5 часов назад
GRC Lead (AI Governance)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Lead (AI Governance): Building Aaru’s governance, risk, and compliance function for an AI platform that simulates human behavior, with an accent on enterprise security reviews, audit readiness, evidence automation, vendor risk, and AI governance. Focus on establishing repeatable controls and policies, automating compliance workflows, supporting SOC 2 or ISO 27001 readiness, and addressing complex questions about model training data, personal data, and simulated outputs.
Location: New York City metropolitan area; in-person, 5 days a week in the office. Candidates must be located in the area or be open to relocation.
Company
develops AI agents that simulate human behavior and populations to help enterprise customers test strategic decisions, understand audiences, validate concepts, optimize pricing, and analyze customer outcomes.
What you will do
- Own customer security reviews, security questionnaires, due diligence requests, RFP security sections, and vendor risk conversations.
- Build and maintain a canonical security response library for enterprise sales cycles.
- Manage external audit readiness, fieldwork, surveillance cycles, information requests, control walkthroughs, and remediation.
- Run control testing, access reviews, recurring checks, and monitoring while documenting effectiveness and driving remediation.
- Govern policies and evidence, including automated evidence collection through a GRC platform.
- Build the third-party risk lifecycle and own governance of ’s models and AI agents with engineering, product, and legal.
Requirements
- 5–8 years of experience in GRC, security compliance, or IT audit, ideally at an enterprise software company.
- Working knowledge of SOC 2 and familiarity with ISO 27001, NIST CSF, HIPAA, or PCI-DSS.
- Experience with Vanta, Drata, OneTrust, or similar platforms for evidence collection and control management.
- Experience supporting live enterprise sales security reviews and explaining control requirements to technical and commercial stakeholders.
- Ability to build repeatable compliance processes and validate AI-assisted work before delivery.
- Must work onsite in the New York City metropolitan area or be open to relocating there.
Nice to have
- Experience leading a first SOC 2 Type II or ISO 27001 certification.
- Experience with AI governance frameworks such as ISO 42001, NIST AI RMF, or the EU AI Act.
- Experience with regulated financial services or public sector procurement.
- Knowledge of US state privacy law, GDPR, Singapore PDPA, and data residency requirements.
- Automation experience with Python, JavaScript, or low-code tools; CISA, CRISC, CISM, or ISO 27001 Lead Auditor / Lead Implementer certification.
Culture & Benefits
- Small, dedicated, mission-driven team with high ownership and limited bureaucracy.
- Competitive base salary and equity participation.
- Comprehensive medical, vision, and dental coverage.
- Visa sponsorship and relocation support are available.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →