Security GRC & Compliance
This role builds and operates the governance, risk, and compliance infrastructure that enables AI companies to scale safely and securely. Professionals develop policies, manage audits, and automate control evidence across frameworks like SOC 2, ISO 27001, and FedRAMP while partnering closely with engineering teams to embed security into products rather than bolt it on afterward. Unlike traditional compliance roles focused on documentation, these positions emphasize continuous monitoring, compliance-as-code automation, and using data pipelines to turn governance into measurable, verifiable systems that support both business velocity and audit readiness.
Measured across 35 of 35 open postings.
This role is advertised at one level, so a single figure for the role would describe none of them. Experience and pay are the midpoints for each level on its own.
| Level | Share | Median years | Median pay |
|---|---|---|---|
| Senior | 43%(15) | 7 | — |
A dash means too few postings stated it to report a midpoint. Most companies do not publish a salary band, so pay is indicative rather than a market rate. 4 levels with fewer than 10 open postings are not shown.
“you use coding agents and curiosity to confirm that what we say is what we do”
“Experience building or tuning an LLM-backed workflow, agent, or automation in a risk, compliance, or operations context”
“Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features)”
“hands-on experience with frameworks such as DORA, the EU AI Act, NIS2”
Requirements are a share of every open posting, so a role missing from this list is one where almost nobody asks. Work mode is different: many postings never say, so that figure counts only the ones that do. A posting stops being advertised when it is filled, cancelled or reorganised, so read the last figure as how long these stay on the market, not as time to hire.
Skills
What companies are looking for in this role.
Compliance program management
Security policy and standards
Security risk management
Security program strategy
Security engineering
Customer security assurance
Cloud and infrastructure security
Third-party risk management
Data privacy compliance
Internal controls and audit readiness
Data quality and governance
Identity and access management
Sales enablement
Compliance automation
AI governance and trust advisory
AI regulatory compliance
AI workflow automation
AI governance & safety product design
Technical communication
Technology
The tools and technologies that define this role.
Open Jobs
35 open Security GRC & Compliance jobs across 22 companies.
Other Security roles
Identifies and mitigates security vulnerabilities in applications and products.
Secures cloud infrastructure, networks, and systems.
Generalist security engineering role spanning multiple security domains. For security engineers who work across application, infrastructure, and cloud security without a single dominant specialization. The default home for "Security Engineer" titles when the function is clearly Security.
Builds detection systems, investigates security incidents, and leads incident response efforts.
Conducts offensive security assessments including red teaming, penetration testing, and adversarial simulation.