SlipstreamJobsFresh Startup & VC-Backed Jobs

Risk & Controls Manager

Consensys - Remote - Remote - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 150,000 - 206,000 / annual

Consensys/MetaMask is seeking a Risk & Controls Manager to operate the internal risk and compliance posture engine. This role is responsible for maintaining the risk register, critical control monitoring, evidence management, audit operations, and GRC tooling to ensure the Risk Committee and leadership have accurate, current data for decision-making. Key responsibilities include: **Planning & Setup** - Operate and maintain the risk register based on the Security Programme threat model, including population, treatment tracking, acceptance decisions, and exception management - Keep the Information Security Management System (ISMS) and security policy library current as part of audit readiness - Manage Drata as the control and evidence system, including Statement of Applicability and framework crosswalks **Execution & Monitoring** - Run critical control monitoring including health check-ins, drift detection, and Drata automation; route drift findings to the SOC - Maintain evidence files for Lead assessments and independent internal audit - Feed threat-assessment findings into the risk register and track confidence ratings - Lead audit coordination and preparation for ISO 27001 and SOC 2 certifications, including ISMS readiness, team preparation, and customer due-diligence questionnaires - Coordinate the control register for external testing (red team, tabletop, penetration testing) - Run security awareness programs and weekly alerts **Performance Tracking** - Track residual risk, exceptions, and gap closure against risk appetite - Report register state and evidence health to leadership and the Risk Committee - Ensure the posture engine (register, evidence, and audit operations) remains current and defensible - Ensure Drata collects evidence continuously with automated evidence where possible The role is fully remote and open to candidates in the US, LATAM, and EMEA (excluding France, Italy, and Germany). This is an individual contributor role that manages processes and systems rather than people, reporting to the Risk Lead. **Requirements** - Hands-on experience running a risk register, control library, and audit cycle (ISO 27001 and/or SOC 2) - Comfortable with GRC platforms (Drata or equivalent) and converting monitoring into evidence - Proven ability to coordinate audits and customer questionnaires with named control owners - Precise written work; register and Statement of Applicability quality is critical - Strong stakeholder management skills with control owners and auditors - CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification

Similar roles