SolutionBox Insight: Agentic software creation platform that lets anyone build applications using natural language.
8+ YOE8+ years in GRC or information security; deep cloud (GCP/AWS) and security architecture; strong regulatory experience; automation mindset with GRC tools.
GCP, AWS, Vanta, Drata, SOC 2, ISO 27001, PCI, HIPAA
Austin or Chicago or New York City or Redwood City or San Francisco or United States
$130k-$145k/yrHybridFull Time
BoxNYSE: BOX: Intelligent content management and collaboration platform.
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
Verkada: Physical security platform for enterprise buildings and facilities.
7+ YOERequires 7+ years in security or IT compliance, cloud service experience, software compliance experience, and SOC 2 or ISO 27001 audit, risk, and compliance experience.
Palo Alto NetworksNASDAQ: PANW: Global cybersecurity platform providing network, cloud, and AI-driven security solutions.
10+ YOERequires 10+ years in information security or IT risk, including 6+ years in GRC, a computer science or cybersecurity-related degree, and active CISSP, CRISC, CISM, or CISA certification.
AWS, Azure, GCP, NIST SP 800-53, NIST CSF, SOC 2 Type II, PCI-DSS, GDPR, NIST AI RMF, ISO 42001
RobloxNYSE: RBLX: Global platform for user-created immersive digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
Lendistry: Minority-led CDFI fintech lender providing loans and grant programs to underserved small businesses nationwide.
3+ YOE3-5 years in GRC, data privacy, risk management; SOC 2 and GLBA; cloud experience (AWS/Azure); privacy engineering; CIPT/CDPSE required; CIPM/CISSP preferred; B.S. in CS/Info Security or equivalent.
Anduril Industries: Defense technology developing AI-powered autonomous military systems.
6+ YOE6+ years in security engineering or GRC, programming and automation experience, compliance framework expertise, cloud and SaaS integrations, infrastructure as code, technical leadership, and eligibility for a U.S. Secret clearance.
xAI: Artificial intelligence research and development.
8+ YOE8+ years GRC/security compliance experience in fintech or financial services; hands-on PCI/NYDFS/FFIEC experience; Compliance-as-Code and GRC automation; technical fluency with cloud and security architecture.
3+ YOERequires 3+ years in technical security, Python, TypeScript, SQL, API and database experience, cloud security expertise, and familiarity with Terraform, CI/CD, Git, Docker, or Kubernetes.
F5NASDAQ: FFIV: Delivering and securing applications across any multi-cloud environment.
10+ YOEBachelor's degree required; 10+ years in cybersecurity/GRC with 3–5 years hands-on engineering; Python, API, and systems-integration experience; ServiceNow IRM and Agentic/LLM framework familiarity; professional certs preferred.
SCAN Group: Nonprofit healthcare organization providing Medicare Advantage coverage and care services for older adults.
7+ YOE7+ years information security experience (2+ years in AI security), Bachelor's in related field required (Master's preferred). Hands-on experience with AI platforms and vendor risk assessment; knowledge of HIPAA, NIST AI RMF, HITRUST, threat modeling, and AI red-teaming.
Microsoft Copilot Studio, Microsoft Azure AI Foundry, Snowflake Cortex, Claude Code, Anthropic APIs, GitHub Copilot, Cursor, OpenAI API, LangChain, AutoGen, Semantic Kernel, Model Context Protocol (MCP), Claude Code CLI, GitHub Copilot CLI, Microsoft Azure Developer CLI, Microsoft Copilot Enterprise, Microsoft Power Platform, Snowpark, Hugging Face, Azure Model Catalog, Garak, PyRIT, PromptBench, MITRE ATLAS, MITRE ATT&CK, SIEM, SOAR, OAuth 2.0, mTLS, OIDC, SAML, HITRUST CSF, NIST AI RMF, OWASP Top 10 for LLM Applications, STRIDE, PASTA, retrieval-augmented generation (RAG)
5+ YOE5+ years in security or compliance engineering; hands-on SOC 2 Type II audit ownership; cloud security (AWS/GCP/Azure); GRC tooling experience; strong written communication and policy authorship skills.
SOC 2 Type II, ISO 27001, GDPR, CCPA, AWS, GCP, Azure, Sprinto, Tugboat Logic, GRC, CI/CD, infrastructure-as-code, DevSecOps, SDLC, IAM
Anthropic: AI research developing safe and steerable AI systems.
8+ YOE8+ years building backend systems, data pipelines, or internal platforms; proficiency in Python or Go; experience with cloud platforms and infrastructure-as-code; strong systems thinking and experience with integrations or data infrastructure.
Python, Go, AWS, GCP, Azure, Claude, ServiceNow, Vanta, Drata, OneTrust, REST APIs, webhooks, CI/CD, ELT, ETL, infrastructure-as-code, version control
Clearly AI: AI-powered security and privacy review software for enterprise security, privacy, and compliance teams.
2+ YOE2+ years in GRC, privacy, or security engineering; hands-on threat modeling, vendor risk, and security tool integrations; strong project management and customer debugging skills.