SolutionBox Insight: Agentic software creation platform that lets anyone build applications using natural language.
8+ YOE8+ years in GRC or information security; deep cloud (GCP/AWS) and security architecture; strong regulatory experience; automation mindset with GRC tools.
GCP, AWS, Vanta, Drata, SOC 2, ISO 27001, PCI, HIPAA
ButterflyMX: Cloud-based property access platform providing hardware and software security solutions to multifamily and commercial property owners.
3+ YOE3+ years in GRC or risk/compliance; SOC 2 audit experience; Vanta experience; familiarity with NIST/ISO frameworks; strong writing and organizational skills; proven use of AI tooling to automate GRC workflows.
Velera: Credit-union-owned payments CUSO and fintech provider serving more than 4,000 financial institutions.
10+ YOEBachelor's degree or equivalent experience; 10+ years as a DBA or GRC Engineer; database compliance, security GRC, program management, control automation, stakeholder collaboration, and AI solutions experience.
Flock Safety: Public-safety technology serving law enforcement, communities, and businesses with license-plate, video, audio, drone, and investigative systems.
Experience in GRC/IT audit for cloud/SaaS, SOC 2 and ISO frameworks, automation of compliance workflows, customer due diligence, and collaboration with engineering and legal teams.
NinjaTrader: Privately held futures trading platform and brokerage serving retail and professional futures traders.
3+ YOE3–5 years in GRC/IT audit/security compliance; hands-on SOC 2/ISO 27001/SOX audits; scripting/automation with Python and REST APIs; familiarity with major cloud platforms and CI/CD; strong documentation and stakeholder skills.
Oscar HealthNYSE: OSCR: Technology-driven health insurance and managed care provider.
7+ YOERequires 7+ years in GRC, cloud security, security engineering, audit, or regulated technology; expertise in CMS EDE, NIST SP 800-53, AWS control implementation, compliance automation, audits, and risk management.
AWS, Azure, NIST SP 800-53, infrastructure as code, policy as code, GRC platforms, SIEM
Workstreet: AI-powered cybersecurity and compliance firm serving high-growth technology companies with security, privacy, and compliance services.
3+ YOE3+ Mgmt3+ years GRC experience with SOC 2/ISO 27001/NIST CSF, 3+ years people leadership, client relationship management, project management, policy development, strong written and verbal English.
Midcontinent Independent System Operator: Independent nonprofit regional transmission organization managing high-voltage electricity for 45 million people across 15 states and Manitoba.
10+ YOERequires 10+ years of professional experience, including 4 years in GRC engineering or a similar role, scripting, REST API integration, enterprise GRC platforms, and risk and compliance operations.
Austin or Chicago or New York City or Redwood City or San Francisco or United States
$130k-$145k/yrHybridFull Time
BoxNYSE: BOX: Intelligent content management and collaboration platform.
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
Berlin or Iași or London or New York City or São Paulo
HybridFull Time
Taktile: Fintech providing an AI-powered decision platform for banks, insurers, and other financial institutions.
4+ YOE4+ years GRC or security compliance at a SaaS company; owned SOC 2 program; Vanta/Drata/Secureframe experience; hands-on scripting against AWS for automated evidence; strong written communication.
Columbus or Chicago or Detroit or Tupelo or Charlotte or Dallas or Atlanta or Houston or Birmingham
$70k-$140k/yrOnsiteFull Time
Huntington BankNASDAQ: HBAN: A regional bank offering consumer, commercial, and financial services.
5+ YOEBachelor's degree or 4+ years equivalent experience, 5+ years software development, and preferably 5+ years in GRC systems. Requires analytical, troubleshooting, communication, and programming skills.
Archer, OpenPages, ProcessUnity, ServiceNow IRM, AWS, Apigee, Linux OS, OpenShift, .NET, C#, Python, Java, Microsoft Office
ezCater: Workplace food platform connecting organizations to restaurants for corporate catering and employee meal programs.
8+ YOE8+ years in security GRC or compliance for SaaS/cloud; deep knowledge of ISO-27001, NIST CSF, SOC 2, ITGC, PCI; experience automating control testing and evidence collection; familiarity with Policy-as-Code (Terraform), AWS, GitHub; strong communication.
Verkada: Physical security platform for enterprise buildings and facilities.
7+ YOERequires 7+ years in security or IT compliance, cloud service experience, software compliance experience, and SOC 2 or ISO 27001 audit, risk, and compliance experience.
ZBD: Private gaming fintech providing licensed financial infrastructure, rewards, payouts, and accounts for game developers and publishers.
3+ YOE3+ years in security governance, cloud and application security, risk management, and third-party risk; experience with Infrastructure as Code (Terraform/OpenTofu), Linux, Git/GitLab and CI/CD; strong security and compliance skills.
CloudflareNYSE: NET: Cloud-based security, performance, and reliability services for Internet applications.
5+ YOE5+ years in security/compliance/automation; strong automation and IaC/Policy-as-Code experience (Terraform, Pulumi, OPA/Rego); proficiency with Python/Go, JS/TypeScript, React, REST APIs; AI governance experience.
Palo Alto NetworksNASDAQ: PANW: Global cybersecurity platform providing network, cloud, and AI-driven security solutions.
10+ YOERequires 10+ years in information security or IT risk, including 6+ years in GRC, a computer science or cybersecurity-related degree, and active CISSP, CRISC, CISM, or CISA certification.
AWS, Azure, GCP, NIST SP 800-53, NIST CSF, SOC 2 Type II, PCI-DSS, GDPR, NIST AI RMF, ISO 42001