Riot Platforms, Inc. Logo

Riot Platforms, Inc.

Director, Risk Management

Reposted An Hour Ago
Remote
Hiring Remotely in United States
Expert/Leader
Remote
Hiring Remotely in United States
Expert/Leader
Owns Riot’s risk management and GRC execution, including SOC 1 and SOC 2 audits, ISO 27001 certification readiness, SOX ITGC coordination, enterprise risk registers, KRI/KPI reporting, POA&M remediation, auditor relationships, and continuous audit readiness. The role partners with executives, Internal Audit, external auditors, mining sites, and data center leadership to identify, quantify, report, and remediate operational and technology risks.
The summary above was generated by AI

About Riot Platforms

Riot’s (NASDAQ: RIOT) vision is to be the world’s most trusted platform for powering and building digital infrastructure. Riot’s mission is to empower the future of digital infrastructure by positively impacting the sectors, networks, and communities that we touch. We believe that the combination of an innovative spirit and strong community partnership allows us to achieve best-in-class execution and create successful outcomes.


Who we are

At Riot, we’re building the future of digital infrastructure. Our team members have unparalleled opportunities to work on groundbreaking initiatives. Through technical excellence and strategic execution, Riot has positioned itself as a leader in the industry driving advancements that continue to set new benchmarks in digital infrastructure. 


We are trailblazers. Problem solvers. People who thrive in fast paced environments, communicate clearly, and bring relentless focus to efficiency and execution.

About the role

The Director, Risk Management owns Riot's most time-critical GRC pillar. This role steps directly into that execution environment — timelines do not pause for onboarding.

This pillar is intentionally scoped: Risk Management owns the external auditor relationship, the evidence pipeline, the enterprise risk register, the POA&M lifecycle, and the ISO 27001 audit readiness and certification audit track. You own risk identification, risk quantification, audit execution, and the remediation lifecycle that closes gaps across all pillars.

You will report to the Senior Director, GRC and serve as Riot's primary relationship owner with external auditors across SOC 1, SOC 2, and ISO 27001. You will partner directly with the CFO on SOX obligations and with Internal Audit on shared ITGC methodology. In critical operations, you will engage mining site and data center leadership to ensure operational risks are captured, assessed, and reflected in the enterprise risk register.


What you'll do

  • Own end-to-end execution of SOC 1 and SOC 2 Type II audits: scoping, control walkthroughs, evidence collection, auditor liaison, management response drafting, and remediation tracking — you are the primary point of contact for all external audit activity.
  • Lead the ISO 27001:2022 audit readiness and certification audit track — coordinating evidence, managing the certification audit relationship, and driving the program to on-schedule certification under the governance of the Sr. Director, GRC.
  • Serve as the primary liaison to Internal Audit for SOX ITGC coordination — establishing a shared control inventory, aligning testing methodologies, dividing walkthroughs to eliminate duplication, and maintaining a joint remediation cadence.
  • Build and operate the Riot enterprise risk register: define the risk taxonomy, conduct risk assessments across all business units including mining and data center operations, tier risks by likelihood and impact, and maintain a living register updated no less than quarterly.
  • Develop and maintain the KRI/KPI framework for executive and Board-level risk reporting — translating risk register outputs into leading indicators that give leadership actionable visibility into Riot's risk posture.
  • Run the POA&M (Plan of Action & Milestones) program: intake all audit findings and control gaps across all GRC pillars, assign ownership, track remediation progress, escalate stalled items, and report status to the Sr. Director on a defined cadence.
  • Build continuous audit-readiness infrastructure: design repeatable evidence pipelines, drive evidence collection automation where possible, and eliminate point-in-time audit scrambles by maintaining a year-round audit-ready posture.


What you'll bring

  • 8–12+ years of progressive GRC, IT audit, or enterprise risk management experience, with direct, hands-on ownership of SOC 1 and/or SOC 2 Type II audits — required, not supporting-role exposure.
  • ISO 27001 Lead Implementer certification — required. Must have credentialed implementation experience to own the audit execution and certification track.
  • Working knowledge of SOX ITGC requirements at a publicly traded company, with demonstrated experience coordinating GRC work with an Internal Audit function.
  • Proven experience building or operating an enterprise risk register, risk taxonomy, and KRI/KPI reporting framework for executive audiences.
  • Experience owning the external auditor relationship — managing audit timelines, evidence requests, walkthrough coordination, and management response drafting across multiple concurrent audit programs.
  • Strong POA&M and remediation lifecycle management: tracking, escalating, and closing audit findings across cross-functional control owners.
  • Familiarity with at least one additional security framework beyond SOC 2 — ISO 27001, NIST CSF, or NIST 800-53.
  • Excellent written and verbal communication — ability to present risk posture and audit status in executive-ready formats for Board Audit Committee reporting.
  • Preferred: CISA or CRISC certification; experience in critical infrastructure, data center, energy, or digital asset environments; exposure to OT/ICS risk environments.


Compensation and Benefits 

  • Competitive Salary: Base range (commensurate with experience) + bonus + sign-on equity grant. 
  • Long-Term Growth: Eligible to participate in Riot’s equity incentive programs and share in the success you help build. 
  • 401(k) Retirement Plan: Incudes a generous company match. 
  • Comprehensive Health Coverage: Multiple medical plan options, including 100% company-paid plans. 
  • Wellness & Lifestyle Perks: Enjoy free gym memberships, pet insurance, childcare discounts, and more to support your life both in and out of work. 


Riot is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.

Similar Jobs at Riot Platforms, Inc.

Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Energy • Infrastructure as a Service (IaaS)
Leads global category strategy, strategic sourcing, supplier development, negotiations, and supply-chain resilience for data center cooling and mechanical infrastructure. Manages substantial spend across chillers, CRAHs, AHUs, liquid cooling, and containment systems. Partners with engineering, operations, and construction teams to align technology roadmaps, secure capacity, optimize total cost, mitigate risks, and support global data center deployment. Monitors commodity markets, refrigerant regulations, supplier capacity, and geopolitical constraints while managing executive-level OEM relationships.
Top Skills: Air Handling Units (Ahus)ChillersComputer Room Air Handlers (Crahs)Containment SystemsCoolant Distribution Units (Cdus)Cooling TowersDirect-To-Chip Liquid CoolingHvacLong-Term Agreements (Ltas)Master Purchasing Agreements (Msas)Service-Level Agreements (Slas)
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Energy • Infrastructure as a Service (IaaS)
Leads global category strategy, strategic sourcing, supplier development, and supply-chain resilience for data center electrical infrastructure. Manages major HV, MV, and LV equipment spend; negotiates capacity reservations and complex commercial agreements; develops Tier-1 supplier relationships; mitigates long-lead and single-source risks; and aligns electrical equipment strategies with engineering, utilities, construction, grid requirements, and AI-driven data center expansion.
Top Skills: Backup Diesel GeneratorsBusway SystemsHigh Voltage (Hv)IecIeeeLow Voltage (Lv)Medium Voltage (Mv)NfpaPower Distribution Units (Pdus)SwitchgearTransformersUninterruptible Power Supplies (Ups)Utility Substations
8 Days Ago
Remote
Senior level
Senior level
Artificial Intelligence • Cloud • Information Technology • Energy • Infrastructure as a Service (IaaS)
Owns the operating model connecting data center asset activity in Nuvolo with fixed asset records in NetSuite. Designs processes, data standards, workflows, integrations, controls, reconciliations, reporting, and exception management. Partners with asset management, accounting, IT, and system owners to ensure asset additions, replacements, transfers, retirements, disposals, and maintenance events are properly documented and routed for accounting review.
Top Skills: CmmsErpMaximoNetSuiteNuvoloServicenow EamSoxTririga

What you need to know about the Edinburgh Tech Scene

From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account