Director, Risk Management

riot-platforms-careers

United States

On-site

USD 150,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Bonus and equity grant
Equity incentive programs
401(k) match
Health coverage

Job summary

Riot Platforms seeks a Director of Risk Management to own the external audit program, risk IQ, and certification readiness across SOC, ISO, and SOX. You will lead audits, maintain the enterprise risk register, and drive remediation with cross-functional teams.

You will partner with the CFO and Internal Audit to align controls, testing, and governance. This role requires hands-on leadership in a fast-paced, critical infrastructure environment with broad accountability.

Qualifications

  • 8–12+ years of progressive GRC, IT audit, or enterprise risk management experience with direct ownership of SOC 1 and/or SOC 2 Type II audits.
  • ISO 27001 Lead Implementer certification is required and must be demonstrated in audit execution and certification tracks.
  • Working knowledge of SOX ITGC requirements at a publicly traded company, with coordination with Internal Audit.
  • Proven experience building or operating an enterprise risk register, risk taxonomy, and KPI/KRI reporting.
  • Experience owning external auditor relationships, managing timelines, requests, walkthroughs, and remediation drafting.

Responsibilities

  • Own end-to-end execution of SOC 1 and SOC 2 Type II audits: scoping, walkthroughs, evidence collection, auditor liaison, management response drafting, and remediation tracking.
  • Lead the ISO 27001:2022 audit readiness and certification audit track, coordinating evidence and governance with the Sr. Director, GRC.
  • Coordinate SOX ITGC with Internal Audit, establishing a shared control inventory and testing methodologies.
  • Build and maintain the Riot enterprise risk register with taxonomy, quarterly risk updates, and risk ranking.
  • Develop and maintain the KRI/KPI framework for executive and Board-level risk reporting.
  • Run the POA&M program, assign ownership, track remediation, and report status on cadence.
  • Design repeatable evidence pipelines to achieve year-round audit readiness.

Skills

GRC experience
SOC 1 & SOC 2 audits
Audit management
Executive communication
Risk assessment
POA&M remediation

Education

ISO 27001 Lead Implementer

Job description

About Riot Platforms

Riot’s (NASDAQ: RIOT) vision is to be the world’s most trusted platform for powering and buildingdigital infrastructure.Riot’s mission is to empower the future of digital infrastructure by positivelyimpactingthe sectors, networks, and communities that we touch. We believe that the combination of an innovative spirit and strong community partnership allows us to achieve best-in-class execution and create successful outcomes.

Who we are

At Riot,we’rebuilding the future of digital infrastructure. Our team members have unparalleled opportunities to work on groundbreaking initiatives. Through technical excellence and strategic execution, Riot has positioned itself as a leader in the industry driving advancements that continue to set new benchmarks in digital infrastructure.

Weare trailblazers. Problem solvers. People who thrive in fast pacedenvironments,communicate clearly, and bring relentless focus to efficiency and execution.

About the role

The Director, Risk Management owns Riot's most time-critical GRC pillar. This role steps directly into that execution environment — timelines do not pause for onboarding.

This pillar is intentionally scoped: Risk Management owns the external auditor relationship, the evidence pipeline, the enterprise risk register, the POA&M lifecycle, and the ISO 27001 audit readiness and certification audit track. You own risk identification, risk quantification, audit execution, and the remediation lifecycle that closes gaps across all pillars.

You will report to the Senior Director, GRC and serve as Riot's primary relationship owner with external auditors across SOC 1, SOC 2, and ISO 27001. You will partner directly with the CFO on SOX obligations and with Internal Audit on shared ITGC methodology. In critical operations, you will engage mining site and data center leadership to ensure operational risks are captured, assessed, and reflected in the enterprise risk register.

What you'll do
  • Own end-to-end execution of SOC 1 and SOC 2 Type II audits: scoping, control walkthroughs, evidence collection, auditor liaison, management response drafting, and remediation tracking — you are the primary point of contact for all external audit activity.
  • Lead the ISO 27001:2022 audit readiness and certification audit track — coordinating evidence, managing the certification audit relationship, and driving the program to on-schedule certification under the governance of the Sr. Director, GRC.
  • Serve as the primary liaison to Internal Audit for SOX ITGC coordination — establishing a shared control inventory, aligning testing methodologies, dividing walkthroughs to eliminate duplication, and maintaining a joint remediation cadence.
  • Build and operate the Riot enterprise risk register: define the risk taxonomy, conduct risk assessments across all business units including mining and data center operations, tier risks by likelihood and impact, and maintain a living register updated no less than quarterly.
  • Develop and maintain the KRI/KPI framework for executive and Board-level risk reporting — translating risk register outputs into leading indicators that give leadership actionable visibility into Riot's risk posture.
  • Run the POA&M (Plan of Action & Milestones) program: intake all audit findings and control gaps across all GRC pillars, assign ownership, track remediation progress, escal…and report status to the Sr. Director on a defined cadence.
  • Build continuous audit-readiness infrastructure: design repeatable evidence pipelines, drive evidence collection automation where possible, and eliminate point-in-time audit scrambles by maintaining a year-round audit-ready posture.
What you'll bring
  • 8–12+ years of progressive GRC, IT audit, or enterprise risk management experience, with direct, hands‑on ownership of SOC 1 and/or SOC 2 Type II audits — required, not supporting-role exposure.
  • ISO 27001 Lead Implementer certification — required. Must have credentialed implementation experience to own the audit execution and certification track.
  • Working knowledge of SOX ITGC requirements at a publicly traded company, with demonstrated experience coordinating GRC work with an Internal Audit function.
  • Proven experience building or operating an enterprise risk register, risk taxonomy, and KRI/KPI reporting framework for executive audiences.
  • Experience owning the external auditor relationship — managing audit timelines, evidence requests, walkthrough coordination, and management response drafting across multiple concurrent audit programs.
  • Strong POA&M and remediation lifecycle management: tracking, escalating, and closing audit findings across cross‑functional control owners.
  • Familiarity with at least one additional security framework beyond SOC 2 — ISO 27001, NIST CSF, or NIST 800‑53.
  • Excellent written and verbal communication — ability to present risk posture and audit status in executive‑ready formats for Board Audit Committee reporting.
  • Preferred: CISA or CRISC certification; experience in critical infrastructure, data center, energy, or digital asset environments; exposure to OT/ICS risk environments.
Compensation and Benefits
  • Competitive Salary: Base range (commensuratewith experience) + bonus + sign-on equity grant.
  • Long-Term Growth: Eligible toparticipatein Riot’s equity incentive programs and share in the success you help build.
  • 401(k) Retiremen Plan: Incudes a generous company match.
  • Comprehensive Health Coverage: Multiple medical plan options, including 100% company-paيدة plans.
  • Wellness & Lifestyle Perks: Enjoy free gymmemberships; pet insurance, childcare discounts, and more to support your life both in and out of work.

Riot is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, Risk Management
Director, Risk Management

Riot Platforms, Inc. • United States

On-site
USD 180,000 - 280,000
401(k) match
Equity grant
Health coverage
+2
Director, Governance
Director, Governance

riot-platforms-careers • United States

On-site
USD 180,000 - 280,000
Bonus
Equity grant
401(k) match
+4
Technical Program Manager - Standards and Governance
Technical Program Manager - Standards and Governance

riot-platforms-careers • Austin (TX)

On-site
USD 120,000 - 170,000
Equity grant
401(k) match
Health coverage
+3
Director, GRC & Audit Strategy
Director, GRC & Audit Strategy

Riot Platforms, Inc. • United States

On-site
USD 180,000 - 280,000
401(k) match
Equity grant
Health coverage
+2
People Operations Manager, Strategic Initiatives
People Operations Manager, Strategic Initiatives

Riot Platforms, Inc. • Austin (TX)

On-site
USD 90,000 - 150,000
Comprehensive Health Coverage
Gym memberships
Pet insurance
+4
Director, Investor Relations
Director, Investor Relations

Riot Platforms, Inc. • Denver (CO)

On-site
USD 185,000 - 205,000
Free gym memberships
Pet insurance
Childcare discounts
Director, Investor Relations
Director, Investor Relations

Riot Platforms, Inc. • Irvine (CA)

On-site
USD 185,000 - 205,000
401(k) retirement plan
Comprehensive health coverage
Wellness & lifestyle perks
+1
Director, Investor Relations
Director, Investor Relations

Riot Platforms, Inc. • Northern (KY), New York (NY)

Hybrid
USD 185,000 - 205,000
Equity incentive programs
Sign-on equity grant
401(k) retirement plan with company-mc
+2
People Operations Manager, Strategic Initiatives
People Operations Manager, Strategic Initiatives

Riot Platforms • Austin (TX)

On-site
USD 110,000 - 170,000
401(k) matching
Health coverage
Wellness perks
+1
GSOC Supervisor
GSOC Supervisor

Riot Platforms • Corsicana (TX)

On-site
USD 65,000 - 90,000
401(k) with company match
Health coverage
Paid time off
+3