Applied Methods
~The MetaSecuritySecurity GRC & Compliance

Security GRC & Compliance

Professionals in this role design and scale compliance programs that enable AI companies to operate securely across multiple regulatory frameworks—SOC 2, ISO 27001, FedRAMP, and emerging AI governance standards. Day-to-day, they conduct risk assessments, build automation to embed compliance into engineering workflows, respond to customer security questionnaires, and manage audit readiness across cloud infrastructure and AI-specific controls. What distinguishes this work is the technical depth required: rather than purely policy-focused compliance, these roles demand hands-on experience implementing controls, scripting automation, and translating complex regulatory requirements into practical controls that don't slow product velocity. They typically sit within security organizations reporting to CISOs or governance leaders, partnering closely with engineering, product, and sales teams to balance compliance rigor with business growth in fast-moving AI environments.

$ titles --canonical
Compliance EngineerGRC ManagerSecurity Compliance, Lead
Open Jobs29
Companies Hiring22
$02

Skills

What companies are looking for in this role.

$ skills --core

Conducting internal audits and security assessments against compliance frameworks such as ISO 27001, SOC 2, and industry-specific standards

95%

Developing and maintaining security policies, procedures, and documentation aligned with compliance requirements

93%

Managing risk assessment processes including identification, scoping, scoring, and residual risk calculation

92%

Maintaining and operationalizing risk registers as dynamic governance tools that drive accountability

88%

Designing and implementing security controls that meet regulatory and compliance requirements

87%

Collecting, organizing, and preparing audit evidence across multiple compliance frameworks

86%

Conducting vendor security assessments and managing third-party risk through security questionnaires and evaluations

85%

Translating complex regulatory requirements into practical, scalable control implementations

84%

Managing audit readiness activities including artifact preparation, timeline tracking, and action item management

83%

Supporting user access reviews and identity governance across systems and applications

82%

Building and managing compliance programs across multiple frameworks and regulatory requirements

81%

Responding to customer security questionnaires and supporting due diligence requests

79%
$ skills --emerging

Evaluating technical implementations such as branch protection, CI/CD pipelines, and cloud architecture for compliance

77%

Automating compliance monitoring and reporting through compliance-as-code tooling and integration

76%

Building lightweight scripts and tools for evidence collection, control tracking, and audit reporting

71%

Supporting AI governance and responsible AI compliance efforts including ISO 42001 and EU AI Act requirements

68%

Implementing continuous monitoring and validation approaches for control effectiveness

65%

Establishing supply chain risk management programs and third-party security controls

62%

Leveraging AI tools to streamline GRC activities including evidence summarization and process documentation

58%

Designing vulnerability management programs with risk-based prioritization and remediation tracking

55%
$ skills --soft

Collaborating across engineering, product, security, and legal teams to align technical and compliance requirements

91%

Communicating technical security concepts and compliance requirements to diverse audiences including executives and non-technical stakeholders

88%

Building and maintaining trusted relationships with internal stakeholders, auditors, and external certification bodies

85%

Acting as a liaison and subject matter expert during compliance audits and regulatory assessments

84%

Driving cross-functional projects and managing timelines for compliance initiatives and remediation efforts

82%

Translating business context and technical reality into clear audit narratives and compliance documentation

80%

Advising senior leadership and security teams on strategic risks and geopolitical developments affecting security posture

65%

Monitoring external policy shifts, regulatory changes, and ecosystem developments relevant to organizational security

62%

Creating and delivering executive briefings and strategic analysis on cyber, geopolitical, and regulatory trends

60%
$03

Technology

The tools and technologies that define this role.

$ tech --platform
AWShigh
Azurehigh
GCPhigh
GitHubmoderate
Kubernetesmoderate
$ tech --tool
Vantamoderate
Jira Service Desklow
$ tech --concept
ISO 27001very high
SOC 2very high
CI/CDhigh
FedRAMPhigh
NISThigh
CISmoderate
DevOpsmoderate
DORAmoderate
GDPRmoderate
HIPAAmoderate
ISO 27701moderate
ISO 42001moderate
RMFmoderate
3PAOlow
BSI IT-Grundschutzlow
CCPAlow
CJISlow
CMMClow
DISA CC SRGlow
EU Digital Services Actlow
HITRUSTlow
ISO 22301low
SOX 404low
UK Online Safety Actlow
$04

Open Jobs

29 open Security GRC & Compliance jobs across 22 companies.

xAI23h
Security Engineer - Governance Risk Compliance
New York, NY; Palo Alto, CA; Washington, D.C.·Security
Abnormal Security1w
Senior Manager, Customer Trust
Remote - USA·Security
Replit2w
GRC Engineer
Foster City, CA·Security
Cursor2w
GRC Security Engineer, Federal & Public Sector
San Francisco·Security
Helsing3w
Information Security Officer
Munich·Security
MongoDB3w
IRM Analyst
United States·Security
MongoDB3w
IRM Analyst
Dublin·Security
Synthesia4w
GRC Analyst
Europe·Security
OpenAI1mo
GRC Program Manager, US Government Compliance
Washington, DC·Security
ElevenLabs1mo
Compliance Engineer - North America
New York·Security
Modal1mo
Security GRC Specialist
New York·Security
Crusoe1mo
Senior GRC Analyst
San Francisco, CA - US·Security
ElevenLabs1mo
Compliance Engineer - APAC
Tokyo·Security
Cohere1mo
GRC Specialist
Toronto·Security
Cerebras Systems1mo
Cybersecurity GRC Manager
Sunnyvale CA or Toronto Canada·Security
MongoDB1mo
Senior IRM Analyst
Dublin·Security
MongoDB1mo
Senior IRM Analyst
United States·Security
CoreWeave1mo
Technical Program Manager (TPM) – SOX Compliance
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA·Security
Databricks2mo
Staff Security Assurance Engineer - Special Projects
United States·Security
Anthropic2mo
Engineering Manager, GRC
San Francisco, CA | New York City, NY | Seattle, WA·Security