About this Senior GRC Program Manager, Ripple Treasury role at Ripple
At Ripple, we’re building a world where value moves like information does today. It’s big, it’s bold, and we’re already doing it. Through our crypto solutions for financial institutions, businesses, governments and developers, we are improving the global financial system and creating greater economic fairness and opportunity for more people, in more places around the world. And we get to do the best work of our career and grow our skills surrounded by colleagues who have our backs.
If you’re ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.
THE WORK:
As a Senior GRC Program Manager, you will support the customer security assurance program, helping Ripple Treasury customers and prospects understand and gain confidence in our security program. This role sits at the intersection of security, sales, and compliance, backing up the RFP team on security questionnaires, meeting directly with prospective customers, maintaining our security-related sales documentation, and supporting the management of customer focused DORA audits.
This is a strong fit for a GRC-minded security professional who translates technical controls into clear, customer-ready answers, owns documentation with rigor, and can handle multiple deadlines across concurrent customer engagements.
WHAT YOU’LL DO:
- RFP & Security Questionnaire Support: Serve as backup to the RFP team, completing and reviewing security questionnaires (e.g., SIG, CAIQ, and custom customer questionnaires) accurately and on deadline, and maintaining a repository of reusable, approved responses.
- Customer Engagement: Meet with prospective and existing customers to walk through the Ripple security program, respond to security and due diligence questions, and support security-related aspects of deals and renewals.
- Security Sales Documentation: Create and maintain security-related sales collateral, security overviews, trust center content, certification and attestation summaries, control mappings, and architecture/data-flow references, ensuring materials stay current and accurately reflect the security program.
- DORA Audit Support: Assist in managing customer-initiated DORA (Digital Operational Resilience Act) audits, including coordinating audit logistics, gathering and organizing evidence, and serving as a liaison between customers and internal control owners.
- Evidence & Control Coordination: Partner with control owners across Information Security, Engineering, and IT to validate questionnaire responses and gather supporting evidence when needed.
- Cross-Functional Collaboration: Work closely with Information Security, Legal, Sales, and Customer Success to ensure consistent, accurate, and contractually aligned representation of Ripple Treasury's security and compliance posture.
- Continuous Improvement: Identify recurring customer questions and contribute to standardized responses, FAQs, and enablement materials to reduce manual effort and improve turnaround time.
- Risk Judgment: Recognize customer requests that may introduce security, compliance, or contractual risk, and escalate appropriately.
WHAT YOU'LL BRING:
- 5+ years in GRC, customer security assurance, or a related security function, with hands-on experience responding to customer security questionnaires and due diligence requests.
- Solid grounding in information security frameworks including SOC 2, ISO 27001, NIST, and SWIFT, with proven understanding of core security domains such as access control, encryption, vulnerability management, and vendor risk.
- Familiarity with regulatory frameworks affecting financial services customers; direct exposure to DORA is a strong plus.
- Strong written and verbal communication skills, with the ability to translate technical security concepts into clear, business-friendly language for non-technical audiences.
- Comfort managing multiple concurrent customer engagements and deadlines with strong organizational discipline.
- Experience with trust center or security assurance platforms (such as SafeBase,Vanta), questionnaire automation tooling, and GRC platforms (such as Drata or LogiGate).
- Background working directly with financial services or FinTech customers, with familiarity with data protection and privacy frameworks including GDPR, CCPA, and DORA.
- Relevant certifications such as CISA, CISM, CISSP, or Security+ are preferred.
WHO WE ARE:
Do Your Best Work
- The opportunity to build in a fast-paced start-up environment with experienced industry leaders
- A learning environment where you can dive deep into the latest technologies and make an impact. A professional development budget to support other modes of learning.
- Thrive in an environment where no matter what race, ethnicity, gender, origin, or culture they identify with, every employee is a respected, valued, and empowered part of the team.
- In-office collaboration for moments that matter is important to our culture, and we give managers and teams the flexibility to decide which 10+ days a month they come in.
- Bi-weekly all-company meeting - business updates and ask me anything style discussion with our Leadership Team
- We come together for moments that matter which include team offsites, team bonding activities, happy hours and more!
Take Control of Your Finances
- Competitive salary, bonuses, and equity
- Competitive benefits that cover physical and mental healthcare, retirement, family forming, and family support
- Employee giving match
- Mobile phone stipend
Take Care of Yourself
- R&R days so you can rest and recharge
- Generous wellness reimbursement and weekly onsite & virtual programming
- Generous vacation policy - work with your manager to take time off when you need it
- Industry-leading parental leave policies. Family planning benefits.
- Catered lunches, fully-stocked kitchens with premium snacks/beverages, and plenty of fun events
Benefits listed above are for full-time employees.