Director, Compliance
About Riot Platforms
Riot’s (NASDAQ: RIOT) vision is to be the world’s most trusted platform for powering and building digital infrastructure. Riot’s mission is to empower the future of digital infrastructure by positively impacting the sectors, networks, and communities that we touch. We believe that the combination of an innovative spirit and strong community partnership allows us to achieve best-in-class execution and create successful outcomes.
About the Role
The Director, Compliance owns the engine that keeps Riot audit-ready year-round: the controls framework, the testing program, the issues and remediation lifecycle, and the GRC platform that ties all of it together. Compliance designs the controls that prove that policies are working — and builds the automation infrastructure that makes proving it sustainable at scale. This pillar is intentionally scoped to execute, not to govern or audit.
- Owns the ISO 27001:2022 controls implementation track — designing, implementing, and evidencing all Annex A controls required for certification, on a schedule with no buffer.
- Executes the control testing program across all in-scope frameworks: design adequacy and operating effectiveness testing, evidence documentation to SOC 2 and ISO 27001 audit-quality standards, and a continuous testing calendar that eliminates point-in-time audit scrambles.
- Leads GRC platform selection, implementation, and administration: evaluate vendors (ServiceNow GRC, Vanta, Drata, Hyperproof, OneTrust, or equivalent), build the business case, drive implementation to production, and own the platform as the system of record for all GRC controls, risks, and evidence.
- Drives compliance automation: identify manual, spreadsheet-based workflows and replace them with automated evidence collection, integrated dashboards, and real-time controls monitoring — integrating the GRC platform with Asana, identity providers, AWS/Azure, and operational source systems.
- Engages mining site and data center teams to design, implement, test, and evidence operational controls (physical access, environmental monitoring, change management, asset management) to the same standard as enterprise IT controls.
What You'll Do
- Design and build the Riot unified controls framework: map the control universe to ISO 27001 Annex A, SOC 2 Trust Services Criteria, NIST CSF, and SOX ITGC; assign control owners; define testing frequencies; and rationalize overlapping framework requirements into a single, audit-efficient control set.
- Execute the control testing program across all in-scope frameworks: design adequacy and operating effectiveness testing, evidence documentation to SOC 2 and ISO 27001 audit-quality standards, and a continuous testing calendar that eliminates point-in-time audit scrambles.
- Lead GRC platform selection, implementation, and administration: evaluate vendors (ServiceNow GRC, Vanta, Drata, Hyperproof, OneTrust, or equivalent), build the business case, drive implementation to production, and own the platform as the system of record for all GRC controls, risks, and evidence.
- Drive compliance automation: identify manual, spreadsheet-based workflows and replace them with automated evidence collection, integrated dashboards, and real-time controls monitoring — integrating the GRC platform with Asana, identity providers, AWS/Azure, and operational source systems.
- Engage mining site and data center teams to design, implement, test, and evidence operational controls (physical access, environmental monitoring, change management, asset management) to the same standard as enterprise IT controls.
What You'll Bring
- 8–12+ years of progressive GRC, IT audit, controls design, or compliance program experience, with hands-on GRC platform administration (required — not observer-level familiarity).
- ISO 27001 Lead Implementer or Lead Auditor certification — required. The Director, Compliance owns the controls framework that underpins ISO 27001:2022 certification. A lead-level credential is the baseline, not a preference.
- Demonstrated experience designing a controls framework mapped simultaneously to multiple standards (SOC 2, ISO 27001, NIST CSF, SOX ITGC) and rationalized to a unified, audit-efficient control set.
- Direct experience executing control testing programs: design adequacy and operating effectiveness testing, evidence documentation to audit-quality standards, and reporting testing results to senior leadership.
- Proven GRC platform experience as a power user or administrator — control library configuration, evidence mapping, workflow design, and integration with source systems (Asana, identity providers, AWS/Azure).
- Strong automation and integration mindset: experience building automated evidence pipelines, dashboard reporting, or integrations between GRC platforms and operational systems.
- Experience managing an issues and remediation lifecycle (POA&M): tracking, owner accountability, escalation, and closure validation across cross-functional control owners.
- Technical fluency: comfortable evaluating AWS and Azure security configurations as control evidence; familiarity with API-based GRC integrations; light scripting (Python, SQL) or AI-assisted automation is a strong plus.
Compensation and Benefits
- Competitive Salary: Base range (commensurate with experience) + bonus + sign-on equity grant.
- Long-Term Growth: Eligible to participate in Riot’s equity incentive programs and share in the success you help build.
- 401(k) Retirement Plan: Includes a generous company match.
- Comprehensive Health Coverage: Multiple medical plan options, including 100% company-paid plans.
- Wellness & Lifestyle Perks: Enjoy free gym memberships, pet insurance, childcare discounts, and more to support your life both in and out of work.
EEO Statement
Riot is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.