Назад
Company hidden
9 часов назад

Head of GRC (AI)

220 000 - 260 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
head
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Head of GRC (AI): Building and owning an audit-ready compliance program for an autonomous AI software development platform with an accent on SOC 2 Type II, ISO 27001:2022, and GRC system-of-record management. Focus on designing proactive evidence processes, managing auditors and compliance partners, and preparing the organization for FedRAMP High.

Location: 1 Kendall Square, Cambridge, MA; on-site

Salary: $220,000–$260,000 plus bonus and equity, commensurate with experience

Company

hirify.global is a Cambridge-based AI software development platform that autonomously converts enterprise requirements into production-ready code.

What you will do

  • Own Vanta or an equivalent GRC platform as the system of record, configuring tests and keeping evidence current.
  • Run SOC 2 Type II and ISO 27001:2022 compliance programs continuously toward audit requirements.
  • Manage auditor and compliance partner relationships directly, including FedRAMP platform partners.
  • Build proactive compliance processes, including formal sub-processor change communications.
  • Critically evaluate audit evidence and verify security controls such as enforced SSO.
  • Reduce engineering involvement in compliance requests by taking ownership of security scope questions and evidence collection.

Requirements

  • Hands-on ownership of at least one complete SOC 2 Type II or ISO 27001:2022 audit cycle.
  • Direct experience operating Vanta or an equivalent GRC platform as the system-of-record owner.
  • Independent experience managing vendors and auditors.
  • Strong judgment and seniority to take compliance work off engineering teams.
  • Clear writing skills for policies, audit narratives, and questionnaire responses.

Nice to have

  • FedRAMP experience, including Moderate-level exposure.
  • Experience building compliance processes from scratch.
  • Experience managing SOC 2, ISO 27001, and GDPR concurrently.
  • Familiarity with Google Workspace as an identity provider.
  • GDPR and data privacy program experience, including cookie consent, Article 27 coordination, and DPA review.

Culture & Benefits

  • In-person collaboration in a fast-growing U.S. company.
  • High standards, decisive execution, and a strong customer focus.
  • Work on autonomous software development and demanding compliance programs such as FedRAMP.
  • Emphasis on sleep, movement, and restorative activities to support sustained performance.
  • Bonus and equity in addition to base compensation.

Hiring process

  • Audit walkthrough interview covering a real SOC 2 or ISO 27001 cycle personally managed.
  • Discussion of how audit findings were handled.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →