WFH.teamOpen app
Back to remote jobs
Remote job detail

Risk & Controls Manager

Consensys

LocationUnited States, LATAM, EMEA
SeniorityManager
CompanyConsensys
Verified recentlyChecked today
Compensation

$150k-$206k

Salary details are shown when available from the source listing. Sign in before applying so the role can be reviewed against your resume, salary goals, seniority, timezone, and location eligibility.

Requirements and working style

Decision details from the source listing

Schedule

unspecified

These fields are normalized from the employer's text. Confirm details on the employer site before applying.

WFH.team analysis

What this posting tells you

Remote-first Risk & Controls Manager role operating the security risk register, control monitoring, audit evidence, and GRC tooling. Open to candidates in the United States, LATAM, and EMEA, except those based in France, Italy, or Germany. The stated US base pay range is $150,000–$206,000, excluding bonus, equity, and other benefits.

Role lane

Accounting, Data, Education, Finance and investments, Healthcare admin, HR and recruiting, Operations, QA and testing, Security, Software, Customer support

Where you can work

United States, LATAM, EMEA

Working hours

Timezone overlap is not stated.

Arrangement

Manager · full_time

Required signals
Risk register managementControl library and monitoringISO 27001 and/or SOC 2 audit operationsGRC platform experience (Drata or equivalent)Audit coordinationCustomer due-diligence questionnairesEvidence managementStakeholder managementPrecise written communication
Preferred signals
CISA certificationISO 27001 Lead Implementer or Auditor certification
Confirm before applying
  • Required timezone overlap is not stated
Market context

Accounting hiring on WFH.team

1,629active related roles
661new in the latest period
941.6jobs per 100 candidates
$183kmedian of comparable listed ranges

This role's listed pay is near the median among 196 comparable roles shown here. Category counts come from WFH.team's latest published remote job market snapshot.

Explore the remote job market
Skills and signals
Risk register managementControl library and monitoringISO 27001 and/or SOC 2 audit operationsGRC platform experience (Drata or equivalent)Audit coordinationCustomer due-diligence questionnairesEvidence managementStakeholder managementPrecise written communicationCISA certificationISO 27001 Lead Implementer or Auditor certificationRemote in the United States, LATAM, and EMEA; applicants based in France, Italy, or Germany are not eligible.
Job description

Risk & Controls Manager at Consensys

Please note that we are unable to consider applications from candidates based in France, Italy, or Germany for this role.

Money is moving onto the internet, and the shift has a name: Open Money. This is money that is open, portable, agentic, and owned by you. MetaMask spent the last ten years building it; with 100M+ downloads, users in ~190 countries, and trillions in cumulative transaction volume, it's the most trusted self-custodial financial platform on the internet. Now we're building the operating system for your money: one place to hold, move, grow, and use anything you own. Join a remote-first, global team rebuilding how money works: a problem that touches everyone, every day.

About the role

This role runs the internal posture engine — the risk register, critical control monitoring, evidence, audit operations and GRC tooling. It keeps risk state current so the Lead and the Risk Committee decide from accurate data in the Risk Dashboard and reporting. Drata is the register of record. Named owners close gaps; this role keeps the register, evidence and audit operations current.

Responsibilities

Planning

  • Operate the risk register from the Security Programme threat model: populate, track treatment, record acceptance decisions, follow up owners, and run the exceptions register.
  • Keep the ISMS and security policy library current as part of audit readiness. Draft security standards when commissioned by the Lead.
  • Run Drata as the control and evidence system — Statement of Applicability, framework crosswalk and automation.

Execution

  • Run critical control monitoring: health check-ins, drift flags and Drata automation. Route drift to the SOC. Maintain the evidence file for Lead assessments and independent internal audit.
  • Feed threat-assessment findings into the register and confidence ratings. Track which required assessments are current.
  • Lead audit coordination and preparation: ISO 27001 and SOC 2 logistics, ISMS readiness, team prep, management-review pack, and customer due-diligence questionnaires.
  • Coordinate the control register for external testing (red team, tabletop, pentest). Run security awareness and weekly alerts.

Tracking and evaluating performance

  • Track residual risk, exceptions and gap-closure against appetite. Exceptions expire and are reported; the underlying requirement stays in force.
  • Report register state and evidence health so the Lead and Risk Committee work from one view.

Achieving overall defined performance

  • Be accountable for a current, defensible posture engine — register, evidence and audit operations.
  • Ensure Drata collects evidence continuously, with automated evidence where coverage exists.

Qualifications

  • Hands-on experience running a risk register, control library and audit cycle (ISO 27001 and/or SOC 2).
  • Comfortable with GRC platforms (Drata or equivalent) and turning monitoring into evidence.
  • Proven ability to coordinate audits and customer questionnaires with named control owners.
  • Precise written work; register and Statement of Applicability quality matters.
  • Strong stakeholder management with control owners and auditors.
  • CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification.

Don't meet all the requirements? Don't sweat it. We’re passionate about building a diverse team of humans and as such, if you think you've got what it takes for our chaotic-but-fun, remote-friendly, start-up environment—apply anyway, detailing your relevant transferable skills in your cover letter. While we have a pretty good idea of what we need, we're ready for you to challenge our thinking on who needs to be in this role .

The salary range listed for this role applies to US-based candidates only. Compensation for candidates based outside the US (including Canada, EMEA, and LATAM) will be determined based on location, experience, and skills during the interview process, and may differ from the listed US range.

US pay range (not including bonus, equity or other benefits)

$150,000 — $206,000 USD

In the rapidly evolving Web3 space, we believe that everyone is a builder. This expansive paradigm requires a range of backgrounds, talents, skills, and experiences to influence and shape the future. At MetaMask, this diversity fuels our ability to shift control and redefine the realm of possibility. We are committed to ensuring that our technology empowers people and communities through decentralized technologies. We welcome the range of perspectives and differences and celebrate them. We're excited to see how your unique skills as a builder can contribute to our vision, drive innovation, and help us shape a more inclusive Web3.

MetaMask is an equal opportunity employer. All employment decisions are made without regard to race, color, national origin, ancestry, sex, gender, gender identity or expression, sexual orientation, age, genetic information, religion, disability, medical condition, pregnancy, marital status, family status, veteran status, or any other characteristic protected by law.

MetaMask is aware of fraudulent recruitment practices and we encourage all applicants to review our best practices to protect yourself, which can be found on our page.

MetaMask may use artificial intelligence (AI) tools to support parts of our recruitment process, such as reviewing applications, screening resumes, or conducting initial candidate assessments. These tools are designed to assist our recruiting team and improve efficiency — they do not replace human judgment. A human recruiter or hiring manager reviews every candidate, and all final hiring decisions are made by people, not AI.

It is a requirement of employment in this position that applicants may be required to submit to background and identity verification checks, including but not limited to employment, education, criminal record checks, and other such checks as determined necessary by the company.

Company context

Working remotely at Consensys

Consensys is hiring for 1 active remote role, with remote-friendly openings, application links, and job details refreshed from the public remote job inventory.

Headquarters
United States
Team size
501-1000
Founded
2014
Remote policy

Remote hiring signal is inferred from active confirmed-remote job listings.

Application process

Review current openings on Consensys's official careers page before applying.

Node.jsNext.jsPhoenix FrameworkTailwind CSSJavaScriptPythonHTML5JavaES6CSS 3
Research Consensys