Fireworks AI: Private AI infrastructure serving developers and enterprises with model training and inference.
3+ YOERequires 3–5 years in GRC, IT audit, information security, or related work; security and privacy framework knowledge; GRC platform experience; access review and security awareness platform administration experience; cloud familiarity.
United States or Massachusetts or New York or California or Colorado
$70k-$88k/yrRemoteFull Time
Coretelligent: Managed IT and cybersecurity services provider serving small, midsized, and highly regulated businesses across the United States.
3+ YOERequires 3+ years in GRC focused on IT or cybersecurity controls, or 3+ years in IT with a cybersecurity focus, plus analytical, organizational, communication, and project management skills.
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
SalesforceNYSE: CRM: The #1 AI CRM driving customer success together.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
Los Angeles or Chicago or Nashville or New York or Seattle
$100k-$135k/yrHybridFull Time
Metropolis Technologies: Building AI for the real world with a computer vision platform for checkout-free payment and mobility services.
3+ YOE3+ years in information security GRC or technology compliance; experience managing security awareness programs; knowledge of SOC 2 and PCI-DSS; familiarity with AI/data security and training platforms; bachelor\u0002s degree required.
RobloxNYSE: RBLX: Global platform for user-created immersive digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
Hillsboro or Irvine or Phoenix or Tacoma or Utah or San Diego or Denver or Liberty Lake or Los Angeles or Las Vegas or Seattle
$80k-$165k/yrOnsiteFull Time
Columbia BankNASDAQ: COLB: Regional financial institution providing banking and wealth management services.
7+ YOE7+ years in information security/IT audit/operations; ServiceNow IRM/GRC experience; knowledge of NIST, FFIEC, CIS, ITIL, COBIT; familiarity with PCI DSS, GLBA, HIPAA; bachelor’s preferred.
Karman Space & DefenseNYSE: KRMN: Provider of mission-critical aerospace and defense system solutions.
5+ YOEBachelor's degree or equivalent experience and 5+ years in cybersecurity GRC, IT audit, risk management, or control assurance. Requires control assessment expertise, regulated-framework knowledge, analytical skills, and stakeholder management.
Microsoft 365, Microsoft Excel, Microsoft PowerPoint, Microsoft Word, Microsoft Teams, Microsoft SharePoint, Microsoft Outlook, ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, Hyperproof
San Francisco or Denver or New York City or Scottsdale or San Jose
$183k-$205k/yrHybridFull Time
Gusto: Gusto is a payroll, benefits, and human-resources software platform serving small and medium-sized businesses.
8+ YOE8+ years in governance, risk, and compliance within SaaS; bachelor's degree required; SOC 2 Type 2 experience; strong communication, analytics, and compliance platform skills; relevant certification preferred.
AdobeNASDAQ: ADBE: Empowering everyone to create through innovative digital experiences.
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
Senior GRC / Third-Party Risk / Data Protection Analyst
California, United States
$104k-$166k/yrRemoteFull Time
Peraton Labs: Private applied research organization developing cybersecurity, communications, electronic-warfare, mobility, and analytics technologies for government and commercial customers.
8+ YOEBachelor's degree or equivalent experience, 8+ years in security GRC, third-party risk, or data protection, active CISA or CGRC, NIST control testing, POA&M management, DLP, GRC, U.S. citizenship, and California clearance.
El Segundo or Los Angeles or Washington or San Francisco or San Diego or Seattle or London
$120k-$150k/yrHybridFull Time
CHAOS Industries: Redefining modern defense with a multi-product portfolio.
5+ YOEBachelor's degree or equivalent experience, 5+ years of GRC or compliance experience, DoD or military experience, audit support, risk assessment, GRC tooling, and knowledge of major security frameworks.
ViasatNASDAQ: VSAT: Global communications providing satellite connectivity and defense solutions.
5+ YOE5+ years in IT audit/compliance or IT risk; bachelor’s or equivalent; SOX/ITGC expertise; experience with control design/testing; strong communication; U.S. citizenship required; CISA/CRISC/CISSP/CPA preferred.
ViasatNASDAQ: VSAT: Global communications providing satellite connectivity and defense solutions.
5+ YOE5+ years in IT audit/compliance/risk, bachelor’s in related field or equivalent, SOX/ITGC expertise, experience designing/testing IT controls, strong communication, CISA/CRISC/CISSP/CPA preferred, U.S. citizenship required.
Ivo: AI-powered contract intelligence platform serving in-house legal and procurement teams at enterprise companies.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yrOnsiteFull Time
SanDiskNASDAQ: SNDK: Specialist in NAND flash memory and data storage solutions.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
Scottsdale or Chicago or San Francisco or New York City
$84k-$105k/yrHybridFull Time
Early Warning Services: U.S. bank-owned fintech and consumer reporting agency providing identity, fraud-risk, and real-time payment solutions to financial institutions.
5+ YOEBachelor's degree in Accounting/Finance/Risk, 5+ years risk experience (3+ in financial services), advanced Microsoft Excel and PowerPoint skills, three-lines-of-defense experience, KRI/GRC familiarity, strong communication.
Senior Governance Risk and Compliance (GRC) Analyst
San Francisco, California, United States
$165k-$190k/yrHybridFull Time
IRENNASDAQ: IREN: Vertically integrated AI cloud and data center infrastructure provider.
5+ YOEBachelor's or master's degree in a relevant field, 5–7 years in cybersecurity or IT program management, FedRAMP authorization leadership, NIST 800-53 expertise, audit experience, and strong analytical and communication skills.
FedRAMP, NIST 800-53, SOC 2, ISO 27001, HITRUST, System Security Plan (SSP)
SpaceXNasdaq: SPCX: Designing, manufacturing, and launching advanced rockets and spacecraft.
1+ YOEBachelor's degree or 3+ years managing cyber assurance for classified systems; 1+ years cyber assurance; RMF A&A lifecycle experience; familiarity with Nessus, Splunk, Security Center, ServiceNow, eMASS, and GRC tools; active TS/SCI clearance and CI polygraph or ability to obtain.
RMF, Nessus, Splunk, Security Center, ServiceNow (SNOW), eMASS, GRC, NRO A&A, JSIG A&A