The Director, Compliance owns the engine that keeps Riot audit-ready year-round: the controls framework, the testing program, the issues and remediation lifecycle, and the GRC platform that ties all of it together. Compliance designs the controls that prove that policies are working — and builds the automation infrastructure that makes proving it sustainable at scale. This pillar is intentionally scoped to execute, not to govern or audit. Compliance owns the unified control library — design, mapping to ISO 27001 Annex A, SOC 2 Trust Services Criteria, NIST CSF, and SOX ITGC — along with owner assignment and testing cadences. Compliance owns the testing program across design adequacy and operating effectiveness. Compliance owns the issues and remediation lifecycle. And Compliance owns the GRC platform: selection, implementation, configuration, integrations, and ongoing administration. You will report to the Senior Director, GRC and partner directly with IT and Security Engineering as the primary technical counterparts for control evidence, cloud configuration reviews, and platform integrations. In critical operations, you will work with mining site and data center teams to ensure operational controls — physical access, environmental monitoring, asset management — are designed, tested, and evidenced to the same standard as enterprise IT controls. This role has one non-negotiable: you must be an operator, not just a strategist. In Year 1 you will personally administer the GRC platform, configure the control library, build integrations, and drive the automation that eliminates manual audit prep.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director
Education Level
No Education Listed