Risk & Controls Manager
MetaMask is an active Consensys-developed self-custodial crypto wallet and onchain finance platform available through browser extensions and mobile apps.
Maintainer signals as of 9/25/2026
Projects
About MetaMask
MetaMask provides self-custodial digital-asset management and access to decentralized applications. Its current platform includes wallet functionality, token swaps, trading, payments, earning, MetaMask Card, security features, Snaps, Agent Wallet, and developer tooling. MetaMask is a Consensys product and brand rather than an independently evidenced legal entity.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will operate the internal risk register, control monitoring, evidence collection, audit operations, and GRC tooling. You will keep the ISMS and security policy library current, manage Drata, monitor critical controls, coordinate audits and customer questionnaires, track residual risk and exceptions, and report risk and evidence health to support decision-making.
Requirements
- Hands-on experience running a risk register, control library, and audit cycle for ISO 27001 and/or SOC 2.
- Experience with GRC platforms such as Drata or equivalent and converting monitoring into evidence.
- Ability to coordinate audits and customer questionnaires with named control owners.
- Precise written documentation, including risk registers and Statements of Applicability.
- Stakeholder management with control owners and auditors.
- CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification.
- Ability to complete background and identity verification checks as required.
Responsibilities
- Operate the risk register, track treatments and acceptance decisions, follow up with owners, and run the exceptions register.
- Maintain the ISMS and security policy library and draft security standards when commissioned.
- Manage Drata as the control and evidence system, including the Statement of Applicability, framework crosswalk, and automation.
- Run critical control monitoring, identify drift, route drift to the SOC, and maintain evidence for assessments and internal audits.
- Feed threat-assessment findings into the register and track required assessments.
- Lead ISO 27001 and SOC 2 audit coordination and preparation, ISMS readiness, team preparation, management-review materials, and customer due-diligence questionnaires.
- Coordinate the control register for external testing, including red-team exercises, tabletop exercises, and penetration tests.
- Run security awareness activities and weekly alerts.
- Track residual risk, exceptions, and gap closure against risk appetite.
- Report register state and evidence health to the Lead and Risk Committee.
- Ensure Drata continuously collects evidence, using automation where coverage exists.
Benefits
- Remote-friendly work environment
- Bonus
- Equity
