обновлено 12 дней назад
GRC Specialist (AI)
200 000 - 220 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Specialist (AI): Managing security and compliance operations for an enterprise AI SaaS platform with an accent on audit readiness, risk management, access reviews, and third-party assessments. Focus on designing internal audits, automating control evidence, maintaining compliance across SOC 2, HIPAA, ISO, and GDPR, and translating program data into targeted risk reduction.
Location: San Mateo or New York, United States; remote and on-site arrangements stated
Salary: $200K–$220K annually, plus equity
Company
provides a platform for building, training, and serving specialized AI models across text, image, embedding, audio, and multimodal workloads.
What you will do
- Own day-to-day GRC operations, including user access reviews, security awareness campaigns, phishing and deepfake simulations, JML tracking, and policy exception management.
- Run annual and ad hoc risk assessments, maintain the risk register, coordinate remediation, and track issues through closure.
- Manage third-party and subprocessor risk assessments, ongoing vendor monitoring, and remediation for critical vendors.
- Design and execute internal audits and support external audit cycles by coordinating evidence, control owners, and remediation.
- Administer the GRC platform, maintain automated control tests and evidence, and support continuous audit readiness.
- Partner with engineering, IT, operations, legal, and sales to improve control ownership, policies, reporting, and program maturity.
Requirements
- 5–7 years of experience in GRC, IT audit, information security, or a related field.
- Working knowledge of SOC 2, ISO 27001, ISO 27701, ISO 42001, NIST CSF, HIPAA, GDPR, or CCPA.
- Experience with GRC platforms such as Anecdotes, Vanta, Drata, Secureframe, OneTrust, or ServiceNow GRC.
- Experience with user access reviews, identity and access management, RBAC, least privilege, segregation of duties, and JML processes.
- Hands-on experience with security awareness or phishing simulation platforms and familiarity with AWS, GCP, or Azure environments.
- Strong written communication, organization, attention to detail, and cross-functional collaboration skills.
Nice to have
- Experience leading end-to-end audits across multiple frameworks.
- Experience improving control maturity, automation, and GRC program efficiency.
- Experience mentoring team members or representing GRC in cross-functional initiatives.
Culture & Benefits
- Work on AI infrastructure challenges including low-latency inference and scalable model serving.
- Collaborate with engineers and AI researchers on emerging technology.
- Operate in a fast-growing environment with significant ownership and direct impact.
- Equity is included in the compensation package.
- Inclusive, equal-opportunity workplace committed to diversity.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Senior GRC Analyst
120 000 - 150 000$
Anthropic
13 дней назад
Security Risk & Compliance, Data Centers & Compute (AI)
270 000 - 345 000$
12 минут назад
Staff Security Analyst - GRC
150 000 - 164 000$
Anthropic
4 дня назад
Supplier Security & Assurance, Security GRC (AI)
255 000 - 270 000$
12 дней назад
Senior Manager, GRC Strategy & AI
142 500 - 237 500$
Snowflake
13 дней назад
Senior Software Engineer (Cloud Security)
200 000 - 287 500$