Security GRC Intern (Summer 2026) jobs in United States
cer-icon
Apply on Employer Site
company-logo

Nifty Gateway Studio · 1 month ago

Security GRC Intern (Summer 2026)

Gemini is a global crypto and Web3 platform that provides secure crypto products and services. The Security GRC Intern will assist in security risk management and vendor security risk programs, focusing on identifying, assessing, and documenting risks across the organization.

Media and Entertainment

Responsibilities

Assist in Identifying, evaluating, documenting, and communicating security risks across the organization, ensuring continuous monitoring and management of these risks
Collaborate with internal stakeholders to observe and learn about risk remediation strategies and assess any residual risks that may remain
Support the team in conducting annual security risk assessments, aligned with the NIST Cybersecurity Framework (NIST CSF)
Participate in supervised Targeted Risk Assessment (TRA) in compliance with PCI DSS and other risk assessment projects
Help conduct comprehensive vendor security risk assessments, and support the team in providing recommendations for contractual security provisions
Participate in supervised external security audits and assist in providing risk related evidence
Contribute ideas and assist in projects to further advance the GRC programs
Support management in identifying potential areas of concern with suggested mitigation strategies
Help review and update security policies and standards, ensuring they remain current and effective in addressing evolving threats and regulatory requirements

Qualification

Risk ManagementSecurity ComplianceSecurity StandardsAnalytical SkillsInterpersonal SkillsOrganizational SkillsUnderstanding Security ControlsOWASPSOC 2ISO 27001PCI DSSTeam CollaborationCreative Problem SolvingIndependent Work

Required

Currently enrolled in a Bachelor's, Associate's or Master's degree program in a relevant field (e.g., Cybersecurity, Information Security, Computer Science, Business, or related discipline)
Strong analytical and creative problem solving skills
Strong interpersonal skills to interact with team members, auditors, and stakeholders
Strong organization skills to prioritize work and balance assigned projects
Ability to work independently and as part of a broader team

Preferred

Exposure to, and interested in learning about risk management lifecycle: risk identification, assessment, remediation and monitoring
Understanding of security controls and third party security risk management
Familiarity and understanding with key security best practices concepts and standards (e.g., OWASP top 10, NICS CSF)
Knowledge of compliance and security standards such as SOC 2 Type II, ISO 27001, PCI DSS

Company

Nifty Gateway Studio

twittertwittertwitter
company-logo
A digital production studio working with creators and brands to develop immersive social entertainment and creative experiences onchain.