Remote
Risk & Controls Manager
About this role
Please note that we are unable to consider applications from candidates based in France, Italy, or Germany for this role. Money is moving onto the internet, and the shift has a name: Open Money. This is money that is open, portable, agentic, and owned by you. MetaMask spent the last ten years building it; with 100M+ downloads, users in ~190 countries, and trillions in cumulative transaction volume, it's the most trusted self-custodial financial platform on the internet.
Now we're building the operating system for your money: one place to hold, move, grow, and use anything you own. Join a remote-first, global team rebuilding how money works: a problem that touches everyone, every day. About the role This role runs the internal posture engine — the risk register, critical control monitoring, evidence, audit operations and GRC tooling. It keeps risk state current so the Lead and the Risk Committee decide from accurate data in the Risk Dashboard and reporting.
Drata is the register of record. Named owners close gaps; this role keeps the register, evidence and audit operations current. Responsibilities Planning Operate the risk register from the Security Programme threat model: populate, track treatment, record acceptance decisions, follow up owners, and run the exceptions register. Keep the ISMS and security policy library current as part of audit readiness. Draft security standards when commissioned by the Lead.
Run Drata as the control and evidence system — Statement of Applicability, framework crosswalk and automation. Execution Run critical control monitoring: health check-ins, drift flags and Drata automation. Route drift to the SOC. Maintain the evidence file for Lead assessments and independent internal audit. Feed threat-assessment findings into the register and confidence ratings. Track which required assessments are current.
Lead audit coordination and preparation: ISO 27001 and SOC 2 logistics, ISMS readiness, team prep, management-review pack, and customer due-diligence questionnaires. Coordinate the control register for external testing (red team, tabletop, pentest). Run security awareness and weekly alerts. Tracking and evaluating performance Track residual risk, exceptions and gap-closure against appetite. Exceptions expire and are reported; the underlying requirement stays in force.