Mintlify: AI-powered platform for generating and hosting software documentation.
3+ YOE3+ years GRC/compliance program management with direct audit ownership, hands-on Drata (or Vanta) administration, vendor and auditor management, strong follow-through and automation bias.
Substack: Platform for independent writers to publish and monetize newsletters.
3+ YOE3–5 years in corporate IT/systems administration; hands-on Okta and Apple-focused MDM experience (Iru/Kandji/Jamf); familiarity with SOC 2 and compliance platforms (Vanta/Drata); strong communication and documentation skills.
San Francisco or New York City or London or Sydney
$190k-$215k/yrOnsiteFull Time
Sigma Computing: Cloud-native analytics platform featuring a spreadsheet-style interface.
4+ YOE4+ years GRC experience in SaaS/tech, proven track record building GRC programs and leading SOC 2/ISO 27001/HIPAA audits, experience with ERM frameworks (COSO, ISO 31000, NIST RMF), data privacy (GDPR/CCPA), policy and control development, strong communication.
WindBorne Systems: Operates smart weather balloons to provide global atmospheric data.
3+ YOE3+ years in compliance audits and US government compliance; experience with CMMC, FedRAMP, NIST frameworks; security, cloud, and GRC tooling expertise; ability to obtain security clearance.
Drata, Vanta, eMASS, Tenable Security Center, Burp, SIEM, AWS, Azure
AKASA: Develops AI-powered automation software for healthcare revenue cycle management.
8+ YOE2+ MgmtRequires 8+ years in security compliance, GRC, or risk management, including 2+ years leading a team or function; expertise in HITRUST, SOC 2, HIPAA, AI governance, and compliance automation.
NIST AI RMF, Okta, Google Workspace, Kandji, Iru, SentinelOne, Nightfall, AWS, Vanta, Drata, Hyperproof, ChatGPT, Claude, Python, Zapier, Tray.io
Clearstory: SaaS platform for managing construction project change orders.
4+ YOE4-7 years in IT operations, security operations, or SaaS business operations; hands-on SOC 2 audit coordination; Google Workspace admin; experience with compliance platforms; SaaS vendor management; automation mindset; collaborates with CTO; proactive, process-driven.
Anthropic: Developing safe and reliable artificial intelligence systems.
8+ YOE8+ years building backend systems, data pipelines, or internal platforms; proficiency in Python or Go; experience with cloud platforms and infrastructure-as-code; strong systems thinking and experience with integrations or data infrastructure.
Python, Go, AWS, GCP, Azure, Claude, ServiceNow, Vanta, Drata, OneTrust, REST APIs, webhooks, CI/CD, ELT, ETL, infrastructure-as-code, version control
Aegis Ventures: Venture studio building healthcare and artificial intelligence companies.
5+ YOERequires 5+ years of compliance experience in B2B SaaS or healthcare technology, HIPAA and SOC 2 expertise, HITRUST knowledge, technical-controls collaboration, policy writing, and strong cross-functional communication.
Avandra Imaging: Federated network for de-identified medical imaging and clinical data.
5+ YOERequires 5+ years of hands-on compliance experience in B2B SaaS or healthcare technology, HIPAA and HITRUST knowledge, SOC 2 Type II experience, technical-control collaboration, and strong writing skills.
Neurophos: Develops high-performance photonic processors for AI inference acceleration.
8+ YOERequires 8+ years in infrastructure security, security engineering, or cybersecurity management, including 3+ years leading security programs; expertise in cloud security, networks, IAM, endpoints, incident response, and compliance.
VeSync: Designs and sells smart home appliances and wellness products.
3+ YOE3+ years information security experience, hands-on security monitoring, incident response, vulnerability management, familiarity with cloud (AWS/Azure/GCP), security frameworks, and strong communication skills.
NavanNasdaq: NAVN: Integrated platform for corporate travel and expense management.
6+ YOE6+ years in security GRC/auditing, hands-on ISMS management, experience with PCI, SOX, ISO 27001/42001, SOC 1/2, control automation, auditor coordination, and cloud security.
HEN Technologies: Building an AI-powered intelligent ecosystem for fire suppression.
12+ YOE4+ Mgmt12+ years in information security with 4+ years leading a security function; SOC 2 leadership; strong cloud (GCP) and product security experience; hands-on technical credibility with IaC/CI/CD and vendor risk/IR processes.
Anomali: AI-powered platform for threat intelligence and security analytics.
8+ YOE3+ Mgmt8+ years in GRC/compliance with 3+ years leadership; hands-on FedRAMP, ISO 27001, SOC 2 experience; regional cloud frameworks (DESC, Saudi NCA/CCC, IRAP); cloud security (AWS/Azure/GCP); strong stakeholder and written communication.
Vapi: Build and deploy AI-powered voice agents via flexible APIs.
5+ YOE5+ years engineering experience in cloud-native SaaS; strong security experience for multi-tenant cloud environments; proficiency with AWS, Kubernetes, and Postgres; ability to write/review code and implement shift-left security.
Obsidian Security: Provides cybersecurity and threat detection for enterprise SaaS applications.
8+ YOE8+ years building and operating identity, endpoint, or platform infrastructure; deep Okta and Jamf Pro experience; IaC with Terraform/OpenTofu; scripting in Python or PowerShell; strong written and verbal communication.
Volta: Building and operating GPU-dense infrastructure for AI factories.
3+ YOE3+ years in information security with compliance/GRC/audit experience, hands-on ISO 27001 or SOC 2 work, GRC platform experience, risk assessment skills, strong writing and collaboration with engineers.