Назад
Company hidden
3 дня назад

Senior GRC Analyst (AI Governance)

164 000 - 205 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Analyst (AI Governance) (SOC 2/PHI/AI risk): Owning an end-to-end governance, risk, and compliance program for an AI healthcare platform with an accent on SOC 2, PHI governance, vendor risk, and AI-model risk. Focus on investigating controls directly from the codebase, closing security gaps with engineering, and maintaining customer-facing compliance evidence.

Location: San Francisco, United States; hybrid

Salary: $164,000–$205,000 annually plus equity

Company

hirify.global builds an AI intelligence platform for healthcare, providing real-time coding-aware documentation and clinical workflow support to health systems.

What you will do

  • Own the SOC 2 program end to end, including auditor relationships, evidence collection in Vanta, and continuous audit readiness.
  • Build and maintain an authoritative inventory of PHI, systems, and models, identifying and closing HIPAA and governance gaps.
  • Use AI coding tools such as Claude Code to investigate controls directly from the source code and produce evidence-based answers.
  • Establish vendor and AI-model security reviews, including data-flow analysis and documented risk assessments.
  • Partner with engineering to prioritize and remediate security risks, and write practical security and compliance policies.
  • Manage customer trust activities, including RFPs, security questionnaires, and the trust portal.

Requirements

  • Senior-level GRC or compliance experience in a SaaS environment.
  • Experience owning a SOC 2 or equivalent audit from evidence collection through auditor sign-off.
  • Technical curiosity and the ability to use AI coding tools to verify controls in source code without writing code.
  • Ability to threat-model vendors by analyzing the data they access, data flows, and required controls.
  • Strong policy writing and communication skills with engineering, legal, and customer stakeholders.
  • Ownership mindset and comfort operating in ambiguity within a startup environment.

Nice to have

  • ISO 27001 experience and exposure to ISO 42001 or other AI governance frameworks.
  • Experience in healthcare, fintech, or another highly regulated industry.

Culture & Benefits

  • High-ownership, high-trust environment focused on decisive execution and continuous growth.
  • Remote-friendly culture with a San Francisco headquarters and full equipment provisioning.
  • Medical, dental, and vision coverage for employees and dependents.
  • 401(k) with a company match of up to 3% of base salary.
  • Parental leave, flexible time off, company holidays, and a year-end holiday shutdown.
  • Company and team off-sites, lunches, and all-hands events with covered travel, lodging, and meals.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →