Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in GRC or information security; deep cloud (GCP/AWS) and security architecture; strong regulatory experience; automation mindset with GRC tools.
GCP, AWS, Vanta, Drata, SOC 2, ISO 27001, PCI, HIPAA
Postman: Platform for building, testing, and managing software APIs.
6+ YOE6+ years GRC experience in tech, SOC2/ISO27001/HIPAA/GDPR/CCPA/FedRAMP knowledge, proficiency in Python or JavaScript, experience integrating GRC tooling, and strong communication.
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
Fireworks AI: Provides high-performance generative AI model inference and deployment infrastructure.
5+ YOE5+ years in GRC/IT audit or information security; working knowledge of SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR; experience with GRC platforms, user access reviews, security awareness tooling, and cloud environments; strong communication.
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
Brex: Corporate cards and spend management software for businesses.
5+ YOE5+ years in GRC or Security Engineering; strong automation; security frameworks SOC 2, PCI DSS, ISO 27001; Python and API integrations; cross-functional collaboration; cloud native; Terraform.
Phylo: An applied research lab building AI agents for biomedical discovery.
5+ YOE5+ years in security GRC or adjacent role; experience leading SOC 2, ISO 27001, HIPAA, FedRAMP or similar; cloud and application security knowledge; audit and enterprise customer review experience; strong cross-functional communication.
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
United States or San Francisco or New York City or Bengaluru
$150k-$200k/yrHybridFull Time
Mesh: Connecting digital wallets and exchanges for unified cryptocurrency payments.
5+ YOERequires 5+ years of hands-on GRC experience, compliance program management, major security framework familiarity, business continuity and disaster recovery experience, risk lifecycle expertise, and scalable process-building skills.
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
Airwallex: Global financial platform for business payments and money management.
5+ YOE5-7 years cybersecurity experience, Mexican Tax ID (RFC) or dual Mexican citizenship required, fluent English and Spanish, knowledge of PCI-DSS/ISO 27001/SOC2, fintech and cloud compliance experience, CISSP/CEH/CISA strong advantage.
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
New York City or San Francisco or Seattle or United States
$150k-$210k/yrRemoteFull Time
Runway: Develops generative AI software for creative video production.
7+ YOE7+ years in information security, risk or compliance; deep knowledge of NIST/SOC 2/ISO frameworks; hands-on SOC 2 Type II and ISO 27001 audits; GDPR/CCPA operational experience; cloud security and ML/AI understanding.
NIST, SOC 2, ISO 27001, ISO 27701, ISO 42001, FedRAMP, GDPR, CCPA
Senior SAP Security and GRC Consultant (Contractor)
Bengaluru or San Jose
OnsiteContract
ArchLynk: Consulting services for global supply chain and trade operations
5+ YOEBachelor's degree in a relevant field and 5+ years of SAP Security and GRC experience, including SAP GRC 12.0, access control, role design, user administration, SoD, and SAP Fiori security.
SAP, S/4HANA, ECC, BW, Fiori, SAP GRC 12.0, RBAC, GDPR
Tata Consultancy ServicesNational Stock Exchange of India: TCS: Global provider of IT services, consulting, and business solutions.
5+ YOERequires 5+ years in cybersecurity, TPRM, GRC, or supplier risk; knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ; GRC tool experience and strong client-facing communication.