SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ripple is seeking a Senior GRC Program Manager to support the customer security assurance program for Ripple Treasury. This role bridges security, sales, and compliance, serving as a key resource for RFP teams, prospective customers, and existing clients seeking to understand and validate Ripple's security posture.
Key responsibilities include:
• RFP & Security Questionnaire Support: Back up the RFP team by completing and reviewing security questionnaires (SIG, CAIQ, custom formats) on deadline. Maintain a repository of approved, reusable responses to streamline future engagements.
• Customer Engagement: Meet directly with prospective and existing customers to present the Ripple security program, answer due diligence questions, and support security aspects of deal cycles and renewals.
• Security Sales Documentation: Create and maintain security-related sales collateral, including trust center content, certification summaries, control mappings, architecture diagrams, and data-flow references. Ensure all materials remain current and accurately reflect the security program.
• DORA Audit Support: Manage customer-initiated Digital Operational Resilience Act audits by coordinating logistics, gathering evidence, and serving as liaison between customers and internal control owners.
• Evidence & Control Coordination: Partner with Information Security, Engineering, and IT teams to validate questionnaire responses and gather supporting evidence.
• Cross-Functional Collaboration: Work with Information Security, Legal, Sales, and Customer Success to ensure consistent, accurate, and contractually aligned communication of Ripple Treasury's security and compliance posture.
• Continuous Improvement: Identify recurring customer questions and develop standardized responses, FAQs, and enablement materials to reduce manual effort and improve turnaround time.
• Risk Judgment: Recognize customer requests that may introduce security, compliance, or contractual risk and escalate appropriately.
Required qualifications: 5+ years in GRC, customer security assurance, or related security function with hands-on experience responding to customer security questionnaires. Strong grounding in SOC 2, ISO 27001, NIST, and SWIFT frameworks. Familiarity with financial services regulatory frameworks; DORA exposure is a plus. Excellent written and verbal communication skills to translate technical concepts for non-technical audiences. Proven ability to manage multiple concurrent customer engagements and deadlines. Experience with trust center platforms (SafeBase, Vanta), questionnaire automation, and GRC platforms (Drata, LogiGate) preferred. Background with financial services or FinTech customers and knowledge of GDPR, CCPA, and DORA is valued. Relevant certifications (CISA, CISM, CISSP, Security+) are preferred.