Senior Associate, Security GRC

Gemini

Gemini

Posted on Jul 27, 2023

Empower the Individual Through Crypto

Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.

Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we want to help you buy, sell, and store your bitcoin and cryptocurrency. Crypto is not just a technology, it's a movement.

At Gemini, our mission is to empower the individual and that includes giving our employees flexibility of choice — our Office Optional Policy allows employees to choose to work from one of our physical locations or from home.

The Department: Information Security

The Role: Senior Associate, Security GRC

Gemini has an exciting opportunity for a Security GRC Governance Senior Associate. The company seeks to identify a highly proactive and technical individual with proven talent in security process development, policy creation, security standard navigation, risk and control framework mapping capabilities, and strategic evidence collection/curation insight. The successful candidate will work alongside the rest of the GRC team to ensure policies, procedures, and guidelines align with regulatory requirements and security frameworks; assess internal and external risks; and ensure compliance with security regulations. This individual will work with other internal teams to align security goals and objectives with business stakeholders.

Responsibilities:

  • Establish and maintain data governance frameworks and best practices for ensuring data quality, integrity, and security.
  • Advise Gemini’s security team and leadership on additional security governance measures.
  • Serve as a primary point of contact for security issues that require governance remediation.
  • Collaborate with cross-functional teams to identify and document data requirements, standards, and processes.
  • Support Gemini’s response to Regulators, Auditors, Client inquiries, and Due Diligence Questionnaires.
  • Develop and maintain Gemini’s security policies, standards and guidelines.
  • Design and manage a comprehensive data taxonomy for classifying and organizing data assets effectively.
  • Create and maintain a centralized data dictionary with detailed definitions, metadata, and lineage information for critical data elements.
  • Implement data governance tools and technologies to support data profiling, lineage tracking, and data quality monitoring.
  • Conduct data impact assessments and risk assessments to identify and mitigate potential data privacy or security vulnerabilities.
  • Collaborate with cross functional teams and data owners to establish and enforce data governance roles and responsibilities.
  • Develop and implement data governance policies and procedures to ensure compliance with privacy regulations (e.g., GDPR, CCPA).
  • Stay up to date with evolving data privacy laws and regulations, assess their impact on the organization, and provide guidance on compliance measures.
  • Develop and deliver training programs to educate employees on data governance principles, policies, and procedures.
  • Develop and maintain data governance dashboards and metrics to measure data quality, compliance, and governance effectiveness.
  • Utilize database SQL and associated programming languages (e.g., Python, R) proficiently for data querying, manipulation, and analysis.

Minimum Qualifications:

  • BA/BS degree or equivalent practical experience.
  • Five years of experience in the cyber security field developing and/or updating cyber security related documentation, policies, procedures and standards.
  • Familiarity with Data privacy regulations such as GDPR, CCPA etc.
  • Familiarity with SQL, Python or any other programming language
  • Strong analytical and creative problem solving skills.
  • Strong interpersonal skills to interact with customers, senior level personnel, auditors, and team members.
  • Strong organization skills to prioritize work and balance complex projects.
  • Ability to work independently and as part of a broader team.

Preferred Qualifications:

  • Experience with automation of GRC initiatives and priorities.
  • Understanding of endpoint security, networking, and application-layer gateway technologies.
  • Operational knowledge of systems, databases, and network security best practices.
  • Experience with IDS, DLP, and SIEM tooling.
  • Experience with cloud-native environments.
It Pays to Work Here
The compensation & benefits package for this role includes:
  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Annual Learning & Development stipend
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $95,000 - $133,000 in New York City, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.

#LI-MW1