Riot Platforms, Inc. Logo

Riot Platforms, Inc.

Director, Compliance

Posted 39 Minutes Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Expert/Leader
Remote
Hiring Remotely in United States
Expert/Leader
Owns Riot’s unified compliance controls framework, including ISO 27001, SOC 2, NIST CSF, and SOX ITGC mapping. Leads control testing, evidence collection, issues and remediation management, GRC platform selection and administration, and compliance automation. Partners with IT, Security Engineering, mining sites, and data centers to implement and evidence enterprise and operational controls. The role requires hands-on platform configuration, integrations, automated evidence pipelines, and year-round audit readiness.
The summary above was generated by AI

About Riot Platforms

Riot’s (NASDAQ: RIOT) vision is to be the world’s most trusted platform for powering and building digital infrastructure. Riot’s mission is to empower the future of digital infrastructure by positively impacting the sectors, networks, and communities that we touch. We believe that the combination of an innovative spirit and strong community partnership allows us to achieve best-in-class execution and create successful outcomes.


Who we are

At Riot, we’re building the future of digital infrastructure. Our team members have unparalleled opportunities to work on groundbreaking initiatives. Through technical excellence and strategic execution, Riot has positioned itself as a leader in the industry driving advancements that continue to set new benchmarks in digital infrastructure. 


We are trailblazers. Problem solvers. People who thrive in fast paced environments, communicate clearly, and bring relentless focus to efficiency and execution.

About the role

The Director, Compliance owns the engine that keeps Riot audit-ready year-round: the controls framework, the testing program, the issues and remediation lifecycle, and the GRC platform that ties all of it together. Compliance designs the controls that prove that policies are working — and builds the automation infrastructure that makes proving it sustainable at scale.

This pillar is intentionally scoped to execute, not to govern or audit. Compliance owns the unified control library — design, mapping to ISO 27001 Annex A, SOC 2 Trust Services Criteria, NIST CSF, and SOX ITGC — along with owner assignment and testing cadences. Compliance owns the testing program across design adequacy and operating effectiveness. Compliance owns the issues and remediation lifecycle. And Compliance owns the GRC platform: selection, implementation, configuration, integrations, and ongoing administration.

You will report to the Senior Director, GRC and partner directly with IT and Security Engineering as the primary technical counterparts for control evidence, cloud configuration reviews, and platform integrations. In critical operations, you will work with mining site and data center teams to ensure operational controls — physical access, environmental monitoring, asset management — are designed, tested, and evidenced to the same standard as enterprise IT controls.

This role has one non-negotiable: you must be an operator, not just a strategist. In Year 1 you will personally administer the GRC platform, configure the control library, build integrations, and drive the automation that eliminates manual audit prep.


What you'll do

  • Design and build the Riot unified controls framework: map the control universe to ISO 27001 Annex A, SOC 2 Trust Services Criteria, NIST CSF, and SOX ITGC; assign control owners; define testing frequencies; and rationalize overlapping framework requirements into a single, audit-efficient control set.
  • Own the ISO 27001:2022 controls implementation track — designing, implementing, and evidencing all Annex A controls required for certification, on a schedule with no buffer.
  • Execute the control testing program across all in-scope frameworks: design adequacy and operating effectiveness testing, evidence documentation to SOC 2 and ISO 27001 audit-quality standards, and a continuous testing calendar that eliminates point-in-time audit scrambles.
  • Lead GRC platform selection, implementation, and administration: evaluate vendors (ServiceNow GRC, Vanta, Drata, Hyperproof, OneTrust, or equivalent), build the business case, drive implementation to production, and own the platform as the system of record for all GRC controls, risks, and evidence.
  • Build and operate the issues and remediation lifecycle: intake all control failures and audit findings from across all pillars, assign ownership, track remediation progress, validate closure, and feed status into the POA&M program in coordination with the Director, Risk Management.
  • Drive compliance automation: identify manual, spreadsheet-based workflows and replace them with automated evidence collection, integrated dashboards, and real-time controls monitoring — integrating the GRC platform with Asana, identity providers, AWS/Azure, and operational source systems.
  • Engage mining site and data center teams to design, implement, test, and evidence operational controls (physical access, environmental monitoring, change management, asset management) to the same standard as enterprise IT controls.


What you'll bring

  • 8–12+ years of progressive GRC, IT audit, controls design, or compliance program experience, with hands-on GRC platform administration (required — not observer-level familiarity).
  • ISO 27001 Lead Implementer or Lead Auditor certification — required. The Director, Compliance owns the controls framework that underpins ISO 27001:2022 certification. A lead-level credential is the baseline, not a preference.
  • Demonstrated experience designing a controls framework mapped simultaneously to multiple standards (SOC 2, ISO 27001, NIST CSF, SOX ITGC) and rationalized to a unified, audit-efficient control set.
  • Direct experience executing control testing programs: design adequacy and operating effectiveness testing, evidence documentation to audit-quality standards, and reporting testing results to senior leadership.
  • Proven GRC platform experience as a power user or administrator — control library configuration, evidence mapping, workflow design, and integration with source systems (Asana, identity providers, AWS/Azure).
  • Strong automation and integration mindset: experience building automated evidence pipelines, dashboard reporting, or integrations between GRC platforms and operational systems.
  • Experience managing an issues and remediation lifecycle (POA&M): tracking, owner accountability, escalation, and closure validation across cross-functional control owners.
  • Technical fluency: comfortable evaluating AWS and Azure security configurations as control evidence; familiarity with API-based GRC integrations; light scripting (Python, SQL) or AI-assisted automation is a strong plus.
  • Preferred: CISA certification; experience in critical infrastructure, data center, or digital asset environments; experience with SOC 2 evidence preparation and auditor walkthrough facilitation.

Compensation and Benefits 

  • Competitive Salary: Base range (commensurate with experience) + bonus + sign-on equity grant. 
  • Long-Term Growth: Eligible to participate in Riot’s equity incentive programs and share in the success you help build. 
  • 401(k) Retirement Plan: Incudes a generous company match. 
  • Comprehensive Health Coverage: Multiple medical plan options, including 100% company-paid plans. 
  • Wellness & Lifestyle Perks: Enjoy free gym memberships, pet insurance, childcare discounts, and more to support your life both in and out of work. 


Riot is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.

HQ

Riot Platforms, Inc. Castle Rock, Colorado, USA Office

Riot Platforms, Inc. Castle Rock, CO Office

Located between Denver and Colorado Springs, Castle Rock draws a highly educated, technically skilled workforce with top schools and strong incomes. Nationally recognized for livability, it pairs metro access with a strong outdoor lifestyle.

Similar Jobs at Riot Platforms, Inc.

39 Minutes Ago
Remote
United States
Expert/Leader
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Energy • Infrastructure as a Service (IaaS)
Owns Riot’s risk management and GRC execution, including SOC 1 and SOC 2 audits, ISO 27001 certification readiness, SOX ITGC coordination, enterprise risk registers, KRI/KPI reporting, POA&M remediation, auditor relationships, and continuous audit readiness. The role partners with executives, Internal Audit, external auditors, mining sites, and data center leadership to identify, quantify, report, and remediate operational and technology risks.
Top Skills: Iso 27001:2022Nist 800-53Nist CsfOt/IcsSoc 1Soc 2 Type IiSox Itgc
39 Minutes Ago
Remote
United States
Expert/Leader
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Energy • Infrastructure as a Service (IaaS)
Build and own Riot’s governance program, including the ISO 27001:2022 documentation framework, enterprise policy library, regulatory horizon scanning, contracts management, third-party risk management, and framework mappings across SOC 2, SOX, NIST CSF, and applicable regulations. The role drives policy adoption, attestation, vendor due diligence, contract risk workflows, and alignment of site-level operational, physical security, and environmental policies.
Top Skills: DoraIso 27001:2022Nis2Nist CsfSoc 2Sox
2 Days Ago
Remote
United States
169K-208K Annually
Expert/Leader
169K-208K Annually
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Energy • Infrastructure as a Service (IaaS)
Leads global category strategy, strategic sourcing, supplier development, commercial negotiations, and supply-chain resiliency for hyperscale data-center cooling infrastructure. Manages substantial spend across chillers, CRAHs, AHUs, containment, liquid cooling, and related systems. Partners with engineering, operations, and construction teams; develops supplier capacity; mitigates supply risks; monitors commodity markets and refrigerant regulations; and presents recommendations to executive stakeholders.
Top Skills: Air Handling Units (Ahus)Capacity AgreementsChillersComputer Room Air Handlers (Crahs)Containment SystemsCoolant Distribution Units (Cdus)Cooling TowersHvacLiquid CoolingMaster Purchasing AgreementsService Level Agreements (Slas)

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account