Назад
21 час назад

Governance, Risk & Compliance Manager (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Governance, Risk & Compliance Manager (AI): Designing and owning the end-to-end GRC framework for an AI compute cloud platform with an accent on continuous compliance and risk mitigation. Focus on maturing SOC 2, ISO 27001, and SOX frameworks to enable enterprise sales and regulatory readiness.

Location: On-site in Las Vegas, Nevada. Must be authorized to work in the United States.

Company

An AI infrastructure provider delivering seamless, secure, and resilient AI compute at scale via a versatile cloud platform.

What you will do

  • Design, implement, and continuously test a unified controls framework, including IT General Controls (ITGCs).
  • Maintain and mature SOC 2 Type II and ISO 27001 certifications, moving toward automated evidence collection.
  • Develop the SOX roadmap and design internal controls over financial reporting (ICFR) aligned to AICPA/PCAOB standards.
  • Establish an automated, enterprise-grade third-party risk management program for a SaaS ecosystem.
  • Operationalize a corporate risk register and conduct quarterly reviews with leadership to prioritize security spend.
  • Partner with engineering to embed compliance into the CI/CD development lifecycle.

Requirements

  • 5–8+ years of experience in Information Security, IT Audit, or GRC.
  • Hands-on experience designing and defending controls for SOC 2 Type II, ISO 27001, SOX, and/or PCI DSS.
  • Strong working knowledge of Sarbanes-Oxley compliance and evidence preparation for AICPA or PCAOB standards.
  • Track record spanning both fast-paced Series B/C startups and mature enterprise or Big 4 audit environments.
  • Legal authorization to work in the United States.

Nice to have

  • Experience with API-driven GRC tooling such as Vanta or Drata.
  • Exposure to cloud or GPU infrastructure security.
  • Relevant certifications: CISA, CISSP, CRISC, or ISO 27001 Lead Auditor/Implementer.
  • Experience integrating compliance into CI/CD pipelines.

Culture & Benefits

  • Equity through stock options.
  • 100% paid medical, dental, and vision insurance for employees.
  • Company HSA contributions and 401(k) plan.
  • 100% paid short-term and long-term disability insurance.
  • Flexible PTO, paid holidays, and parental leave.
  • Various in-office perks and an Employee Assistance Program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →