hero

Companies you'll love to work for

companies
Jobs

Security GRC Intern (Summer 2026)

Gemini

Gemini

New York, NY, USA
USD 50-50 / hour
Posted on Dec 20, 2025

About the Company

Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future. We envision a world where crypto reshapes the global financial system, internet, and money to create greater choice, independence, and opportunity for all — bridging traditional finance with the emerging cryptoeconomy in a way that is more open, fair, and secure. As a publicly traded company, Gemini is poised to accelerate this vision with greater scale, reach, and impact.

The Department: Security

In the emerging industry of digital assets, there is nothing more important than trust. The Gemini security team forms the backbone of trust. In fact, Gemini’s very first hires were security specialists and we continue to tackle unique challenges in the crypto space. Our team ensures that our customers, clients, and employees are safe, secure, and supported.

The Role: Security GRC Intern

Gemini has an exciting opportunity for a Security Governance Risk and Compliance (“GRC”) Intern specializing in Security Risk Management and Third Party Risk Management. We’re searching for a motivated and detail-oriented student with an interest in risk management who is a self-starter. In this role, you will play a key part in our security risk management and vendor security risk programs. You will assist in identifying, assessing, monitoring, and documenting risks across the organization and learn how vendors comply with security standards and best practices. You will also support the GRC team by contributing to governance and compliance projects and audits.

This will be a 12-week summer internship program with 3 days a week in person at our San Francisco, CA or New York City, NY office.

Responsibilities:

  • Assist in Identifying, evaluating, documenting, and communicating security risks across the organization, ensuring continuous monitoring and management of these risks.
  • Collaborate with internal stakeholders to observe and learn about risk remediation strategies and assess any residual risks that may remain.
  • Support the team in conducting annual security risk assessments, aligned with the NIST Cybersecurity Framework (NIST CSF).
  • Participate in supervised Targeted Risk Assessment (TRA) in compliance with PCI DSS and other risk assessment projects.
  • Help conduct comprehensive vendor security risk assessments, and support the team in providing recommendations for contractual security provisions.
  • Participate in supervised external security audits and assist in providing risk related evidence.
  • Contribute ideas and assist in projects to further advance the GRC programs.
  • Support management in identifying potential areas of concern with suggested mitigation strategies.
  • Help review and update security policies and standards, ensuring they remain current and effective in addressing evolving threats and regulatory requirements.

Qualifications:

  • Currently enrolled in a Bachelor’s, Associate’s or Master’s degree program in a relevant field (e.g., Cybersecurity, Information Security, Computer Science, Business, or related discipline).
  • Strong analytical and creative problem solving skills.
  • Strong interpersonal skills to interact with team members, auditors, and stakeholders.
  • Strong organization skills to prioritize work and balance assigned projects.
  • Ability to work independently and as part of a broader team.
  • Exposure to, and interested in learning about risk management lifecycle: risk identification, assessment, remediation and monitoring preferred.
  • Understanding of security controls and third party security risk management.
  • Familiarity and understanding with key security best practices concepts and standards preferred (e.g., OWASP top 10, NICS CSF).
  • Knowledge of compliance and security standards such as SOC 2 Type II, ISO 27001, PCI DSS preferred.

Pay Rate: The hourly pay rate for this role is $50/hour in the State of New York, the State of California and the State of Washington. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

In the United States, we offer a hybrid work approach at our hub offices, balancing the benefits of in-person collaboration with the flexibility of remote work. Expectations may vary by location and role, so candidates are encouraged to connect with their recruiter to learn more about the specific policy for the role. Employees who do not live near one of our hubs are part of our remote workforce.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.

#LI-GR1