Security GRC & Compliance
Professionals in this role design and scale compliance programs that enable AI companies to operate securely across multiple regulatory frameworks—SOC 2, ISO 27001, FedRAMP, and emerging AI governance standards. Day-to-day, they conduct risk assessments, build automation to embed compliance into engineering workflows, respond to customer security questionnaires, and manage audit readiness across cloud infrastructure and AI-specific controls. What distinguishes this work is the technical depth required: rather than purely policy-focused compliance, these roles demand hands-on experience implementing controls, scripting automation, and translating complex regulatory requirements into practical controls that don't slow product velocity. They typically sit within security organizations reporting to CISOs or governance leaders, partnering closely with engineering, product, and sales teams to balance compliance rigor with business growth in fast-moving AI environments.
Skills
What companies are looking for in this role.
Implementing and auditing against security compliance frameworks such as ISO 27001, SOC 2, FedRAMP, NIST, and HIPAA
Identifying, assessing, and prioritizing organizational risks across cybersecurity, regulatory, and operational domains
Developing and maintaining security policies, procedures, and documentation aligned with regulatory requirements
Designing and implementing risk mitigation strategies including monitoring systems, contingency plans, and vulnerability management
Conducting internal and external security audits and assessments
Maintaining audit readiness through documentation, evidence management, and control demonstration
Establishing and managing control mapping, evidence standards, and testing approaches
Translating technical implementations into audit narratives and control documentation
Managing authorization and accreditation processes with government agencies and third-party assessors
Developing risk registers, risk assessment methodologies, and risk-based decision making frameworks
Responding to customer security questionnaires and RFP requests with technical accuracy and credibility
Managing vendor risk and third-party security assessments
Managing Plans of Action and Milestones and tracking remediation efforts
Designing control narratives that accurately represent technical implementation and compliance intent
Executing user access reviews and maintaining access control systems
Supporting System Security Plans, Risk Management Framework documentation, and authorization packages
Evaluating technical implementations in cloud, containerization, and CI/CD environments against compliance requirements
Designing and implementing classified information security programs and controls
Managing security awareness training programs and compliance tracking across the organization
Building and scaling compliance automation and compliance-as-code infrastructure
Automating evidence collection, monitoring, and continuous compliance using technical tools and scripting
Implementing AI governance frameworks and responsible AI compliance measures
Using AI-augmented tools and large language models to accelerate compliance documentation and analysis
Collaborating across cross-functional teams including engineering, product, sales, and legal to integrate compliance requirements
Communicating complex compliance and security concepts to technical and non-technical stakeholders
Managing program execution, timelines, and accountability for large, complex compliance initiatives
Leading and developing high-performing GRC teams with focus on quality and accountability
Driving organizational change and building a culture of compliance and security awareness
Building and maintaining customer trust through transparent security posture communication and assurance
Coaching teams on translating customer and regulatory requirements into technical and operational capabilities
Technology
The tools and technologies that define this role.
Open Jobs
40 open Security GRC & Compliance jobs across 24 companies.
Other Security roles
Identifies and mitigates security vulnerabilities in applications and products.
Secures cloud infrastructure, networks, and systems.
Generalist security engineering role spanning multiple security domains. For security engineers who work across application, infrastructure, and cloud security without a single dominant specialization. The default home for "Security Engineer" titles when the function is clearly Security.
Builds detection systems, investigates security incidents, and leads incident response efforts.
Conducts offensive security assessments including red teaming, penetration testing, and adversarial simulation.