About the company
Founded in Paris in 2014, LEDGER is a global platform for digital assets and Web3. Ledger is already the world leader in Critical Digital Asset security and utility. With more than 6M devices sold to consumers in 200 countries and 10+ languages, 100+ financial institutions and brands as customers, 20% of the worldās crypto assets are secured, plus services supporting trading, buying, spending, earning, and NFTs. LEDGERās products include: Ledger Stax, Nano S Plus, Nano X hardware wallets, LEDGER Live companion app, [ LEDGER ] Market, the worldās first secure-minting and first-sale distribution platform, and Ledger Enterprise. With its ease of use, LEDGER allows a user to begin investing in digital assets and ultimately, achieve financial freedom in a safe and stress-free environment.
Job Summary
Your mission
šConduct comprehensive security assessments of third-party vendors, including reviewing their security policies, procedures, and controls šIdentify and evaluate security/privacy risks, especially for vendors handling sensitive customer data and critical product supply chain operations. šDevelop and implement risk mitigation strategies to address identified vulnerabilities šCollaborate with vendors to remediate security gaps and ensure compliance with Ledger's stringent security requirements šMonitor vendor performance and compliance with security agreements šContribute to the development and improvement of Ledger's third-party security risk management program šPrepare reports and presentations on vendor security risks and mitigation efforts for various stakeholders
What we're looking for
šDegree or equivalent experience in Information Security, Cybersecurity, or a related field šMinimum 2 years of experience in areas like audit, risk management, compliance or control function šStrong organizational skills to manage multiple projects and document outcomes effectively šFamiliarity with security frameworks and standards (e.g., ISO 27001, NIST Cybersecurity Framework) šAnalytical and problem-solving mindset with a proactive approach to challenges šClear and inclusive communication skills for technical and non-technical audiences šExperience with security assessment tools and technologies is an asset šKnowledge of data privacy regulations (e.g., GDPR, CCPA) šCertifications (e.g., CISSP, CISM, CISA) are welcome