Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
OpenAI: Develops artificial intelligence models and generative AI software services.
Experienced GRC/product assurance professional with product launch review, customer trust, and security compliance experience; able to build operating models, automation, metrics, and clear customer-facing security narratives.
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
Form Energy: Developing multi-day batteries for grid-scale energy storage.
10+ YOE5+ Mgmt10+ years in cybersecurity/IT GRC with 5+ years leadership; deep ITGC, IAM, EDR/MDR, vulnerability management, incident response, and audit liaison experience; ISO 27001/SOC 2/NIST familiarity; strong executive communication.
Sierra: Conversational AI platform for building enterprise customer agents
10+ YOE3+ Mgmt10+ years in compliance/security/customer trust, 3+ years building/scaling customer-facing security programs, experience with regulated industries, knowledge of security frameworks and multi-cloud, and experience implementing trust automation platforms.
NIST 800-53, SOC 2, ISO 27001, PCI DSS, HIPAA, AWS, GCP, GDPR, UK GDPR, EU AI Act, SIG, CAIQ, ISO 42001, NIST AI RMF, CRM
San Francisco or New York City or London or Sydney
$190k-$215k/yrOnsiteFull Time
Sigma Computing: Cloud-native analytics platform featuring a spreadsheet-style interface.
4+ YOE4+ years GRC experience in SaaS/tech, proven track record building GRC programs and leading SOC 2/ISO 27001/HIPAA audits, experience with ERM frameworks (COSO, ISO 31000, NIST RMF), data privacy (GDPR/CCPA), policy and control development, strong communication.
Risk Consulting - Risk Technology - Oracle GRC - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
5+ YOEBachelor's or master's degree with ~5 years related experience; Oracle security/controls and controls testing experience; strong project management, client service, leadership, communication, analytical skills; valid US driver’s license and passport; willing to travel.
Austin or Tampa or Chicago or Cleveland or Miami or Los Angeles or Boston or New York City or Florham Park or San Diego or San Francisco or Philadelphia or Houston
$99k-$232k/yrOnsiteFull Time
PwC: Providing audit, tax, and management consulting services to businesses.
5+ YOEBachelor's degree,5+ years relevant experience,proficiency with GRC solutions and ServiceNow,knowledge of ISO/IEC 27001 and NIST CSF,team leadership and client-facing skills.
Ivo: AI-powered contract review and intelligence platform for legal teams.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
United States or Canada or Columbus or Austin or San Francisco or New York City
$172k-$238k/yrRemoteFull Time
UpstartNasdaq: UPST: AI-powered lending marketplace for consumer and automotive loans.
8+ YOE3+ MgmtBachelor's or equivalent, 8+ years technology risk/information security/IT audit experience in banking, 3+ years people management, FFIEC/OCC regulatory experience, regulator engagement, and GRC program experience; professional certs preferred.
PenumbraNYSE: PEN: Designs and manufactures medical devices for vascular conditions.
8+ YOEBachelor's in accounting or information systems, 8+ years in IT SOX compliance/InfoSec/IT risk, experience with SOX 404, ITGCs/ITACs, SAP and GRC platforms preferred, strong communication and problem-solving skills.
DocuSignNASDAQ: DOCU: Provides electronic signature and agreement management software solutions.
8+ YOE8+ years in security risk management/GRC, bachelor’s in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and security domain expertise; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, FAIR, Tableau, Power BI
5+ YOE5+ years in security operations/GRC/IT security, SOC 2 familiarity, incident response, endpoint and access controls, vendor and MSP management, strong communication and independent execution.
15+ YOE15+ years in risk operations, compliance, internal audit or information security with leadership experience; experience building controls assurance, third-party risk, incident response, and AI safety; familiarity with auditors/regulators and GRC platforms.
Parafin: Embedded financial infrastructure for small business platforms.
3+ YOE3+ years compliance or business banking experience; familiarity with vendor management, SOC1/SOC2, risk/GRC processes; strong communication and multi-tasking; experience with BSA/AML/OFAC/KYC and bank partners preferred.
DocuSignNASDAQ: DOCU: Provider of e-signature and intelligent agreement management software.
8+ YOE8+ years in security risk/GRC, Bachelor's in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and strong communication; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, Tableau, Power BI
Mintlify: AI-powered platform for generating and hosting software documentation.
3+ YOE3+ years GRC/compliance program management with direct audit ownership, hands-on Drata (or Vanta) administration, vendor and auditor management, strong follow-through and automation bias.
United States or San Francisco or New York City or London or Dublin or Tel Aviv or Sydney
$179k-$210k/yrRemoteFull Time
Vanta: Automated security compliance and trust management software for businesses.
8+ YOE8+ years customer success experience managing high-value public sector accounts; deep knowledge of GovRAMP, NIST, CJIS; SaaS/GRC expertise; strong executive communication; US work authorization required.
Strava: Fitness tracking and social networking app for athletes.
8+ YOEBachelor's degree,8-12 years in security or technical risk,security certification (CISSP or CISM) preferred,experience building GRC/risk programs,AI/automation in security,team management and executive reporting.