Security Governance and Risk Specialist
About Us
Chainlink Labs is leading the development of Chainlink, the decentralized computing platform that powers the verifiable web. Chainlink is the industry-standard platform for providing access to real-world data, offchain computation, and secure cross-chain interoperability across any blockchain. Chainlink Labs collaborates with major financial institutions and top Web3 teams in various industries like banking, DeFi, global trade, and gaming, to create verifiable applications. Ranked in Newsweek’s 100 Most Loved Workplaces in the U.S. and UK, Chainlink Labs is a renowned contributor.
The Security Team
The security department at Chainlink Labs ensures the safety of people and vital assets by mitigating external and internal threats. Using advanced security engineering, up-to-date technologies, progressive policy development, and training, the team safeguards Chainlink Labs and its resources from potential risks, cultivating a security-conscious culture within the organization.
The Role
Chainlink Labs is looking for a skilled Security Governance & Risk Specialist to join the Security Assurance team. This role involves establishing security governance committees, conducting security risk assessments, maintaining risk register, collaborating with stakeholders for remediation efforts, and contributing to security compliance requirements. The ideal candidate will have a proven track record in managing complex engineering, security, and operational projects with a strong technical background.
Your Impact
- Develop, maintain, and implement security policies to guide security practices.
- Establish security frameworks like ISO 27001, NIST, or COBIT to strengthen security governance.
- Execute security risk assessment processes, document findings, and implement risk treatment strategies.
- Track identified risks and their mitigation efforts in a risk register.
- Implement security controls to address identified risks and enhance security posture.
- Define KPIs and metrics to gauge the effectiveness of security controls and governance processes.
- Present security reports to senior management, highlighting risks, incidents, and compliance status.
- Conduct comprehensive third-party risk assessments of vendors in collaboration with Finance and Legal teams.
- Support security due diligence questionnaires for potential customers.
- Automate risk management tools to streamline security risk assessment processes.
- Engage in team-building events, peer reviews, and management review cycles.
Requirements
- Education or experience in Information Security.
- Minimum 3 years of experience in Security Governance and Risk function with end-to-end security risk management capability.
- Previous experience in dynamic technology or Web 3 companies.
- Proficiency in building enterprise security risk management processes compliant with ISO and SOC2 standards.
- Strong technical background in handling complex engineering, security, and operations projects.
- Certification(s) such as CISSP, CISM, CRISC, AWS/Azure/CGP security, etc.
- Excellent communication skills, especially in risk assessment.
Desired Qualifications
- Experience in security risk management within the Web3 space.
- Background in cybersecurity practice at a major audit firm.
- Proficiency with Security GRC tool implementation.
- Ability to devise and implement strategies for mitigating security risks.
All opportunities with Chainlink Labs are global and remote-based. Candidates must ensure some overlap of working hours with Eastern Standard Time (EST) unless otherwise specified.
Commitment to Equal Opportunity
Chainlink Labs provides equal employment opportunities and ensures fair consideration for all applicants based on legal requirements. Candidates seeking assistance due to disabilities or special needs during the application process can reach out via the provided form.
Global Data Privacy Notice for Job Candidates and Applicants
By submitting applications or creating a profile through Chainlink Labs Careers, candidates agree to the use and processing of their data as per the privacy policy guidelines.
