Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
About The Company
Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future. We envision a world where crypto reshapes the global financial system, internet, and money to create greater choice, independence, and opportunity for all — bridging traditional finance with the emerging cryptoeconomy in a way that is more open, fair, and secure. As a publicly traded company, Gemini is poised to accelerate this vision with greater scale, reach, and impact.
The Department: Security
In the emerging industry of digital assets, there is nothing more important than trust. The Gemini security team forms the backbone of trust. In fact, Gemini’s very first hires were security specialists and we continue to tackle unique challenges in the crypto space. Our team ensures that our customers, clients, and employees are safe, secure, and supported.
The Role: Security GRC Intern
Gemini has an exciting opportunity for a Security GRC Intern specializing in Security Risk Management and Third Party Risk Management. We’re searching for a motivated and detail-oriented student with an interest in risk management who is a self-starter. In this role, you will play a key part in our security risk management and vendor security risk programs. You will assist in identifying, assessing, monitoring, and documenting risks across the organization and learn how vendors comply with security standards and best practices. You will also support the GRC team by contributing to governance and compliance projects and audits.
This will be a 12-week summer internship program with 3 days a week in person at our San Francisco, CA or New York City, NY office.
Responsibilities
- Assist in Identifying, evaluating, documenting, and communicating security risks across the organization, ensuring continuous monitoring and management of these risks.
- Collaborate with internal stakeholders to observe and learn about risk remediation strategies and assess any residual risks that may remain.
- Support the team in conducting annual security risk assessments, aligned with the NIST Cybersecurity Framework (NIST CSF).
- Participate in supervised Targeted Risk Assessment (TRA) in compliance with PCI DSS and other risk assessment projects.
- Help conduct comprehensive vendor security risk assessments, and support the team in providing recommendations for contractual security provisions.
- Participate in supervised external security audits and assist in providing risk related evidence.
- Contribute ideas and assist in projects to further advance the GRC programs.
- Support management in identifying potential areas of concern with suggested mitigation strategies.
- Help review and update security policies and standards, ensuring they remain current and effective in addressing evolving threats and regulatory requirements.
Qualifications
- Currently enrolled in a Bachelor’s, Associate’s or Master’s degree program in a relevant field (e.g., Cybersecurity, Information Security, Computer Science, Business, or related discipline).
- Strong analytical and creative problem solving skills.
- Strong interpersonal skills to interact with team members, auditors, and stakeholders.
- Strong organization skills to prioritize work and balance assigned projects.
- Ability to work independently and as part of a broader team.
- Exposure to, and interested in learning about risk management lifecycle: risk identification, assessment, remediation and monitoring preferred.
- Understanding of security controls and third party security risk management.
- Familiarity and understanding with key security best practices concepts and standards preferred (e.g., OWASP top 10, NICS CSF).
- Knowledge of compliance and security standards such as SOC 2 Type II, ISO 27001, PCI DSS preferred.
Key skills/competency
- Security Risk Management
- Third-Party Risk Management
- NIST Cybersecurity Framework
- PCI DSS Compliance
- Security Audits
- Policy Development
- Information Security
- GRC Programs
- Stakeholder Collaboration
- Analytical Problem Solving
How to Get Hired at Gemini
- Research Gemini's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor. Understand their commitment to trust in the crypto industry.
- Tailor your resume: Customize your resume to highlight analytical skills, problem-solving, and any exposure to risk management, NIST CSF, or PCI DSS. Quantify achievements where possible.
- Show GRC interest: Emphasize your genuine interest in security governance, risk management, and compliance. Demonstrate self-starter qualities and attention to detail specific to GRC.
- Prepare for technical questions: Review fundamental concepts of cybersecurity, risk identification, assessment, and common frameworks like OWASP Top 10, NIST CSF, and compliance standards such as SOC 2 and ISO 27001 for Gemini.
- Highlight collaboration and communication: Be ready to discuss experiences working independently and in teams, showcasing strong interpersonal skills crucial for stakeholder and auditor interaction at Gemini.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background