2 дня назад
Staff Security Governance Engineer, Policies & Standards (AI)
168 000 - 238 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Security Governance Engineer, Policies & Standards (AI): Owns the lifecycle of security policies and standards while translating emerging regulations into actionable requirements for engineering, product, legal, and security teams with an accent on AI regulation, framework alignment, and measurable policy adherence. Focus on automating policy management, evidence collection, control monitoring, exception handling, and Policy as Code across a remote-first DevSecOps environment.
Location: Remote, United States
Base salary: $168,000–$238,000 USD per year for United States residents.
Company
provides an intelligent orchestration platform for DevSecOps that helps organizations improve developer productivity, operational efficiency, security, compliance, and digital transformation.
What you will do
- Own the full lifecycle of security policies, standards, procedures, and guidelines, including drafting, review, approval, publication, annual review, and retirement.
- Define exception management, policy attestation, adherence investigations, risk-based approvals, expiry tracking, and trend reporting.
- Monitor regulations and standards such as the EU AI Act, NIST AI RMF, ISO 42001, SOC 2, ISO 27001, FedRAMP, and NIST CSF, and maintain reusable policy mappings.
- Define policy adherence KPIs, run internal assessments, coordinate audit evidence and testing, and drive remediation to closure.
- Support customer questionnaires and meetings, turning recurring customer requests into stronger policies and self-service content.
- Implement automation and AI-assisted workflows for policy management, evidence collection, control monitoring, assessments, and Policy as Code.
Requirements
- 10+ years of experience in security governance, GRC, or IT risk, including hands-on ownership of a policy and standards lifecycle.
- Practical knowledge of SOC 2, ISO 27001, ISO 42001, FedRAMP, and NIST CSF.
- Understanding of cloud, SaaS, and DevSecOps practices, with the ability to write policies that engineering teams can follow.
- Experience using automation or AI to reduce manual GRC work.
- Strong written and verbal communication for working with engineers, executives, auditors, customers, Security, Product, Legal, and Engineering.
- Ability to work remotely from the United States.
Nice to have
- CISSP, CISM, CISA, or a similar certification.
- Experience at a global technology company.
Culture & Benefits
- Remote-first and asynchronous working environment.
- Open documentation and collaboration across Security, Legal, Product, and Engineering.
- Flexible paid time off, parental leave, and benefits supporting health, finances, and well-being.
- Equity compensation and employee stock purchase plan.
- Growth and development fund and team member resource groups.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Senior IT Governance & Compliance Manager (AI GRC)
115 000 - 140 000$
9 дней назад
GRC Specialist (AI)
200 000 - 220 000$
3 дня назад
GRC Security Analyst (AI Governance)
114 000 - 139 000$
Asana
7 дней назад
Security Risk Manager (Cybersecurity)
194 000 - 220 000$
Sardine
4 дня назад
Security Compliance Lead (Fintech)
130 000 - 190 000$
3 дня назад
Senior GRC Analyst (AI Governance)
164 000 - 205 000$