Назад
Company hidden
обновлено 12 дней назад

GRC Specialist (AI)

200 000 - 220 000$
Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Specialist (AI): Managing security and compliance operations for an enterprise AI SaaS platform with an accent on audit readiness, risk management, access reviews, and third-party assessments. Focus on designing internal audits, automating control evidence, maintaining compliance across SOC 2, HIPAA, ISO, and GDPR, and translating program data into targeted risk reduction.

Location: San Mateo or New York, United States; remote and on-site arrangements stated

Salary: $200K–$220K annually, plus equity

Company

hirify.global provides a platform for building, training, and serving specialized AI models across text, image, embedding, audio, and multimodal workloads.

What you will do

  • Own day-to-day GRC operations, including user access reviews, security awareness campaigns, phishing and deepfake simulations, JML tracking, and policy exception management.
  • Run annual and ad hoc risk assessments, maintain the risk register, coordinate remediation, and track issues through closure.
  • Manage third-party and subprocessor risk assessments, ongoing vendor monitoring, and remediation for critical vendors.
  • Design and execute internal audits and support external audit cycles by coordinating evidence, control owners, and remediation.
  • Administer the GRC platform, maintain automated control tests and evidence, and support continuous audit readiness.
  • Partner with engineering, IT, operations, legal, and sales to improve control ownership, policies, reporting, and program maturity.

Requirements

  • 5–7 years of experience in GRC, IT audit, information security, or a related field.
  • Working knowledge of SOC 2, ISO 27001, ISO 27701, ISO 42001, NIST CSF, HIPAA, GDPR, or CCPA.
  • Experience with GRC platforms such as Anecdotes, Vanta, Drata, Secureframe, OneTrust, or ServiceNow GRC.
  • Experience with user access reviews, identity and access management, RBAC, least privilege, segregation of duties, and JML processes.
  • Hands-on experience with security awareness or phishing simulation platforms and familiarity with AWS, GCP, or Azure environments.
  • Strong written communication, organization, attention to detail, and cross-functional collaboration skills.

Nice to have

  • Experience leading end-to-end audits across multiple frameworks.
  • Experience improving control maturity, automation, and GRC program efficiency.
  • Experience mentoring team members or representing GRC in cross-functional initiatives.

Culture & Benefits

  • Work on AI infrastructure challenges including low-latency inference and scalable model serving.
  • Collaborate with engineers and AI researchers on emerging technology.
  • Operate in a fast-growing environment with significant ownership and direct impact.
  • Equity is included in the compensation package.
  • Inclusive, equal-opportunity workplace committed to diversity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →