Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Assurance & GRC Lead (AI): Owns customer assurance and compliance programs across SOC 2, ISO 27001, privacy, and enterprise requirements with an accent on building scalable GRC systems and translating AI security and data-handling practices for customers. Focus on leading security reviews, prioritizing enterprise blockers, automating assurance workflows, and feeding customer requirements into product security decisions.
Location: Hybrid in San Francisco or New York, United States
Salary: $150,000–$190,000 per year, plus equity
Company
Wispr Flow is an AI research and product company building voice interfaces for computing, including Flow and Notetaker.
What you will do
- Own the GRC roadmap across SOC 2 Type II, ISO 27001, privacy, risk management, and enterprise customer requirements.
- Lead customer security reviews, questionnaires, due-diligence requests, vendor assessments, RFP security sections, and high-priority assurance escalations.
- Partner with Sales on strategic deals and improve the Trust Center, standard responses, and security narratives.
- Standardize and automate assurance workflows while maintaining accurate records in Drata, SafeBase, and Linear.
- Translate security-review patterns into product requirements covering SSO/SCIM, audit logs, permissions, retention, data residency, and AI data handling.
- Coordinate audit evidence, controls, policies, remediation, risk registers, vendor inventories, compliance deadlines, and customer-facing incident communications.
Requirements
- Strong experience in GRC, security compliance, customer assurance, IT audit, or risk management.
- Experience leading customer security reviews and explaining security posture to technical and non-technical audiences.
- Working knowledge of SOC 2, ISO 27001, or comparable security and compliance frameworks.
- Strong judgment, written and verbal communication, project-management discipline, and ability to drive cross-functional work to completion.
- Ability to work across Engineering, Product, IT, Legal, Sales, Customer Success, and Support while improving operational processes.
- Hybrid work in San Francisco or New York is required.
Nice to have
- Startup or growth-stage SaaS experience supporting enterprise customers.
- Experience scaling compliance or customer assurance programs and using Drata, Vanta, SafeBase, or similar tools.
- Knowledge of cloud security, access control, encryption, logging, vulnerability management, incident response, and SaaS architecture.
- Experience with AI security and privacy, GDPR, CCPA, HIPAA, data residency, vendor risk, or compliance automations.
- Security+, CISA, CGRC, ISO 27001 Lead Implementer, or similar certification.
Culture & Benefits
- Equity on employee-friendly terms, including extended exercise windows and a combination of ISOs and RSUs.
- Visa sponsorship is available for H1B, O1, EB1, L1, STEM OPT, and other cases, subject to role and offer-specific review.
- Work with a cross-functional, talent-dense team building AI products intended for everyday use.
- Accessible interview accommodations are available upon request.
Hiring process
- The process is designed to be fair and accessible, with accommodations or adjustments available when needed.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Lead Security Analyst - GRC (Cybersecurity)
172 500 - 215 625$
Legora
11 дней назад
Customer Trust Manager (LegalTech)
151 300 - 204 700$
12 дней назад
Information Security Analyst (AI)
120 000 - 170 000$
CoreWeave
10 дней назад
Senior Technical Program Manager, Third Party Risk Management
157 000 - 210 000$
Snorkel AI
11 дней назад
Head of Security (AI)
252 000 - 370 000$
12 дней назад
Lead AI Security Engineer (Agentic SOC)
150 000 - 275 000$