Risk & Controls Manager

MetaMask

United States

Remote

USD 150,000 - 206,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

MetaMask in the United States is seeking a results-driven risk and compliance professional to run our internal posture engine, maintain the risk register, evidence, and audit operations. You will ensure ISO 27001 and SOC 2 readiness, coordinate audits, and keep documentation accurate for leadership and customers.

The role requires hands-on experience with risk registers, GRC platforms (Drata or equivalent), stakeholder management, and precise reporting.

Qualifications

  • Hands-on experience running a risk register, control library and audit cycle (ISO 27001 and/or SOC 2).
  • Comfortable with GRC platforms (Drata or equivalent) and turning monitoring into evidence.
  • Proven ability to coordinate audits and customer questionnaires with named control owners.
  • Precise written work; register and Statement of Applicability quality matters.
  • Strong stakeholder management with control owners and auditors.
  • CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification.

Responsibilities

  • Operate the risk register: populate, track treatment, record decisions, follow up owners.
  • Maintain ISMS and security policy library for audit readiness and draft standards when asked.
  • Run Drata as control/evidence system: SoA, framework crosswalk, and automation.
  • Monitor critical controls: health checks, drift flags, and route drift to SOC; keep evidence.
  • Feed threat findings into the register and track current assessments.
  • Coordinate ISO 27001/SOC 2 audits: logistics, readiness, and questionnaires.
  • Coordinate control register for tests: red team, tabletop, pentest; run awareness and alerts.
  • Report residual risk and gaps; keep management view one source of truth.
  • Be accountable for posture engine: register, evidence, and audit ops.
  • Ensure continuous evidence collection in Drata where coverage exists.

Skills

Risk management
Audit coordination
Documentation quality
Stakeholder management
Regulatory knowledge

Education

CISA, ISO 27001 Lead Implementer or Auditor, or equivalent

Tools

Drata

Job description

Please note that we are unable to consider applications from candidates based in France, Italy, or Germany for this role.

Money is moving onto the internet, and the shift has a name: Open Money. This is money that is open, portable, agentic, and owned by you. MetaMask spent the last ten years building it; with 100M+ downloads, users in ~190 countries, and trillions in cumulative transaction volume, it's the most trusted self-custodial financial platform on the internet. Now we're building the operating system for your money: one place to hold, move, grow, and use anything you own. Join a remote-first, global team rebuilding how money works: a problem that touches everyone, every day.

About the role

This role runs the internal posture engine — the risk register, critical control monitoring, evidence, audit operations and GRC tooling. It keeps risk state current so the Lead and the Risk Committee decide from accurate data in the Risk Dashboard and reporting. Drata is the register of record. Named owners close gaps; this role keeps the register, evidence and audit operations current.

Responsibilities
Planning
  • Operate the risk register from the Security Programme threat model: populate, track treatment, record acceptance decisions, follow up owners, and run the exceptions register.
  • Keep the ISMS and security policy library current as part of audit readiness. Draft security standards when commissioned by the Lead.
  • Run Drata as the control and evidence system — Statement of Applicability, framework crosswalk and automation.
Execution
  • Run critical control monitoring: health check-ins, drift flags and Drata automation. Route drift to the SOC. Maintain the evidence file for Lead assessments and independent internal audit.
  • Feed threat-assessment findings into the register and confidence ratings. Track which required assessments are current.
  • Lead audit coordination and preparation: ISO 27001 and SOC 2 logistics, ISMS readiness, team prep, management-review pack, and customer due-diligence questionnaires.
  • Coordinate the control register for external testing (red team, tabletop, pentest). Run security awareness and weekly alerts.
Tracking and evaluating performance
  • Track residual risk, exceptions and gap-closure against appetite. Exceptions expire and are reported; the underlying requirement stays in force.
  • Report register state and evidence health so the Lead and Risk Committee work from one view.
Achieving overall defined performance
  • Be accountable for a current, defensible posture engine — register, evidence and audit operations.
  • Ensure Drata collects evidence continuously, with automated evidence where coverage exists.
Qualifications
  • Hands-on experience running a risk register, control library and audit cycle (ISO 27001 and/or SOC 2).
  • Comfortable with GRC platforms (Drata or equivalent) and turning monitoring into evidence.
  • Proven ability to coordinate audits and customer questionnaires with named control owners.
  • Precise written work; register and Statement of Applicability quality matters.
  • Strong stakeholder management with control owners and auditors.
  • CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification.

The salary range listed for this role applies to US-based candidates only. Compensation for candidates based outside the US (including Canada, EMEA, and LATAM) will be determined based on location, experience, and skills during the interview process, and may differ from the listed US range.

US pay range (not including bonus, equity or other benefits)

$150,000 — $206,000 USD

In the rapidly evolving Web3 space, we believe that everyone is a builder. This expansive paradigm requires a range of backgrounds, talents, skills, and experiences to influence and shape the future. At MetaMask, this diversity fuels our ability to shift control and redefine the realm of possibility. We are committed to ensuring that our technology empowers people and communities through decentralized technologies. We welcome the range of perspectives and differences and celebrate them. We're excited to see how your unique skills as a builder can contribute to our vision, drive innovation, and help us shape a more inclusive Web3.

MetaMask is an equal opportunity employer. All employment decisions are made without regard to race, color, national origin, ancestry, sex, gender, gender identity or expression, sexual orientation, age, genetic information, religion, disability, medical condition, pregnancy, marital status, family status, veteran status, or any other characteristic protected by law.

MetaMask is aware of fraudulent recruitment practices and we encourage all applicants to review our best practices to protect yourself, which can be found on our page.

MetaMask may use artificial intelligence (AI) tools to support parts of our recruitment process, such as reviewing applications, screening resumes, or conducting initial candidate assessments. These tools are designed to assist our recruiting team and improve efficiency — they do not replace human judgment. A human recruiter or hiring manager reviews every candidate, and all final hiring decisions are made by people, not AI.

It is a requirement of employment in this position that applicants may be required to submit to background and identity verification checks, including but not limited to employment, education, criminal record checks, and other such checks as determined necessary by the company.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior HRIS Administrator II
Senior HRIS Administrator II

MetaMask • United States

Remote
USD 122,000 - 183,000
Director of Technical Accounting
Director of Technical Accounting

MetaMask • Northern (KY)

Hybrid
USD 182,000 - 262,000
Product Marketing Lead - Trade
Product Marketing Lead - Trade

MetaMask • United States

Remote
USD 146,000 - 220,000
Senior Design Engineer - MetaMask
Senior Design Engineer - MetaMask

MetaMask • United States

Remote
USD 149,000 - 210,000
Lead Product Designer
Lead Product Designer

MetaMask • United States

Remote
USD 125,000 - 195,000
Remote-first team
Global team
risk & controls manager в информационной безопасности
risk & controls manager в информационной безопасности

HireHi • United States

On-site
USD 150,000 - 206,000
Staff UX Motion Designer
Staff UX Motion Designer

MetaMask • United States

Remote
USD 146,000 - 218,000
Exam & Audit — Integrity Program Manager
Exam & Audit — Integrity Program Manager

Meta • Seattle (WA)

On-site
USD 122,000 - 180,000
Program Manager, Privacy Risk Assessment
Program Manager, Privacy Risk Assessment

Meta • Menlo Park (CA)

On-site
USD 122,000 - 180,000
Bonus
Equity
Benefits
Product Risk Program Manager, Evidencing and Monitoring
Product Risk Program Manager, Evidencing and Monitoring

Meta • Washington

On-site
USD 153,000 - 209,000