Role overview
About the Company
Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future. We envision a world where crypto reshapes the global financial system, internet, and money to create greater choice, independence, and opportunity for all â bridging traditional finance with the emerging cryptoeconomy in a way that is more open, fair, and secure. As a publicly traded company, Gemini is poised to accelerate this vision with greater scale, reach, and impact.
The Department: Risk
What you'll work on
- Risk Assessment & Monitoring
- Execute the IT Risk Management Framework, including risk identification, analysis, and reporting.
- Conduct annual IT risk assessments, including RCSAs, targeted risk reviews, and new product/key initiative assessments.
- Maintain the IT risk register; ensure timely updates and accurate reporting of exposures.
- Perform post-mortem risk reviews for critical incidents and support operational loss reviews with ORM.
- Assist the Head of IT Risk in maintaining risk policies, standards, and procedures that align with Geminiâs enterprise risk management program and regulatory expectations (NYDFS, DFS, CFTC, DORA EU 2025).
- Partner with Internal Audit, IT, Security, and BCM to assess design and operating effectiveness of IT and cyber controls.
- Serve as a liaison between IT Risk and other functional areas, facilitating risk awareness and control adoption.
- Assist in the development of periodic risk dashboards and key risk indicators (KRIs).
What we're looking for
- Execute the IT Risk Management Framework, including risk identification, analysis, and reporting.
- Conduct annual IT risk assessments, including RCSAs, targeted risk reviews, and new product/key initiative assessments.
- Maintain the IT risk register; ensure timely updates and accurate reporting of exposures.
- Perform post-mortem risk reviews for critical incidents and support operational loss reviews with ORM.