Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in GRC or information security; deep cloud (GCP/AWS) and security architecture; strong regulatory experience; automation mindset with GRC tools.
GCP, AWS, Vanta, Drata, SOC 2, ISO 27001, PCI, HIPAA
Postman: Platform for building, testing, and managing software APIs.
6+ YOE6+ years GRC experience in tech, SOC2/ISO27001/HIPAA/GDPR/CCPA/FedRAMP knowledge, proficiency in Python or JavaScript, experience integrating GRC tooling, and strong communication.
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
Fireworks AI: Provides high-performance generative AI model inference and deployment infrastructure.
5+ YOE5+ years in GRC/IT audit or information security; working knowledge of SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR; experience with GRC platforms, user access reviews, security awareness tooling, and cloud environments; strong communication.
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
Brex: Corporate cards and spend management software for businesses.
5+ YOE5+ years in GRC or Security Engineering; strong automation; security frameworks SOC 2, PCI DSS, ISO 27001; Python and API integrations; cross-functional collaboration; cloud native; Terraform.
Los Angeles or Chicago or Nashville or New York or Seattle
$100k-$135k/yrHybridFull Time
Metropolis: Computer vision technology for checkout-free parking and retail payments.
3+ YOE3+ years in information security GRC or technology compliance; experience managing security awareness programs; knowledge of SOC 2 and PCI-DSS; familiarity with AI/data security and training platforms; bachelor\u0002s degree required.
Delan Associates: Provides engineering and professional services to government agencies.
15+ YOERequires 15+ years of experience with SAP GRC 12.0 AC/PC, implementation and upgrades, access controls, risk management, cloud integration, testing, deployment, and production support.
SAP GRC 12.0 Access Control (AC), SAP GRC 12.0 Process Control (PC), Access Risk Analysis (ARA), Access Request Management (ARM), Emergency Access Management (EAM), Business Role Management (BRM), Segregation of Duties (SoD), MSMP, SAP GRC Cloud, SAP GRC SuccessFactors (SF)
Phylo: An applied research lab building AI agents for biomedical discovery.
5+ YOE5+ years in security GRC or adjacent role; experience leading SOC 2, ISO 27001, HIPAA, FedRAMP or similar; cloud and application security knowledge; audit and enterprise customer review experience; strong cross-functional communication.
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
Hillsboro or Irvine or Phoenix or Tacoma or Utah or San Diego or Denver or Liberty Lake or Los Angeles or Las Vegas or Seattle
$80k-$165k/yrOnsiteFull Time
Columbia BankNASDAQ: COLB: Commercial and consumer banking services in the Western United States.
7+ YOE7+ years in information security/IT audit/operations; ServiceNow IRM/GRC experience; knowledge of NIST, FFIEC, CIS, ITIL, COBIT; familiarity with PCI DSS, GLBA, HIPAA; bachelor’s preferred.
SHEIN: Global online retailer selling affordable fashion and lifestyle products.
7+ YOE7+ years in information security risk management; bachelor’s degree; CISSP/CISM/CISA or ISO 27001 Lead Auditor desirable; strong standards knowledge; team leadership experience.
Panda Restaurant Group: Operator of American Chinese fast-casual restaurant chains.
7+ YOEBachelor's degree, 7+ years GRC/privacy/security/technology risk experience, knowledge of AI governance and cybersecurity frameworks, policy and program design, and strong advisory skills.
NIST AI RMF, EU AI Act, ISO 42001, NIST CSF, NIST 800-53, ISO 27001, ISO 27002, CIS
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
Airwallex: Global financial platform for business payments and money management.
5+ YOE5-7 years cybersecurity experience, Mexican Tax ID (RFC) or dual Mexican citizenship required, fluent English and Spanish, knowledge of PCI-DSS/ISO 27001/SOC2, fintech and cloud compliance experience, CISSP/CEH/CISA strong advantage.