Назад
Company hidden
3 часа назад

GRC Specialist (AI)

200 000 - 220 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Specialist (AI): Operating and maturing security and compliance programs for an enterprise AI SaaS platform with an accent on risk management, audit readiness, access reviews, and third-party risk. Focus on testing control effectiveness, automating evidence collection, maintaining compliance across SOC 2, HIPAA, ISO, and GDPR, and turning program data into targeted security improvements.

Location: On-site in San Mateo or New York, United States

Salary: $200K–$220K annually plus equity

Company

hirify.global provides an AI platform for building, training, and serving specialized models across text, image, embedding, audio, and multimodal workloads.

What you will do

  • Own daily GRC operations, including user access reviews, security awareness and phishing/deepfake simulations, JML tracking, and policy exception management.
  • Run annual and ad hoc risk assessments, maintain the risk register, and track remediation through closure.
  • Manage vendor and subprocessor risk assessments, monitoring, and remediation for critical third parties.
  • Design targeted internal audits and support external audit cycles by coordinating evidence, control owners, and remediation.
  • Administer the GRC platform, maintain automated control tests and evidence, and keep the program audit-ready year-round.
  • Partner with engineering, IT, operations, legal, and sales to operationalize controls, maintain policies, and report risk insights to leadership.

Requirements

  • 5–7 years of experience in GRC, IT audit, information security, or a related field.
  • Working knowledge of SOC 2, ISO 27001, ISO 27701, ISO 42001, NIST CSF, HIPAA, GDPR, or CCPA.
  • Experience with GRC platforms such as Anecdotes, Vanta, Drata, Secureframe, OneTrust, or ServiceNow GRC.
  • Experience with user access reviews and identity and access management concepts, including RBAC, least privilege, segregation of duties, and JML processes.
  • Hands-on experience administering security awareness or phishing simulation platforms, plus familiarity with AWS, GCP, or Azure SaaS environments.
  • Strong written communication, organization, attention to detail, and cross-functional collaboration skills.

Culture & Benefits

  • Work on challenging AI infrastructure problems, including low-latency inference and scalable model serving.
  • Build technology used by businesses and developers to work with AI globally.
  • Collaborate with experienced engineers and AI researchers in a fast-moving environment.
  • Receive equity as part of the compensation package.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →