Risk & Controls Manager

MetaMask
•$150,000 - $206,000•Remote

About The Position

This role runs the internal posture engine — the risk register, critical control monitoring, evidence, audit operations and GRC tooling. It keeps risk state current so the Lead and the Risk Committee decide from accurate data in the Risk Dashboard and reporting. Drata is the register of record. Named owners close gaps; this role keeps the register, evidence and audit operations current.

Requirements

  • Hands-on experience running a risk register, control library and audit cycle (ISO 27001 and/or SOC 2).
  • Comfortable with GRC platforms (Drata or equivalent) and turning monitoring into evidence.
  • Proven ability to coordinate audits and customer questionnaires with named control owners.
  • Precise written work; register and Statement of Applicability quality matters.
  • Strong stakeholder management with control owners and auditors.
  • CISA, ISO 27001 Lead Implementer or Auditor, or equivalent professional certification.

Nice To Haves

  • Don't meet all the requirements? Don't sweat it. We’re passionate about building a diverse team of humans and as such, if you think you've got what it takes for our chaotic-but-fun, remote-friendly, start-up environment—apply anyway, detailing your relevant transferable skills in your cover letter. While we have a pretty good idea of what we need, we're ready for you to challenge our thinking on who needs to be in this role.

Responsibilities

  • Operate the risk register from the Security Programme threat model: populate, track treatment, record acceptance decisions, follow up owners, and run the exceptions register.
  • Keep the ISMS and security policy library current as part of audit readiness. Draft security standards when commissioned by the Lead.
  • Run Drata as the control and evidence system — Statement of Applicability, framework crosswalk and automation.
  • Run critical control monitoring: health check-ins, drift flags and Drata automation. Route drift to the SOC. Maintain the evidence file for Lead assessments and independent internal audit.
  • Feed threat-assessment findings into the register and confidence ratings. Track which required assessments are current.
  • Lead audit coordination and preparation: ISO 27001 and SOC 2 logistics, ISMS readiness, team prep, management-review pack, and customer due-diligence questionnaires.
  • Coordinate the control register for external testing (red team, tabletop, pentest). Run security awareness and weekly alerts.
  • Track residual risk, exceptions and gap-closure against appetite. Exceptions expire and are reported; the underlying requirement stays in force.
  • Report register state and evidence health so the Lead and Risk Committee work from one view.
  • Be accountable for a current, defensible posture engine — register, evidence and audit operations.
  • Ensure Drata collects evidence continuously, with automated evidence where coverage exists.

Benefits

  • bonus
  • equity
  • other benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service