Applied Methods
~The MetaSecuritySecurity GRC & Compliance

Security GRC & Compliance

This role builds and operates the governance, risk, and compliance infrastructure that enables AI companies to scale safely and securely. Professionals develop policies, manage audits, and automate control evidence across frameworks like SOC 2, ISO 27001, and FedRAMP while partnering closely with engineering teams to embed security into products rather than bolt it on afterward. Unlike traditional compliance roles focused on documentation, these positions emphasize continuous monitoring, compliance-as-code automation, and using data pipelines to turn governance into measurable, verifiable systems that support both business velocity and audit readiness.

$ titles --canonical
Compliance EngineerGRC ManagerSecurity Compliance, Lead
Open Jobs35
Companies Hiring22
$ expectations --role security-grc-&-compliance

Measured across 35 of 35 open postings.

46%
expect AI in the role's own work
6% state it as a requirement
23%
work directly with customers
0%
manage people
Senior
most common level
43% of open postings
BY LEVEL

This role is advertised at one level, so a single figure for the role would describe none of them. Experience and pay are the midpoints for each level on its own.

LevelShareMedian yearsMedian pay
Senior43%(15)7—

A dash means too few postings stated it to report a midpoint. Most companies do not publish a salary band, so pay is indicative rather than a market rate. 4 levels with fewer than 10 open postings are not shown.

WHAT THEY ASK FOR, VERBATIM

“you use coding agents and curiosity to confirm that what we say is what we do”

Cursor · Security GRC Engineer

“Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context”

Anthropic · Supplier Security & Assurance, Security GRC

“Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features)”

Block · Senior GRC Engineer

“hands-on experience with frameworks such as DORA, the EU AI Act, NIS2”

xAI · Sr. Security Engineer - GRC Fintech & Financial Services EU/UK
$ barriers
53%
advertised as remote
of postings that state a work mode
23%
state a degree requirement
11%
need a security clearance
84%
still advertised a month later
about typical for the board

Requirements are a share of every open posting, so a role missing from this list is one where almost nobody asks. Work mode is different: many postings never say, so that figure counts only the ones that do. A posting stops being advertised when it is filled, cancelled or reorganised, so read the last figure as how long these stay on the market, not as time to hire.

$02

Skills

What companies are looking for in this role.

$ skills --core

Compliance program management

69%

Security policy and standards

49%

Security risk management

43%

Security program strategy

29%

Security engineering

26%

Customer security assurance

26%

Cloud and infrastructure security

20%

Third-party risk management

17%

Data privacy compliance

17%

Internal controls and audit readiness

14%

Data quality and governance

9%

Identity and access management

9%

Sales enablement

9%
$ skills --emerging

Compliance automation

49%

AI governance and trust advisory

46%

AI regulatory compliance

11%

AI workflow automation

11%

AI governance & safety product design

9%
$ skills --soft

Technical communication

26%
$03

Technology

The tools and technologies that define this role.

$ tech --language
C/C++low
Golow
Pythonlow
Rustlow
$ tech --platform
AWSmoderate
Azurelow
Google Cloud Platformlow
Kuberneteslow
$ tech --tool
Vantamoderate
Jiralow
Terraformlow
$ tech --concept
FedRAMPmoderate
GDPRmoderate
ISO 27001moderate
ISO 42001moderate
NIST 800-53moderate
PCI DSSmoderate
SOC 2moderate
AI agentslow
CCPAlow
CI/CDlow
CMMClow
EU AI Actlow
HIPAAlow
ISO 27701low
NISTlow
$04

Open Jobs

35 open Security GRC & Compliance jobs across 22 companies.

Anthropic2w
Security Risk & Compliance, Data Centers & Compute
San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC·Security
Cursor2w
Security GRC Engineer
San Francisco·Security
MongoDB2w
Associate Third-Party Risk Management (TPRM) Risk Analyst
United States·Security
MongoDB2w
Third-Party Risk Management (TPRM) Risk Analyst
Dublin, Ireland·Security
Anthropic3w
Supplier Security & Assurance, Security GRC
San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC·Security
CHAOS Industries1mo
Governance, Risk & Compliance (GRC) Analyst
Washington, District of Columbia, United States·Security
Anthropic1mo
Lead, Security Controls Assurance - SOX
San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC·Security
Nebius1mo
Security Risk Lead
Tel Aviv, Israel·Security
Nebius1mo
GRC Program Coordinator
Tel Aviv, Israel·Security
Nebius1mo
Security Analyst (compliance and controls)
Prague, Czech Republic·Security
Block1mo
Senior GRC Engineer
Bay Area, CA, United States of America·Security
OpenAI1mo
GRC Technical Program Manager, Product Lifecycle Assurance
San Francisco·Security
Abnormal Security1mo
Security & Compliance Analyst, Public Sector
Remote - USA·Security
Figma1mo
Federal Compliance Manager
San Francisco, CA • New York, NY • United States·Security
Snorkel AI1mo
Senior Technical Compliance Analyst
New York City, NY (Hybrid); San Francisco, CA (Hybrid)·Security
Parloa1mo
Senior IS&T Governance Partner
New York Office·Security
Rescale1mo
Principal Security GRC Analyst
Remote (United States)·Security
xAI1mo
Sr. Security Engineer - GRC Fintech & Financial Services EU/UK
Dublin, Ireland; London, England, United Kingdom·Security
Ada2mo
Compliance and Security Lead
Remote - Canada·Security
OpenAI2mo
GRC Program Manager, Audit & Controls
San Francisco·Security