Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in GRC or information security; deep cloud (GCP/AWS) and security architecture; strong regulatory experience; automation mindset with GRC tools.
GCP, AWS, Vanta, Drata, SOC 2, ISO 27001, PCI, HIPAA
Legora: AI workspace for legal document research and drafting.
6+ YOE6+ years in GRC, security compliance, or IT audit in B2B SaaS; ownership of SOC 2/ISO 27001; AI governance and regulatory knowledge; risk and policy experience; ability to read code and verify controls.
ButterflyMX: Smart video intercom and building access control systems.
3+ YOE3+ years in GRC or risk/compliance; SOC 2 audit experience; Vanta experience; familiarity with NIST/ISO frameworks; strong writing and organizational skills; proven use of AI tooling to automate GRC workflows.
São Paulo or Denver or Colombia or Argentina or Brazil or Costa Rica or United States
RemoteContract
AspenView: Provides nearshore software engineering and digital transformation services.
3+ YOE3+ years GRC experience; hands-on with GRC tools (Archer, LogicGate, ServiceNow GRC); familiarity with ISO 27001, SOC 2, NIST CSF, HIPAA, SOX; strong analytical and communication skills.
University of Oklahoma: A public research university in Norman, Oklahoma.
Bachelor's in Computer Science/IT or equivalent experience; knowledge of cybersecurity frameworks, risk assessments, GRC platforms, vulnerability scanning, strong communication and analytical skills.
Postman: Platform for building, testing, and managing software APIs.
6+ YOE6+ years GRC experience in tech, SOC2/ISO27001/HIPAA/GDPR/CCPA/FedRAMP knowledge, proficiency in Python or JavaScript, experience integrating GRC tooling, and strong communication.
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
Brain Co.: Builds AI software platforms for governments and large enterprises.
8+ YOE8+ years building and running GRC programs in regulated environments; hands-on with SOC 2 Type II, HIPAA, ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA.
Fluidstack: Provides high-performance cloud GPU infrastructure for AI development.
Experienced in operating compliance controls and audits across SOC 2, ISO 27001, NIST 800-53 or FedRAMP; owning policy sets, evidence collection, and audit readiness on GRC platforms.
Vercel: Frontend cloud platform for building and hosting web applications.
3+ YOE3+ years supporting audit lifecycle in cloud environments; manage ISO/SOC/HIPAA/PCI compliance, collaborate with engineering, strong project management and communication; familiarity with cloud and GRC tools.
MACOMNASDAQ: MTSI: Designs and manufactures semiconductor products for communications infrastructure.
1+ YOEBachelor's in relevant field (or equivalent), 1–3 years information security/risk/compliance experience, knowledge of security frameworks, strong analytical and communication skills, and willingness to learn ServiceNow GRC.
ServiceNow GRC, NIST, ISO 27001, SOC2, CIS, ISO9001, ISO14001
Hayward HoldingsNYSE: HAYW: Manufacturer of residential and commercial swimming pool equipment.
3+ YOEBachelor's degree in Accounting, Information Systems, Cybersecurity or related; 3+ years SOX-focused GRC/audit experience; hands-on Varonis and SailPoint experience; strong ITGC/ICFR and audit evidence knowledge.
Valence: Builds an AI-native leadership coaching platform for enterprise customers.
Experienced in running GRC and security compliance programs (SOC 2, ISO 27001, ISO 42001), audit coordination, risk management, cloud security (AWS/Azure), and cross-functional stakeholder collaboration.
SOC 2, ISO 27001, ISO 42001, NIST CSF, GDPR, EU AI Act, AWS, Azure, Vanta, Drata, Secureframe, OneTrust, Archer
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
Charlie Health: Providing virtual intensive outpatient programs for mental health and recovery.
5+ YOE5+ years in GRC/security engineering; hands-on experience building automated controls, continuous control monitoring, audit evidence pipelines; familiarity with HIPAA, SOC 2, NIST, ISO 27001 and enterprise systems.