Senior GRC Program Manager

Ripple
Luxembourg
Workplace: OnsiteFull timeFunction: Program & Project Management (PMO)Experience: 5+ yearsEducation: bachelorsSkills: ["Cross-functional collaboration","Technical documentation","Operational oversight","Incident response support"]

Lead governance, risk, and compliance program initiatives for Ripple’s information security function in Luxembourg. Own operational implementation of EU and Luxembourg security frameworks, including DORA, while managing outsourced ICT and security services and ensuring delivery against SLAs. Coordinate technical security controls, provide evidence for audits and regulatory exams, and partner with global engineering, compliance, finance, and product teams to strengthen operational resilience and customer trust.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ripple
Ripple
2 months ago

Senior GRC Program Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 12 hours agoStatus: Live

Job Summary

Lead governance, risk, and compliance program initiatives for Ripple’s information security function in Luxembourg. Own operational implementation of EU and Luxembourg security frameworks, including DORA, while managing outsourced ICT and security services and ensuring delivery against SLAs. Coordinate technical security controls, provide evidence for audits and regulatory exams, and partner with global engineering, compliance, finance, and product teams to strengthen operational resilience and customer trust.
Location: Luxembourg
Workplace: Onsite
Employment Type: Full time
Job Function: Program & Project Management (PMO)
Seniority: Mid level

Key Responsibilities

  • •Ensure operational implementation and maintenance of EU/Luxembourg security frameworks, including DORA.
  • •Manage day-to-day oversight of outsourced ICT and security services to meet local regulatory standards and SLAs.
  • •Coordinate implementation of technical security controls across infrastructure and application environments in line with internal controls and regulatory guidelines (e.g., EBA, ESMA, CSSF).
  • •Access systems to pull technical evidence (e.g., logs and access reports) supporting monitoring, incident response, and compliance.
  • •Serve as subject matter expert for internal audits, customer audits, and regulatory exams, and support security due diligence questionnaires.

Pay and Benefits

Perks:Learning BudgetEquityHealth InsuranceRetirementParental LeaveMobile StipendWellness Stipend

Key Requirements

  • •5+ years of experience in information security infrastructure, preferably in a highly regulated industry.
  • •Solid working knowledge of DORA operational requirements, including resilience testing, ICT third-party management, and incident response.
  • •Familiarity with EU regulatory frameworks, including MiCA and related EBA and ESMA technical standards.
  • •Proficiency with information security frameworks such as ISO 27001, SOC 2, and NIST.
  • •English proficiency required; French proficiency is desirable.
Experience:5+ yearsHighly regulated industryLuxembourg financial servicesCryptoDigital assetsGRC
Education:Bachelor's
Skills:Cross-functional collaborationTechnical documentationOperational oversightIncident response support
Certifications:CISSPCISAAWS Certified SecurityPMP
Languages:EnglishFrench
Tech Stack:Digital Operational Resilience Act (DORA)MiCAEBAESMACSSFISO 27001SOC 2NISTJiraConfluenceJupiterOneOktaAWSTines

Company Brief

Ripple
Builds blockchain-based payment and liquidity infrastructure for financial institutions and enterprises. Its products support cross-border payments, crypto liquidity, and digital asset settlement.
Industry: Fintech Infrastructure
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: San Francisco, United States
Founded: 2012
WebsiteLinkedIn