GRC Specialist
Core
Build, implement, and scale compliance programs, controls, and processes across frameworks and regulatory requirements including SOC 2, ISO 27001, HIPAA, ISO 42001, and FedRAMP/DoD for an AI model company.
Role type
GRC Specialist (Security Organization)
Builds
Scalable compliance programs, practical controls, and durable governance processes for an AI enterprise.
Domain
AI Governance, Cybersecurity Compliance, Public Sector Readiness
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Building and scaling compliance programs, AI governance frameworks (ISO 42001), project management, cross-functional execution, technical fluency, automation and workflow tooling, Python scripting
Preferred skills
Risk management frameworks (FAIR), multi-jurisdictional consulting experience, NIST standards (CSF, RMF, AI RMF, CMMC), cloud-native/SaaS environments, executive reporting
Technologies
Python, SOC 2, ISO 27001, HIPAA, ISO 42001, FedRAMP, DoD, NIST CSF, NIST RMF, NIST AI RMF, CMMC
Responsibilities
Build and scale compliance programs across frameworks; Support AI governance efforts aligned to ISO 42001 and EU AI Act; Drive compliance readiness for FedRAMP and DoD; Partner with cross-functional teams to translate requirements into controls; Improve compliance operations through automation and tooling; Build scripts for evidence collection and audit readiness; Manage cross-functional projects and audit preparation.
Seniority
Mid-Senior (5+ years experience)