Senior Associate, Security GRC

7 days ago


New York NY, United States Gemini Full time

Maximise your chances of a successful application to this job by ensuring your CV and skills are a good match.
Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future. We envision a world where crypto reshapes the global financial system, internet, and money to create greater choice, independence, and opportunity for all — bridging traditional finance with the emerging cryptoeconomy in a way that is more open, fair, and secure. The Department: SEC Governance, Risk & Compliance
The Role: Senior Associate, Security GRC (Cyber)
Gemini is seeking a hands-on Senior Associate, Security GRC to join our cybersecurity team. You will blend security engineering with governance and risk to mature Gemini’s security controls. You will also support regulatory obligations and customer diligence with automated, repeatable evidence.
This role is required to be in person twice a week at either our San Francisco, CA or New York City, NY office.
Perform technical security reviews and assessments for cloud architectures, Kubernetes and containers, serverless, network controls, and IAM. Build and support API-based integrations across GRC, cloud, and identity platforms (AWS, Azure, Okta, Atlassian). Use REST, GraphQL, webhooks, OAuth, and service accounts.
Lead threat modeling and design reviews for infrastructure, applications, and services. Document risks and compensating controls.
Develop continuous control monitoring and evidence pipelines. Drive zero trust improvements across identity, device posture, network segmentation, and service-to-service authentication.
Prepare for audits and regulatory requests using automated evidence, inventories, and dashboards. Own and drive workstreams across security governance (e.g., entitlement reviews, access management, vendor security, cyber risk, software compliance).
Assess and lead cybersecurity projects across cloud security, container security, and infrastructure hardening.
Drive cybersecurity transformation initiatives including implementation of modern security architectures, DevSecOps practices, and zero trust frameworks.
Collaborate with DevOps and engineering teams to embed security into CI/CD pipelines, container orchestration platforms (e.g., Kubernetes), and cloud-native services.
Advise technical and business teams on secure configurations, emerging threats, and remediation strategies.
Bachelor’s degree in computer science, information security, engineering, or related field, or equivalent experience.
~5+ years in cybersecurity with hands-on security engineering in cloud, automation, or platform security.
~ Proficiency in basic coding. Python or JavaScript and shell scripting. Experience building and operating REST or GraphQL integrations. Working knowledge of AWS, GCP, and Azure. Comfortable with IAM, networking, KMS, logging and monitoring, and cloud-native security services.
~ Familiar with Helm, admission controllers, and runtime security.
~ Applied knowledge of CIS Benchmarks for AWS, GCP, Linux, and Kubernetes. Strong understanding of enterprise security practices, including DevSecOps, zero trust, and security automation.
~ At least one core security certification, such as CISSP, CCSP, AWS Security Specialty, GCP Professional Cloud Security Engineer, or OSCP.
~ Strong writing, communication, and presentation skills across technical and business audiences. Experience leading or supporting enterprise security modernization and cloud guardrails.
Experience with policy-as-code and platform guardrails (OPA or Rego, AWS Config, Azure Policy, Google Organization Policy).
Experience with CI systems and embedding security checks (GitHub Actions, GitLab CI, CircleCI, Jenkins).
Experience with evidence automation and GRC tooling (AuditBoard, Vanta, Drata, Secureframe, or in-house).
Experience with CSPM and CWPP platforms and SIEM or EDR (Wiz, Prisma Cloud, Aqua, Falco, Splunk, Elastic, Chronicle, Datadog, Panther).
Ability to build dashboards and basic analytics for control monitoring. SQL or notebook-based analysis is a plus.
A discretionary annual bonus
~ Long-term incentive in the form of a new hire equity grant
~ Comprehensive health plans
~Flexible time off

This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.
In the United States, we offer a hybrid work approach at our hub offices, balancing the benefits of in-person collaboration with the flexibility of remote work. Expectations may vary by location and role, so candidates are encouraged to connect with their recruiter to learn more about the specific policy for the role. Employees who do not live near one of our hubs are part of our remote workforce.
At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status.



  • New York, United States Gemini Full time

    About the CompanyMaximise your chances of a successful application to this job by ensuring your CV and skills are a good match.Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our...


  • New York, New York, United States Gemini Full time $112,000 - $160,000 per year

    About The CompanyGemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to...


  • New York, United States SelekIT LLC Full time

    Senior Security Consultant SAP CP GRC and SAP SecurityJob Openings Senior Security Consultant SAP CP GRC and SAP SecurityAbout the job Senior Security Consultant SAP CP GRC and SAP SecurityPosition: Senior Security Consultant, SAP CP GRC and SAP SecurityEmployment Type: 1099 Contract (Fully Remote)Eligibility: Only U.S. citizensTravel: Light travel within...


  • New York, United States Next Step Systems LTD Full time

    Senior Analyst, Cybersecurity GRC, New York, NY The Senior Analyst, Cybersecurity GRCwill administer the completion of compliance-related client requests to assess security policies and procedures. The Senior Analyst will respond to inquiries on the security controls policy, processes, and procedures implemented for managed systems and applications, as well...


  • New York, NY, United States SelekIT Full time

    About the job Senior Security Consultant SAP CP GRC and SAP Security Position: Senior Security Consultant, SAP CP GRC and SAP Security Employment Type: 1099 Contract (Fully Remote) Eligibility: Only U.S. citizens Travel: Light travel within the US (as needed) About the Role We are seeking an experienced Senior Security Consultant with 45 years of hands-on...


  • New York, New York, United States SelektIT Full time

    Position: Senior Security Consultant,  SAP CP GRC and SAP SecurityEmployment Type: 1099 Contract (Fully Remote)Eligibility: Only U.S. citizens Travel: Light travel within the US (as needed)About the RoleWe are seeking an experienced Senior Security Consultant with 45 years of hands-on expertise in SAP CP GRC and SAP Security. As a consultant, you will be...

  • Security GRC Engineer

    4 weeks ago


    New York, NY, United States Anysphere Full time

    Security GRC Engineers design, implement, and scale our governance, risk, and compliance (GRC) program. You will lead automation of compliance workflows, build self-serve tools to enable GTM teams, and ensure our products and infrastructure meet the highest security standards. This role combines technical implementation with strategic program development,...

  • Lead, Security GRC

    3 weeks ago


    New York, United States Gemini Full time

    Lead, Security GRC (Compliance) Join Gemini, a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014. We seek a Security GRC Lead to manage PCI, ISO 27001, NYDFS, and SOC II compliance programs. The role requires strong project management, executive communication, and deep expertise in security compliance frameworks....

  • Lead, Security GRC

    7 days ago


    New York, United States Gemini Full time

    About the Company Applying for this role is straight forward Scroll down and click on Apply to be considered for this position.Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our...

  • Senior GRC Analyst

    2 weeks ago


    New York, United States Kendall And Davis, Inc. Full time

    Position Title: Senior GRC Analyst FTE/Direct Hire Hybrid Work Schedule Long Island, NY Company Story: Large financial institution with over $110+ billion in assets Over 2 Centuries of providing service to the community Family-oriented environment that respects their employees and promotes a work-life balance. Technology driven environment Benefits and...