About the company
Gemini is a regulated cryptocurrency exchange, wallet, and custodian that makes it simple and secure to buy bitcoin, ether, and other cryptocurrencies.
Job Summary
Responsibilities:
šAssist in identifying, evaluating, documenting, and communicating security risks across the organization, ensuring continuous monitoring and management of these risks.
šCollaborate with internal stakeholders to observe and learn about risk remediation strategies and assess any residual risks that may remain.
šSupport the team in conducting annual security risk assessments, aligned with the NIST Cybersecurity Framework (NIST CSF).
šParticipate in supervised Targeted Risk Assessment (TRA) in compliance with PCI DSS and other risk assessment projects.
šHelp conduct comprehensive vendor security risk assessments, and support the team in providing recommendations for contractual security provisions.
šParticipate in supervised external security audits and assist in providing risk related evidence.
šContribute ideas and assist in projects to further advance the GRC programs.
šSupport management in identifying potential areas of concern with suggested mitigation strategies.
šHelp review and update security policies and standards, ensuring they remain current and effective in addressing evolving threats and regulatory requirements.
Qualifications:
šCurrently enrolled in a BachelorĆ¢ĀĀs or MasterĆ¢ĀĀs degree program in a relevant field (e.g., Cybersecurity, Information Security, Computer Science, Business, or related discipline). šStrong analytical and creative problem solving skills. šStrong interpersonal skills to interact with team members, auditors, and stakeholders. šStrong organization skills to prioritize work and balance assigned projects. šAbility to work independently and as part of a broader team. šUnderstanding of security controls and third party security risk management. šFamiliarity and understanding with key security best practices concepts and standards preferred (e.g., OWASP top 10, NICS CSF). šKnowledge of compliance and security standards such as SOC 2 Type II, ISO 27001, PCI DSS preferred.
If youāre passionate about blockchain and decentralized technologies, explore more opportunities in web3 and cryptocurrency careers.