Senior Security Engineer (GRC)



United States · Remote
Posted on Thursday, November 9, 2023

Empower the Individual Through Crypto

Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.

Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we want to help you buy, sell, and store your bitcoin and cryptocurrency. Crypto is not just a technology, it's a movement.

At Gemini, our mission is to empower the individual and that includes giving our employees flexibility of choice — our Office Optional Policy allows employees to choose to work from one of our physical locations or from home.

The Department: Information Security

The Role: Senior Security Engineer

Gemini has an exciting opportunity for a Senior Security Engineer, GRC. The company seeks to identify a highly proactive and technical individual with proven talent in programming and data analytics as a key requirement for this security engineering role, which involves crafting robust security automations, formulating metrics, and ensuring compliance with privacy regulations. The successful candidate will work alongside the rest of the GRC team to ensure policies, procedures, and guidelines align with regulatory requirements and security frameworks; assess internal and external risks; and ensure compliance with security regulations. This individual will work with other internal teams to align security goals and objectives with business stakeholders.


  • Advise Gemini’s security team and leadership on additional security governance measures.
  • Serve as a primary point of contact for security issues that require governance remediation.
  • Establish and maintain data governance frameworks and best practices for ensuring data quality, integrity, and security.
  • Demonstrate proficiency in database SQL and related programming languages (e.g., Python, R) for advanced data querying, manipulation, and security analysis.
  • Develop and maintain security governance dashboards and metrics to measure data security, compliance, and the overall effectiveness of security protocols.
  • Create automated solutions and facilitate the integration of data analytics systems to uphold data privacy and governance requirements.
  • Collaborate with cross-functional teams to identify and document data requirements, standards, and processes.
  • Design and manage a comprehensive data taxonomy for classifying and organizing data assets effectively.
  • Create and maintain a centralized data dictionary with detailed definitions, metadata, and lineage information for critical data elements.
  • Implement data governance tools and technologies to support data profiling, lineage tracking, and data quality monitoring.
  • Enhance and maintain Gemini’s security policies, standards and guidelines.
  • Conduct data protection impact assessments (DPIAs) and maintain records of processing activities (ROPAs) to recognize and alleviate potential security or data privacy weaknesses.

Minimum Qualifications:

  • BA/BS degree or equivalent practical experience.
  • 5 years of experience in the cyber security field developing and/or updating cyber security related documentation, policies, procedures and standards.
  • Familiarity with Data privacy regulations such as GDPR, CCPA etc.
  • Familiarity with SQL, Python or any other programming language.
  • Operational knowledge of systems, databases, and network security best practices.
  • Strong analytical and creative problem solving skills.
  • Strong interpersonal skills to interact with customers, senior level personnel, auditors, and team members.
  • Strong organization skills to prioritize work and balance complex projects.
  • Ability to work independently and as part of a broader team.

Preferred Qualifications:

  • Experience with automation of GRC initiatives and priorities.
  • Understanding of endpoint security, networking, and application-layer gateway technologies.
  • Experience with IDS, DLP, and SIEM tooling.
  • Experience with cloud-native environments.
It Pays to Work Here
The compensation & benefits package for this role includes:
  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Annual Learning & Development stipend
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $136,000 - $190,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.