Nifty Gateway Studio
Senior Associate, Security GRC (Cyber)
Nifty Gateway Studio, San Francisco, California, United States, 94199
Senior Associate, Security GRC (Cyber) – Gemini
Join our cybersecurity team in a technical GRC role that blends security engineering with governance and risk to mature Gemini’s security controls.
About The Company Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014. It offers a wide range of secure crypto products and services to individuals and institutions in over 70 countries. Gemini’s mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future.
The Department SEC Governance, Risk & Compliance
Location San Francisco, CA or New York City, NY (in‑person attendance twice a week)
Responsibilities
Perform technical security reviews and assessments for cloud architectures, Kubernetes and containers, serverless, network controls, and IAM. Apply CIS Benchmarks and vendor best practices. Produce clear remediation plans and track closure.
Build and support API-based integrations across GRC, cloud, and identity platforms (AWS, Azure, Okta, Atlassian). Use REST, GraphQL, webhooks, OAuth, and service accounts.
Lead threat modeling and design reviews for infrastructure, applications, and services. Document risks and compensating controls.
Develop continuous control monitoring and evidence pipelines. Collect, normalize, and map evidence to ISO 27001, SOC 2, PCI DSS, NIST CSF, and ISO 22301 requirements.
Drive zero‑trust improvements across identity, device posture, network segmentation, and service‑to‑service authentication.
Prepare for audits and regulatory requests using automated evidence, inventories, and dashboards. Reduce manual work through automation and self‑service.
Own and drive workstreams across security governance (e.g., entitlement reviews, access management, vendor security, cyber risk, software compliance).
Assess and lead cybersecurity projects across cloud security, container security, and infrastructure hardening.
Drive cybersecurity transformation initiatives including implementation of modern security architectures, DevSecOps practices, and zero‑trust frameworks.
Collaborate with DevOps and engineering teams to embed security into CI/CD pipelines, container orchestration platforms (e.g., Kubernetes), and cloud‑native services.
Advise technical and business teams on secure configurations, emerging threats, and remediation strategies.
Minimum Qualifications
Bachelor’s degree in computer science, information security, engineering, or related field, or equivalent experience.
5+ years in cybersecurity with hands‑on security engineering in cloud, automation, or platform security.
Proficiency in basic coding (Python or JavaScript and shell scripting). Ability to write API clients, parse JSON, and orchestrate workflows in n8n or similar tools (Tines, StackStorm, Airflow, Zapier).
Experience building and operating REST or GraphQL integrations. Familiarity with OAuth, service principals, and webhooks.
Working knowledge of AWS, GCP, and Azure. Comfortable with IAM, networking, KMS, logging and monitoring, and cloud‑native security services.
Experience with containers and Kubernetes. Familiar with Helm, admission controllers, and runtime security.
Experience with infrastructure as code (Terraform or CloudFormation). Ability to review plans and implement guardrails.
Applied knowledge of CIS Benchmarks for AWS, GCP, Linux, and Kubernetes. Ability to run benchmark tooling and harden systems against findings.
Strong understanding of enterprise security practices, including DevSecOps, zero‑trust, and security automation.
At least one core security certification, such as CISSP, CCSP, AWS Security Specialty, GCP Professional Cloud Security Engineer, or OSCP.
Strong writing, communication, and presentation skills across technical and business audiences. Strong stakeholder management. Highly organized.
Preferred Qualifications
Big 4 or consulting experience supporting cybersecurity programs.
Experience leading or supporting enterprise security modernization and cloud guardrails.
Experience with policy‑as‑code and platform guardrails (OPA or Rego, AWS Config, Azure Policy, Google Organization Policy).
Experience with CI systems and embedding security checks (GitHub Actions, GitLab CI, CircleCI, Jenkins).
Experience with evidence automation and GRC tooling (AuditBoard, Vanta, Drata, Secureframe, or in‑house).
Experience with CSPM and CWPP platforms and SIEM or EDR (Wiz, Prisma Cloud, Aqua, Falco, Splunk, Elastic, Chronicle, Datadog, Panther).
Ability to build dashboards and basic analytics for control monitoring. SQL or notebook‑based analysis is a plus.
Benefits
Competitive starting salary
A discretionary annual bonus
Long‑term incentive in the form of a new‑hire equity grant
Comprehensive health plans
401K with company matching
Paid parental leave
Flexible time off
Salary Range The base salary range for this role is $112,000 – $160,000 in New York, California, and Washington. This range does not include discretionary bonus or equity. Compensation is based on skillset, experience, job scope, and market data.
In the United States, we offer a hybrid work approach at our hub offices, balancing the benefits of in‑person collaboration with the flexibility of remote work. Expectations may vary by location and role; candidates are encouraged to connect with a recruiter for specifics. Employees who do not live near a hub are part of our remote workforce.
At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or veteran status. Gemini is proud to be an equal‑opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.
#J-18808-Ljbffr
Join our cybersecurity team in a technical GRC role that blends security engineering with governance and risk to mature Gemini’s security controls.
About The Company Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014. It offers a wide range of secure crypto products and services to individuals and institutions in over 70 countries. Gemini’s mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future.
The Department SEC Governance, Risk & Compliance
Location San Francisco, CA or New York City, NY (in‑person attendance twice a week)
Responsibilities
Perform technical security reviews and assessments for cloud architectures, Kubernetes and containers, serverless, network controls, and IAM. Apply CIS Benchmarks and vendor best practices. Produce clear remediation plans and track closure.
Build and support API-based integrations across GRC, cloud, and identity platforms (AWS, Azure, Okta, Atlassian). Use REST, GraphQL, webhooks, OAuth, and service accounts.
Lead threat modeling and design reviews for infrastructure, applications, and services. Document risks and compensating controls.
Develop continuous control monitoring and evidence pipelines. Collect, normalize, and map evidence to ISO 27001, SOC 2, PCI DSS, NIST CSF, and ISO 22301 requirements.
Drive zero‑trust improvements across identity, device posture, network segmentation, and service‑to‑service authentication.
Prepare for audits and regulatory requests using automated evidence, inventories, and dashboards. Reduce manual work through automation and self‑service.
Own and drive workstreams across security governance (e.g., entitlement reviews, access management, vendor security, cyber risk, software compliance).
Assess and lead cybersecurity projects across cloud security, container security, and infrastructure hardening.
Drive cybersecurity transformation initiatives including implementation of modern security architectures, DevSecOps practices, and zero‑trust frameworks.
Collaborate with DevOps and engineering teams to embed security into CI/CD pipelines, container orchestration platforms (e.g., Kubernetes), and cloud‑native services.
Advise technical and business teams on secure configurations, emerging threats, and remediation strategies.
Minimum Qualifications
Bachelor’s degree in computer science, information security, engineering, or related field, or equivalent experience.
5+ years in cybersecurity with hands‑on security engineering in cloud, automation, or platform security.
Proficiency in basic coding (Python or JavaScript and shell scripting). Ability to write API clients, parse JSON, and orchestrate workflows in n8n or similar tools (Tines, StackStorm, Airflow, Zapier).
Experience building and operating REST or GraphQL integrations. Familiarity with OAuth, service principals, and webhooks.
Working knowledge of AWS, GCP, and Azure. Comfortable with IAM, networking, KMS, logging and monitoring, and cloud‑native security services.
Experience with containers and Kubernetes. Familiar with Helm, admission controllers, and runtime security.
Experience with infrastructure as code (Terraform or CloudFormation). Ability to review plans and implement guardrails.
Applied knowledge of CIS Benchmarks for AWS, GCP, Linux, and Kubernetes. Ability to run benchmark tooling and harden systems against findings.
Strong understanding of enterprise security practices, including DevSecOps, zero‑trust, and security automation.
At least one core security certification, such as CISSP, CCSP, AWS Security Specialty, GCP Professional Cloud Security Engineer, or OSCP.
Strong writing, communication, and presentation skills across technical and business audiences. Strong stakeholder management. Highly organized.
Preferred Qualifications
Big 4 or consulting experience supporting cybersecurity programs.
Experience leading or supporting enterprise security modernization and cloud guardrails.
Experience with policy‑as‑code and platform guardrails (OPA or Rego, AWS Config, Azure Policy, Google Organization Policy).
Experience with CI systems and embedding security checks (GitHub Actions, GitLab CI, CircleCI, Jenkins).
Experience with evidence automation and GRC tooling (AuditBoard, Vanta, Drata, Secureframe, or in‑house).
Experience with CSPM and CWPP platforms and SIEM or EDR (Wiz, Prisma Cloud, Aqua, Falco, Splunk, Elastic, Chronicle, Datadog, Panther).
Ability to build dashboards and basic analytics for control monitoring. SQL or notebook‑based analysis is a plus.
Benefits
Competitive starting salary
A discretionary annual bonus
Long‑term incentive in the form of a new‑hire equity grant
Comprehensive health plans
401K with company matching
Paid parental leave
Flexible time off
Salary Range The base salary range for this role is $112,000 – $160,000 in New York, California, and Washington. This range does not include discretionary bonus or equity. Compensation is based on skillset, experience, job scope, and market data.
In the United States, we offer a hybrid work approach at our hub offices, balancing the benefits of in‑person collaboration with the flexibility of remote work. Expectations may vary by location and role; candidates are encouraged to connect with a recruiter for specifics. Employees who do not live near a hub are part of our remote workforce.
At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or veteran status. Gemini is proud to be an equal‑opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.
#J-18808-Ljbffr