Senior Director of Governance, Risk and Compliance

Ripple Ripple · Fintech · San Francisco, CA +1 · Engineering

This role leads the Governance, Risk, and Compliance (GRC) strategy for Ripple, focusing on building an engineering-first GRC function. Key responsibilities include defining the GRC roadmap, pioneering AI and automation within GRC processes (e.g., continuous monitoring, risk assessments, policy management), managing a GRC team, and overseeing integrated GRC programs covering ERM, compliance, BCDR, and internal audit. The role also involves driving global regulatory compliance, maintaining certifications (SOC 2, ISO 27001), managing third-party risk, and fostering a security-first culture. Experience in crypto, blockchain, or FinTech is preferred, with a strong emphasis on building and scaling GRC programs.

What you'd actually do

  1. Set the strategic vision and multi-year roadmap for GRC, ensuring programs scale with Ripple's growth and evolving regulatory landscape.
  2. Pioneer the use of AI and automation across the GRC function, from continuous control monitoring and automated evidence collection to AI-assisted risk assessments and policy management, reducing manual overhead, accelerating audit readiness, and shifting the program from reactive compliance to predictive risk intelligence.
  3. Lead, mentor, and grow a team of GRC Program Managers and Engineers, fostering a culture of rigorous thinking, continuous improvement, and cross-functional collaboration.
  4. Design and operate an integrated GRC program spanning Enterprise Risk Management (ERM), Compliance, BCDR, and Internal Audit, with a strong emphasis on data sharing and cross-functional alignment.
  5. Own and advance Ripple's regulatory compliance posture across global jurisdictions, including NYDFS, MAS, DFSA, CBI, FSA, DORA, CSSF, GDPR, LGPD, and NIST.

Skills

Required

  • 15+ years of experience in information security GRC
  • 5+ years in a senior leadership role
  • Deep expertise in global regulatory frameworks
  • Proven experience leading cross-functional GRC programs
  • Strong track record of building automated, self-service evidence collection and audit readiness programs
  • Experience operating a Third-Party Risk Management program at scale
  • Hands-on knowledge of vendor security assessments and supply chain risk
  • Hands-on experience with GRC platforms
  • Executive-level communication skills
  • ability to translate complex risk and compliance concepts into clear, actionable narratives
  • Demonstrated ability to lead and develop geographically distributed, cross-functional teams

Nice to have

  • preferably in crypto, blockchain, or FinTech
  • Experience integrating an acquired entity's security function serves as a significant differentiator
  • comfort driving tooling strategy
  • Experience with crypto, digital asset, or stablecoin compliance (e.g., SOX attestation for stablecoin reserves, digital asset risk frameworks) is a strong plus
  • A builder's mindset: you are drawn to ambiguity, energized by building structure where none exists, and motivated by measurable outcomes.

What the JD emphasized

  • AI and automation across the GRC function
  • AI-assisted risk assessments
  • continuous control monitoring
  • automated evidence collection
  • policy management
  • predictive risk intelligence
  • global regulatory frameworks
  • NYDFS
  • MAS
  • DFSA
  • DORA
  • GDPR
  • SOC 2
  • ISO 27001
  • NIST CSF
  • SOX/ITGC
  • integrated GRC program
  • Enterprise Risk Management (ERM)
  • Compliance
  • BCDR
  • Internal Audit
  • data-driven, systems-first mindset
  • automated, self-service evidence collection
  • audit readiness programs
  • Third-Party Risk Management program
  • vendor security assessments
  • supply chain risk
  • GRC platforms
  • tooling strategy
  • Executive-level communication skills
  • crypto, digital asset, or stablecoin compliance
  • SOX attestation for stablecoin reserves
  • digital asset risk frameworks
  • building and scaling GRC programs from the ground up
  • high-growth or M&A environment
  • integrating an acquired entity's security function
  • builder's mindset