Oscar HealthNYSE: OSCR: Technology-driven health insurance and managed care provider.
7+ YOERequires 7+ years in GRC, cloud security, security engineering, audit, or regulated technology; expertise in CMS EDE, NIST SP 800-53, AWS control implementation, compliance automation, audits, and risk management.
AWS, Azure, NIST SP 800-53, infrastructure as code, policy as code, GRC platforms, SIEM
Austin or Chicago or New York City or Redwood City or San Francisco or United States
$130k-$145k/yrHybridFull Time
BoxNYSE: BOX: Intelligent content management and collaboration platform.
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
Berlin or Iași or London or New York City or São Paulo
HybridFull Time
Taktile: Fintech providing an AI-powered decision platform for banks, insurers, and other financial institutions.
4+ YOE4+ years GRC or security compliance at a SaaS company; owned SOC 2 program; Vanta/Drata/Secureframe experience; hands-on scripting against AWS for automated evidence; strong written communication.
New York City or Maryland or Massachusetts or Virginia or Georgia or New York
$97k-$184k/yrOnsiteFull Time
Chainalysis: Blockchain data and AI platform serving governments, crypto businesses, and financial institutions with investigation and compliance tools.
Experience implementing and operating security and compliance controls in cloud/SaaS environments; built evidence collection, control testing, or remediation workflows; supported SOC 2/ISO 27001 or similar; strong written/verbal communication; US citizenship required.
Hospital for Special Surgery: Academic medical center specializing in musculoskeletal health.
Translate security and regulatory requirements into technical control objectives, implement automated control testing and evidence collection, perform technical risk assessments, support audits, and develop policy-as-code and tooling for continuous compliance.
FiservNYSE: FI: Global leader in financial services technology solutions.
8+ YOERequires 8+ years in governance, risk, compliance, cybersecurity, or related disciplines; 5+ years in enterprise architecture or senior engineering; AI governance, REST APIs, OAuth, scripting, and GRC platform expertise.
OneTrust, Archer, REST APIs, OAuth, Python, JavaScript, Power BI
xAI: Artificial intelligence research and development.
8+ YOE8+ years GRC/security compliance experience in fintech or financial services; hands-on PCI/NYDFS/FFIEC experience; Compliance-as-Code and GRC automation; technical fluency with cloud and security architecture.
3+ YOERequires 3+ years in technical security, Python, TypeScript, SQL, API and database experience, cloud security expertise, and familiarity with Terraform, CI/CD, Git, Docker, or Kubernetes.
Anthropic: AI research developing safe and steerable AI systems.
8+ YOE8+ years building backend systems, data pipelines, or internal platforms; proficiency in Python or Go; experience with cloud platforms and infrastructure-as-code; strong systems thinking and experience with integrations or data infrastructure.
Python, Go, AWS, GCP, Azure, Claude, ServiceNow, Vanta, Drata, OneTrust, REST APIs, webhooks, CI/CD, ELT, ETL, infrastructure-as-code, version control
Compyl: AI-powered GRC platform for CISOs and compliance, risk, audit, and security teams.
4+ YOE4+ years in sales engineering or technical consulting, cloud infrastructure knowledge (Azure preferred), familiarity with GRC domains and regulatory frameworks, strong communication and collaboration skills.
Omnea: Private UK B2B SaaS providing AI-powered procurement and supplier risk-management software to businesses.
3+ YOE3+ years in sales/solutions engineering or technical consulting, experience with ERPs/CLMs/GRC or procurement stack, comfortable directing AI for demos/PoCs, strong communicator, able to own RFPs/RFIs/security questionnaires.
DatadogNASDAQ: DDOG: Cloud observability and security platform for the AI era.
Experience leading security/GRC engineering teams, building automation and tooling for compliance, strong technical background (code review, cloud, Kubernetes), and excellent communication and leadership skills.
Forus: AI-powered healthcare technology automating prior authorizations, affordability, and pharmacy routing for doctors, patients, and biopharma.
4+ YOE4+ years in GRC/security compliance with hands-on SOC 2 and HIPAA experience, HITRUST a plus; experience with compliance automation, vendor risk, audits, and working with engineering and enterprise buyers.
Compass International HoldingsNYSE: COMP: Technology-driven residential real estate brokerage and software platform.
12+ YOE10+ Mgmt12+ years technical experience, 10+ years senior security leadership, deep expertise across AppSec, cloud security, identity, GRC, incident response; hands-on engineering background preferred; experience with SOX and CPRA.
Jane Street: A global quantitative trading firm and liquidity provider.
3+ YOEBachelor's degree in finance, engineering, computer science, or related quantitative field plus 3 years of cybersecurity GRC experience. Requires vendor risk, regulatory compliance, assessments, and OCaml/Python trading-environment experience.