Назад
15 часов назад

Senior GRC Lead (AI)

174 250 - 205 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Lead (AI) (AI Governance, SOC 2, ISO 27001): Building and scaling Jasper’s governance, risk, and compliance program for AI-native SaaS products with an accent on audits, control mapping, vendor risk, and AI governance. Focus on automating compliance workflows, maintaining risk registers, integrating requirements into engineering processes, and supporting enterprise security due diligence.

Location: Fully remote, open to candidates located anywhere in the continental United States

Salary: $174,250–$205,000 annual base salary

Company

Jasper provides an AI marketing agents platform that helps enterprises execute campaigns, personalization, localization, and compliance at scale with enterprise-grade governance and control.

What you will do

  • Own SOC 2, ISO 27001, and similar compliance audits from readiness through certification, with a path toward ISO 42001.
  • Maintain the compliance control framework, rationalize overlapping requirements, and serve as the control-mapping expert during audits, RFPs, and enterprise sales engagements.
  • Manage the risk register, including risk identification, scoring, remediation tracking, and continuous improvement.
  • Lead vendor and third-party risk assessments, security questionnaires, and vendor security reviews.
  • Draft, review, and maintain security and compliance policies while partnering with Security, Legal, Product, Engineering, GTM, and People.
  • Automate audit evidence collection, compliance reviews, continuous monitoring, and AI governance workflows.

Requirements

  • 8+ years of Governance, Risk, and Compliance experience, ideally in a SaaS company.
  • Deep expertise in SOC 2 Type II, ISO 27001, NIST CSF, and at least one regulatory framework such as GDPR, CCPA, or HIPAA.
  • Working knowledge of AI concepts including LLMs, agents, copilots, tokens, context windows, RAG, and data governance.
  • Experience with cloud-native web application security practices, especially GCP and frontier AI platforms.
  • Experience with GRC tools such as Vanta, Drata, or OneTrust, as well as risk registers and vendor risk programs.
  • Working knowledge of Python and experience using AI agents or coding tools to modify scripts, build automations, and ship small tools.

Nice to have

  • CISA, CISSP, CRISC, or a similar certification.
  • Experience scoping or pursuing ISO 42001 or other AI governance frameworks.
  • Previous experience at a startup or fast-growing SaaS company.

Culture & Benefits

  • Fully remote work within the continental United States.
  • Health, dental, and vision coverage for employees and families from the first day.
  • 401(k) program with up to 2% company matching and equity grant participation.
  • Flexible PTO, a $900 FlexExperience budget, and a $1,800 FlexWellness program.
  • Home office setup support, a $1,500 annual learning and development stipend, and 16 weeks of paid parental leave.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →