Security GRC Intern (Summer 2025)
Seattle, Washington
Gemini
Gemini makes crypto simple. Find, Trade and Buy over 80 coins including bitcoin on the best cryptocurrency platform. Start trading crypto here.About the Company
Gemini is a global crypto and Web3 platform founded by Tyler Winklevoss and Cameron Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.
Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we help you buy, sell, and store your bitcoin and cryptocurrency.
At Gemini, our mission is to unlock the next era of financial, creative, and personal freedom.
The Department: Security Governance Risk and Compliance
The Role: Security GRC Intern
Gemini has an exciting opportunity for a Security Governance Risk and Compliance (“GRC”) Intern specializing in Security Risk Management and Third Party Risk Management. We’re searching for a motivated and detail-oriented student with an interest in risk management who is a self-starter. In this role, you will play a key part in our security risk management and vendor security risk programs. You will assist in identifying, assessing, monitoring, and documenting risks across the organization and learn how vendors comply with security standards and best practices. You will also support the GRC team by contributing to governance and compliance projects and audits.
This will be a hybrid, 10-week summer internship program starting the second week of June with 3 days a week in office.
Responsibilities:
- Assist in identifying, evaluating, documenting, and communicating security risks across the organization, ensuring continuous monitoring and management of these risks.
- Collaborate with internal stakeholders to observe and learn about risk remediation strategies and assess any residual risks that may remain.
- Support the team in conducting annual security risk assessments, aligned with the NIST Cybersecurity Framework (NIST CSF).
- Participate in supervised Targeted Risk Assessment (TRA) in compliance with PCI DSS and other risk assessment projects.
- Help conduct comprehensive vendor security risk assessments, and support the team in providing recommendations for contractual security provisions.
- Participate in supervised external security audits and assist in providing risk related evidence.
- Contribute ideas and assist in projects to further advance the GRC programs.
- Support management in identifying potential areas of concern with suggested mitigation strategies.
- Help review and update security policies and standards, ensuring they remain current and effective in addressing evolving threats and regulatory requirements.
Qualifications:
- Currently enrolled in a Bachelor’s or Master’s degree program in a relevant field (e.g., Cybersecurity, Information Security, Computer Science, Business, or related discipline).
- Strong analytical and creative problem solving skills.
- Strong interpersonal skills to interact with team members, auditors, and stakeholders.
- Strong organization skills to prioritize work and balance assigned projects.
- Ability to work independently and as part of a broader team.
- Exposure to, and interested in learning about risk management lifecycle: risk identification, assessment, remediation and monitoring preferred.
- Understanding of security controls and third party security risk management.
- Familiarity and understanding with key security best practices concepts and standards preferred (e.g., OWASP top 10, NICS CSF).
- Knowledge of compliance and security standards such as SOC 2 Type II, ISO 27001, PCI DSS preferred.
Pay Rate: The hourly pay rate for this role is $34/hour in the State of New York, the State of California and the State of Washington. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.
At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.
#LI-GR1
Tags: Audits Compliance Computer Science Crypto Governance ISO 27001 Monitoring NIST OWASP PCI DSS Risk assessment Risk management SOC SOC 2
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.