CareerPlanSign in

Security GRC Lead

San Francisco💼 Full-time🗓 2026-09-09 → 2026-09-27

Core

Lead the Security GRC function for an AI data company, managing continuous compliance audits and trust frameworks for enterprise customers and frontier AI labs.

Role type

Lead Security GRC Engineer (Compliance & Audit)

Builds

SOC 2 Type 2, ISO 27001, and future frameworks (HIPAA, FedRAMP, EU AI Act) operating cadence; automated evidence collection and questionnaire response systems.

Domain

AI/ML Data Infrastructure, Enterprise Security Compliance

Deliverable

production ML models | product features | dashboards & analysis | client delivery | infrastructure

Required skills

SOC 2 Type 2 program ownership, ISO 27001 certification delivery, Vanta/Drata integration and administration, Big 4 audit experience, controls-as-code (Python/SQL), cloud security policy mapping, third-party risk management.

Preferred skills

AI-specific frameworks (NIST AI RMF, ISO 42001), FedRAMP Moderate/HIPAA experience, LLM automation for GRC workflows, third-party risk program setup from zero.

Technologies

Vanta, Wiz, Panther, SQL, Python, shell, MCP (Model Context Protocol), KPMG audit tools.

Responsibilities

Own the continuous SOC 2 monitoring and ISO 27001 buildout; manage enterprise customer audits with sub-48h SLA; design and execute third-party risk programs; implement controls-as-code and automated evidence collection; draft and manage policy lifecycle and trust narratives.

Seniority

Senior, hands-on IC

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.