity incentive programs
401(k) match
+1
Director, Risk Management
Director, Risk Management

Riot Platforms, Inc. • United States

On-site
USD 180,000 - 280,000
401(k) match
Equity grant
Health coverage
+2
Director, Risk Management
Director, Risk Management

riot-platforms-careers • United States

On-site
USD 150,000 - 190,000
Bonus and equity grant
Equity incentive programs
401(k) match
+1
Governance & Audit Readiness Technical PM
Governance & Audit Readiness Technical PM

Riot Platforms, Inc. • Austin (TX)

On-site
USD 120,000 - 180,000
Bonus
Sign-on equity grant
401(k) matching
+4
Director of GRC, Risk & Compliance Strategy
Director of GRC, Risk & Compliance Strategy

Wilco • United States

On-site
USD 180,000 - 280,000
Technical Program Manager, Governance & Audit Readiness
Technical Program Manager, Governance & Audit Readiness

riot-platforms-careers • Austin (TX)

On-site
USD 120,000 - 170,000
Equity grant
401(k) match
Health coverage
+3
Technical Program Manager - Standards and Governance
Technical Program Manager - Standards and Governance

riot-platforms-careers • Austin (TX)

On-site
USD 120,000 - 170,000
Equity grant
401(k) match
Health coverage
+3
Security Governance Lead - SOC 2, ISO 27001, AI
Security Governance Lead - SOC 2, ISO 27001, AI

Field Nation • Northern (KY)

Hybrid
USD 120,000 - 150,000
Unlimited paid time off
Annual vacation bonus
401K