Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
MetaMask

Risk & Controls Manager

MetaMask

. Operate the risk register from the Security Programme threat model, including treatment tracking, acceptance decisions, owner follow-up and the exceptions register .

Posted 9/24/2026full-timeRemote • United StatesMid-LevelSenior💰 $150,000 - $206,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing risk registers, coordinating ISO 27001 and SOC 2 audits, and utilizing GRC platforms like Drata for evidence collection and monitoring. Strong stakeholder management and precise documentation skills are essential for maintaining compliance and security standards.

Highest-signal resume keywords
Risk Register ManagementISO 27001 Audit CoordinationSOC 2 Audit PreparationGRC Platform ProficiencyStakeholder Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk Register OperationControl Library ManagementAudit Cycle ExecutionSecurity Standards DraftingEvidence Maintenance
Soft Skills
Strong Written CommunicationStakeholder Management
Tools & Technologies
DrataControl Monitoring Systems
Certifications & Qualifications
CISAISO 27001 Lead ImplementerISO 27001 Auditor
Industry Keywords
ISMSSecurity PolicyThreat AssessmentControl RegisterPenetration Testing

About the role

Key responsibilities & impact
  • Operate the risk register from the Security Programme threat model, including treatment tracking, acceptance decisions, owner follow-up and the exceptions register
  • Keep the ISMS and security policy library current and draft security standards when commissioned
  • Run Drata as the control and evidence system, including the Statement of Applicability, framework crosswalk and automation
  • Run critical control monitoring, health check-ins, drift flags and Drata automation
  • Maintain evidence for Lead assessments and independent internal audit
  • Feed threat-assessment findings into the register and confidence ratings
  • Lead ISO 27001 and SOC 2 audit coordination and preparation, including ISMS readiness, team preparation, management-review packs and customer due-diligence questionnaires
  • Coordinate the control register for red-team, tabletop and penetration testing
  • Run security awareness and weekly alerts
  • Track residual risk, exceptions and gap closure against appetite
  • Report register state and evidence health to the Lead and Risk Committee
  • Maintain a current, defensible posture engine and ensure Drata collects evidence continuously

Requirements

What you’ll need
  • Hands-on experience running a risk register, control library and audit cycle (ISO 27001 and/or SOC 2)
  • Comfort with GRC platforms (Drata or equivalent) and turning monitoring into evidence
  • Proven ability to coordinate audits and customer questionnaires with named control owners
  • Precise written work; register and Statement of Applicability quality matters
  • Strong stakeholder management with control owners and auditors
  • CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification
  • Applicants may be required to submit to employment, education, criminal record and other background and identity checks
  • Applications are not considered from candidates based in France, Italy, or Germany

Benefits

Comp & perks
  • Equal opportunity employment
  • Background and identity verification checks as a condition of employment
  • Remote-friendly, remote-first work environment