Назад
10 дней назад

Security Assurance & GRC Lead (AI)

150 000 - 190 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Assurance & GRC Lead (AI): Owns customer assurance and compliance programs across SOC 2, ISO 27001, privacy, and enterprise requirements with an accent on building scalable GRC systems and translating AI security and data-handling practices for customers. Focus on leading security reviews, prioritizing enterprise blockers, automating assurance workflows, and feeding customer requirements into product security decisions.

Location: Hybrid in San Francisco or New York, United States

Salary: $150,000–$190,000 per year, plus equity

Company

Wispr Flow is an AI research and product company building voice interfaces for computing, including Flow and Notetaker.

What you will do

  • Own the GRC roadmap across SOC 2 Type II, ISO 27001, privacy, risk management, and enterprise customer requirements.
  • Lead customer security reviews, questionnaires, due-diligence requests, vendor assessments, RFP security sections, and high-priority assurance escalations.
  • Partner with Sales on strategic deals and improve the Trust Center, standard responses, and security narratives.
  • Standardize and automate assurance workflows while maintaining accurate records in Drata, SafeBase, and Linear.
  • Translate security-review patterns into product requirements covering SSO/SCIM, audit logs, permissions, retention, data residency, and AI data handling.
  • Coordinate audit evidence, controls, policies, remediation, risk registers, vendor inventories, compliance deadlines, and customer-facing incident communications.

Requirements

  • Strong experience in GRC, security compliance, customer assurance, IT audit, or risk management.
  • Experience leading customer security reviews and explaining security posture to technical and non-technical audiences.
  • Working knowledge of SOC 2, ISO 27001, or comparable security and compliance frameworks.
  • Strong judgment, written and verbal communication, project-management discipline, and ability to drive cross-functional work to completion.
  • Ability to work across Engineering, Product, IT, Legal, Sales, Customer Success, and Support while improving operational processes.
  • Hybrid work in San Francisco or New York is required.

Nice to have

  • Startup or growth-stage SaaS experience supporting enterprise customers.
  • Experience scaling compliance or customer assurance programs and using Drata, Vanta, SafeBase, or similar tools.
  • Knowledge of cloud security, access control, encryption, logging, vulnerability management, incident response, and SaaS architecture.
  • Experience with AI security and privacy, GDPR, CCPA, HIPAA, data residency, vendor risk, or compliance automations.
  • Security+, CISA, CGRC, ISO 27001 Lead Implementer, or similar certification.

Culture & Benefits

  • Equity on employee-friendly terms, including extended exercise windows and a combination of ISOs and RSUs.
  • Visa sponsorship is available for H1B, O1, EB1, L1, STEM OPT, and other cases, subject to role and offer-specific review.
  • Work with a cross-functional, talent-dense team building AI products intended for everyday use.
  • Accessible interview accommodations are available upon request.

Hiring process

  • The process is designed to be fair and accessible, with accommodations or adjustments available when needed.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →