TechJobBoard
Why TechJobBoard?

Gemini

Senior Associate, Security GRC

at Gemini

San Francisco, New York, United States



About the Company

Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future. We envision a world where crypto reshapes the global financial system, internet, and money to create greater choice, independence, and opportunity for all — bridging traditional finance with the emerging cryptoeconomy in a way that is more open, fair, and secure. As a publicly traded company, Gemini is poised to accelerate this vision with greater scale, reach, and impact.

The Department: SEC Governance, Risk & Compliance

The Role: Senior Associate, Security GRC

Gemini is seeking a driven and experienced Senior Associate, Security GRC to join our cybersecurity team. This cross-functional role blends strategic planning and hands-on execution to mature Gemini's cybersecurity programs. You will collaborate across teams to manage and enhance cyber processes, support regulatory obligations, and advise on cyber risk. The ideal candidate will demonstrate subject matter fluency, strong stakeholder engagement, and a track record of delivering impactful cybersecurity transformation and risk mitigation outcomes.

This role is required to be in person twice a week at either our San Francisco, CA or New York City, NY office.

Responsibilities:

  • Own and drive workstreams across security governance (e.g., entitlement reviews, access management, vendor security, cyber risk, software compliance).
  • Assess and lead cybersecurity projects across cloud security, container security, and infrastructure hardening.
  • Drive cybersecurity transformation initiatives including implementation of modern security architectures, DevSecOps practices, and zero trust frameworks.
  • Collaborate with DevOps and engineering teams to embed security into CI/CD pipelines, container orchestration platforms (e.g., Kubernetes), and cloud-native services.
  • Collaborate with engineering teams around security reviews and threat modeling for infrastructure, applications, and services.
  • Partner with engineering, IT, and business units to align security improvements with strategic objectives and technology modernization efforts.
  • Support third-party risk initiatives, including due diligence responses for customers, banks, and partners.
  • Champion automation initiatives to improve detection, response, and control monitoring.
  • Identify security gaps across cloud environments (e.g., AWS, GCP) and lead remediation efforts.
  • Advise technical and business teams on secure configurations, emerging threats, and remediation strategies.

Minimum Qualifications:

  • Bachelor’s degree in a technical, security, or related field, or equivalent practical experience.
  • 5+ years of experience in cybersecurity, with emphasis on cyber transformation initiatives. 
  • Strong understanding of modern enterprise security practices, including cloud security, and security automation.
  • Knowledge of cloud service providers (AWS, GCP, Azure), container platforms (Docker, Kubernetes), and modern security tooling.
  • Strong understanding of modern enterprise security practices, including IaC, DevSecOps, and zero trust.
  • Minimum of one core security certification such as CISSP, CCSP, GCP/AWS Security Specialty, or OSCP.
  • Knowledge of at least one or two security frameworks and standards (e.g., ISO 27001, ISO 27018, SOC 2, PCI DSS, NIST CSF, ISO 22301).
  • Strong writing, communication, and presentation skills across technical and business audiences.
  • Excellent stakeholder management skills; ability to influence across departments and levels.
  • Highly organized; able to manage multiple priorities and initiatives with minimal oversight.

Preferred Qualifications:

  • Big 4 or consulting experience supporting cybersecurity programs.
  • Experience leading or supporting enterprise-wide cyber transformation or modernization programs.
  • A compliance certification (e.g., ISO 27001, PCI QSA).
  • Experience with evidence automation, GRC tooling, or security compliance platforms.
  • Strong analytical skills and a proactive mindset with a bias for action.
It Pays to Work Here
 
The compensation & benefits package for this role includes:
  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $112,000 - $160,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

In the United States, we offer a hybrid work approach at our hub offices, balancing the benefits of in-person collaboration with the flexibility of remote work. Expectations may vary by location and role, so candidates are encouraged to connect with their recruiter to learn more about the specific policy for the role. Employees who do not live near one of our hubs are part of our remote workforce.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.

#LI-ES1

TechJobBoard

Search open jobs in the tech industry faster and find your match.

© 2023 TechJobBoard. All rights reserved.