Security GRC Lead
Core
Lead the Security GRC function for an AI data company, managing continuous compliance audits and trust frameworks for enterprise customers and frontier AI labs.
Role type
Lead Security GRC Engineer (Compliance & Audit)
Builds
SOC 2 Type 2, ISO 27001, and future frameworks (HIPAA, FedRAMP, EU AI Act) operating cadence; automated evidence collection and questionnaire response systems.
Domain
AI/ML Data Infrastructure, Enterprise Security Compliance
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOC 2 Type 2 program ownership, ISO 27001 certification delivery, Vanta/Drata integration and administration, Big 4 audit experience, controls-as-code (Python/SQL), cloud security policy mapping, third-party risk management.
Preferred skills
AI-specific frameworks (NIST AI RMF, ISO 42001), FedRAMP Moderate/HIPAA experience, LLM automation for GRC workflows, third-party risk program setup from zero.
Technologies
Vanta, Wiz, Panther, SQL, Python, shell, MCP (Model Context Protocol), KPMG audit tools.
Responsibilities
Own the continuous SOC 2 monitoring and ISO 27001 buildout; manage enterprise customer audits with sub-48h SLA; design and execute third-party risk programs; implement controls-as-code and automated evidence collection; draft and manage policy lifecycle and trust narratives.
Seniority
Senior, hands-on IC