Remote GRC & Risk Controls Lead (ISO 27001/SOC 2)

MetaMask

United States

Remote

USD 150,000 - 206,000

Full time

10 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

MetaMask in the United States is seeking a results-driven risk and compliance professional to run our internal posture engine, maintain the risk register, evidence, and audit operations. You will ensure ISO 27001 and SOC 2 readiness, coordinate audits, and keep documentation accurate for leadership and customers.

The role requires hands-on experience with risk registers, GRC platforms (Drata or equivalent), stakeholder management, and precise reporting.

Qualifications

  • Hands-on experience running a risk register, control library and audit cycle (ISO 27001 and/or SOC 2).
  • Comfortable with GRC platforms (Drata or equivalent) and turning monitoring into evidence.
  • Proven ability to coordinate audits and customer questionnaires with named control owners.
  • Precise written work; register and Statement of Applicability quality matters.
  • Strong stakeholder management with control owners and auditors.
  • CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification.

Responsibilities

  • Operate the risk register: populate, track treatment, record decisions, follow up owners.
  • Maintain ISMS and security policy library for audit readiness and draft standards when asked.
  • Run Drata as control/evidence system: SoA, framework crosswalk, and automation.
  • Monitor critical controls: health checks, drift flags, and route drift to SOC; keep evidence.
  • Feed threat findings into the register and track current assessments.
  • Coordinate ISO 27001/SOC 2 audits: logistics, readiness, and questionnaires.
  • Coordinate control register for tests: red team, tabletop, pentest; run awareness and alerts.
  • Report residual risk and gaps; keep management view one source of truth.
  • Be accountable for posture engine: register, evidence, and audit ops.
  • Ensure continuous evidence collection in Drata where coverage exists.

Skills

Risk management
Audit coordination
Documentation quality
Stakeholder management
Regulatory knowledge

Education

CISA, ISO 27001 Lead Implementer or Auditor, or equivalent

Tools

Drata

Job description

MetaMask in the United States is seeking a results-driven risk and compliance professional to run our internal posture engine, maintain the risk register, evidence, and audit operations. You will ensure ISO 27001 and SOC 2 readiness, coordinate audits, and keep documentation accurate for leadership and customers.

The role requires hands-on experience with risk registers, GRC platforms (Drata or equivalent), stakeholder management, and precise reporting.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Risk & Controls Manager (ISO27001/SOC2)
Senior Risk & Controls Manager (ISO27001/SOC2)

HireHi • United States

Remote
USD 150,000 - 206,000
Remote GRC Specialist - Build ISO 27001 & SOC 2 Compliance
Remote GRC Specialist - Build ISO 27001 & SOC 2 Compliance

United States Digital Space LLC • United States

Remote
USD 110,000 - 165,000
Remote work: 100% remote
Competitive local salary
Equity
+8
GRC Lead for AI Security: SOC 2 & ISO 27001
GRC Lead for AI Security: SOC 2 & ISO 27001

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
GRC Automation Lead: ISO/GDPR Compliance (Remote)
GRC Automation Lead: ISO/GDPR Compliance (Remote)

United States Digital Space LLC • United States

Remote
USD 120,000 - 180,000
Remote work
Equity
Mentorship
+5
GRC Security compliance leader
GRC Security compliance leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Remote GRC Specialist: ISO 27001, SOC 2 & GDPR
Remote GRC Specialist: ISO 27001, SOC 2 & GDPR

Secfix • United States

Remote
USD 120,000 - 180,000
Annual development budget
Home office budget
Co-working spaces
+2
risk & controls manager в информационной безопасности
risk & controls manager в информационной безопасности

HireHi • United States

On-site
USD 150,000 - 206,000
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1
Remote Infosec & GRC Leader - ISO27001 & Risk
Remote Infosec & GRC Leader - ISO27001 & Risk

Avantdigitalnow • San Francisco (CA)

Remote
USD 95,000 - 130,000
Remote GRC Analyst — SOC 2 & ISO 27001 Expert
Remote GRC Analyst — SOC 2 & ISO 27001 Expert

Parallels • United States

Remote
USD 120,000 - 130,000
Fully remote