Oscar HealthNYSE: OSCR: Provides tech-enabled health insurance plans and telemedicine services.
7+ YOERequires 7+ years in GRC, cloud security, security engineering, audit, or regulated technology; expertise in CMS EDE, NIST SP 800-53, AWS control implementation, compliance automation, audits, and risk management.
AWS, Azure, NIST SP 800-53, infrastructure as code, policy as code, GRC platforms, SIEM
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
Berlin or Iași or London or New York City or São Paulo
HybridFull Time
Taktile: Platform for automated financial risk and credit decisioning.
4+ YOE4+ years GRC or security compliance at a SaaS company; owned SOC 2 program; Vanta/Drata/Secureframe experience; hands-on scripting against AWS for automated evidence; strong written communication.
New York City or Maryland or Massachusetts or Virginia or Georgia or New York
$97k-$184k/yrOnsiteFull Time
Chainalysis: Blockchain data platform for cryptocurrency investigation and compliance.
Experience implementing and operating security and compliance controls in cloud/SaaS environments; built evidence collection, control testing, or remediation workflows; supported SOC 2/ISO 27001 or similar; strong written/verbal communication; US citizenship required.
Hospital for Special Surgery: Provides specialized orthopedic, rheumatologic healthcare and medical research.
Translate security and regulatory requirements into technical control objectives, implement automated control testing and evidence collection, perform technical risk assessments, support audits, and develop policy-as-code and tooling for continuous compliance.
FiservNew York Stock Exchange: FI: Provides financial technology and payment processing services to institutions.
8+ YOERequires 8+ years in governance, risk, compliance, cybersecurity, or related disciplines; 5+ years in enterprise architecture or senior engineering; AI governance, REST APIs, OAuth, scripting, and GRC platform expertise.
OneTrust, Archer, REST APIs, OAuth, Python, JavaScript, Power BI
xAI: Develops advanced artificial intelligence systems to understand the universe.
8+ YOE8+ years GRC/security compliance experience in fintech or financial services; hands-on PCI/NYDFS/FFIEC experience; Compliance-as-Code and GRC automation; technical fluency with cloud and security architecture.
Anthropic: Developing safe and reliable artificial intelligence systems.
8+ YOE8+ years building backend systems, data pipelines, or internal platforms; proficiency in Python or Go; experience with cloud platforms and infrastructure-as-code; strong systems thinking and experience with integrations or data infrastructure.
Python, Go, AWS, GCP, Azure, Claude, ServiceNow, Vanta, Drata, OneTrust, REST APIs, webhooks, CI/CD, ELT, ETL, infrastructure-as-code, version control
Compyl: A venture-backed building an automated GRC and security compliance platform for security practitioners.
4+ YOE4+ years in sales engineering or technical consulting, cloud infrastructure knowledge (Azure preferred), familiarity with GRC domains and regulatory frameworks, strong communication and collaboration skills.
Omnea: AI platform for automating enterprise procurement and supplier risk.
3+ YOE3+ years in sales/solutions engineering or technical consulting, experience with ERPs/CLMs/GRC or procurement stack, comfortable directing AI for demos/PoCs, strong communicator, able to own RFPs/RFIs/security questionnaires.
InterDigitalNasdaq: IDCC: Researches and licenses wireless and video communication technologies.
Senior cybersecurity engineer with expertise across enterprise, cloud, AI, IAM, GRC, vulnerability management, and incident response; familiarity with security frameworks; bachelor’s or equivalent and relevant certifications preferred.
DatadogNASDAQ: DDOG: Observability and security platform for cloud applications and infrastructure.
Experience leading security/GRC engineering teams, building automation and tooling for compliance, strong technical background (code review, cloud, Kubernetes), and excellent communication and leadership skills.
Deloitte: Global provider of audit, consulting, tax, and advisory services.
2+ YOEBachelor's degree in engineering or related field and 2 years experience; experience with ServiceNow, ITSM/ITOM, MS Office, SAFe Agile, GRC; requirements analysis, user stories, UAT, testing, and production incident triage.
Microsoft Office, Microsoft Excel, Microsoft PowerPoint, Microsoft Word, ServiceNow, ServiceNow ITSM, ServiceNow Agile, ITSM, ITOM, GRC, Safe agile
Forus: A building an AI-powered platform that connects doctors, pharmacies, payers, and biopharma to accelerate patient access to therapies.
4+ YOE4+ years in GRC/security compliance with hands-on SOC 2 and HIPAA experience, HITRUST a plus; experience with compliance automation, vendor risk, audits, and working with engineering and enterprise buyers.
ChubbNYSE: CB: Provides property, casualty, and life insurance and reinsurance services globally.
5+ YOERequires 5+ years in GRC technology, IT automation, or security platform engineering; ServiceNow IRM development; Python scripting; cyber risk, compliance, or audit experience; and a relevant bachelor's degree or equivalent.