Senior GRC Program Manager
Ripple provides payments, custody and stablecoin solutions that help financial institutions integrate blockchain and digital assets.
Maintainer signals as of 8/23/2026
Funding history
Investors
Projects
About Ripple
Ripple helps financial institutions transform global payments by providing blockchain-powered infrastructure for cross-border payments, digital asset custody, and stablecoin solutions. With it, users can enable instant settlements, reduce costs, and access new markets. The company was originally founded as OpenCoin in 2012 and rebranded to Ripple in 2015.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Lead ICT operations initiatives in Luxembourg, bridge global engineering teams with local regulatory execution, maintain security frameworks, oversee outsourced ICT and security services, gather technical evidence, and support audits and regulatory reviews.
Requirements
- 5+ years of experience in information security infrastructure, preferably in a regulated industry.
- Bachelor's degree in a relevant discipline or equivalent professional experience.
- Experience in the Luxembourg financial or technology sector.
- Working knowledge of DORA, including resilience testing, ICT third-party management, and incident response.
- Familiarity with MiCA, EBA, and ESMA technical standards.
- Proficiency with ISO 27001, SOC2, and NIST.
- Experience gathering and analyzing technical evidence in cloud-native environments.
- Ability to create technical documentation and SOPs.
- Cross-functional collaboration experience.
- Familiarity with Jira, Confluence, JupiterOne, Okta, AWS, Tines, and GRC platforms is advantageous.
- CISSP, CISA, AWS Certified Security, or PMP certifications are desirable.
- Professional English proficiency required; French proficiency desirable.
Responsibilities
- Implement and maintain EU and Luxembourg security frameworks, including DORA.
- Manage and oversee outsourced ICT and security services.
- Coordinate infrastructure, application, and architectural change evaluations with global Engineering and IT teams.
- Implement technical security controls across infrastructure and application environments.
- Develop, maintain, and localize information security policies, standards, and procedures.
- Gather technical evidence such as logs, system settings, and access reports.
- Serve as an operational subject matter expert during internal, customer, and regulatory audits.
- Provide operational security guidance to cross-functional teams.
- Support security due diligence questionnaires and customer contract reviews.
- Participate in regional industry events and discussions.
Benefits
- Professional development budget
- Competitive bonuses and equity
- Healthcare, retirement, family-forming, and family-support benefits
- Employee giving match
- Mobile phone stipend
- R&R days
- Wellness reimbursement
- Generous vacation policy
- Parental leave and family planning benefits
- Catered lunches and stocked kitchens
- Team offsites, bonding activities, and happy hours
