Legora: AI workspace for legal document research and drafting.
6+ YOE6+ years in GRC, security compliance, or IT audit in B2B SaaS; ownership of SOC 2/ISO 27001; AI governance and regulatory knowledge; risk and policy experience; ability to read code and verify controls.
Fluidstack: Provides high-performance cloud GPU infrastructure for AI development.
Experienced in operating compliance controls and audits across SOC 2, ISO 27001, NIST 800-53 or FedRAMP; owning policy sets, evidence collection, and audit readiness on GRC platforms.
Valence: Builds an AI-native leadership coaching platform for enterprise customers.
Experienced in running GRC and security compliance programs (SOC 2, ISO 27001, ISO 42001), audit coordination, risk management, cloud security (AWS/Azure), and cross-functional stakeholder collaboration.
SOC 2, ISO 27001, ISO 42001, NIST CSF, GDPR, EU AI Act, AWS, Azure, Vanta, Drata, Secureframe, OneTrust, Archer
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
New York City or Chicago or Austin or Dallas or Denver or Miami or San Francisco or Seattle
$270k-$290k/yrHybridFull Time
DriveWealth: Provides API-based brokerage infrastructure for fractional stock trading.
15+ YOE15+ years in information security/GRC in regulated financial services; deep SEC/FINRA and global privacy knowledge; hands-on GRC, audit, TPRM, incident response, and executive/board reporting; relevant certifications preferred.
Compyl: A provider of a platform to help companies understand and manage risk, security, and compliance.
5+ YOE5+ years GRC experience with audits, risk assessments, and policy/control rollouts; familiarity with SOC 2/ISO 27001/HIPAA/PCI-DSS/NIST; strong consultative communication and judgment.
Brex: Corporate cards and spend management software for businesses.
5+ YOE5+ years in GRC or Security Engineering; strong automation; security frameworks SOC 2, PCI DSS, ISO 27001; Python and API integrations; cross-functional collaboration; cloud native; Terraform.
Los Angeles or Chicago or Nashville or New York or Seattle
$100k-$135k/yrHybridFull Time
Metropolis: Computer vision technology for checkout-free parking and retail payments.
3+ YOE3+ years in information security GRC or technology compliance; experience managing security awareness programs; knowledge of SOC 2 and PCI-DSS; familiarity with AI/data security and training platforms; bachelor\u0002s degree required.
Berlin or Iași or London or New York City or São Paulo
HybridFull Time
Taktile: Platform for automated financial risk and credit decisioning.
4+ YOE4+ years GRC or security compliance at a SaaS company; owned SOC 2 program; Vanta/Drata/Secureframe experience; hands-on scripting against AWS for automated evidence; strong written communication.
Profound: Analytics platform for brand visibility in AI-generated search results.
3+ YOE3 to 7+ years in security GRC or adjacent roles; hands-on with SOC 2, ISO 27001; experience supporting audits and enterprise security conversations; cloud experience; strong written communication.
PSEGNYSE: PEG: Investor-owned electric and gas utility.
4+ YOEBachelor's in related field or 8+ years' equivalent; 4+ years cybersecurity GRC/IT audit experience; proficiency with Cyber GRC tools; experience with risk and control assessments, audit coordination, and remediation tracking; DOE 10 CFR 810 eligibility.
United States or San Francisco or New York City or Bengaluru
$150k-$200k/yrHybridFull Time
Mesh: Connecting digital wallets and exchanges for unified cryptocurrency payments.
5+ YOERequires 5+ years of hands-on GRC experience, compliance program management, major security framework familiarity, business continuity and disaster recovery experience, risk lifecycle expertise, and scalable process-building skills.
Rokt: Provides AI-driven personalization for ecommerce transaction checkouts.
4+ YOE4+ years GRC/audit experience in tech, working knowledge of ISO/SOC/NIST/privacy frameworks, hands-on audit experience, experience designing agentic AI systems, familiarity with cloud (AWS), APIs, SQL, Git, and basic scripting (Python/TypeScript).
Claude Code, Cursor, Copilot, Google ADK, LangGraph, OpenAI Agents SDK, MCP, OWASP Agentic Top 10, NIST AI RMF, ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, CCPA, CPRA, PCI-DSS, CIS, SCF, ISO 42001, AWS, APIs, SQL, Git, GitHub, Python, TypeScript, Jira
5+ YOE5+ years in SaaS GRC or information security; GCP, AI architectures, data governance, model validation, NIST, PCI, ISO, SOC 2, communication, and process improvement experience.
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
Bachelor's degree or equivalent experience in cybersecurity, information systems, computer science, or risk management; experience with automated controls, GRC platforms, integrations, monitoring, and regulated environments.
Azure DevOps, Jira, GitHub, Jenkins, Microsoft Power Automate, ServiceNow, ServiceNow IRM, Governance, Risk, and Compliance (GRC), APIs, CMDB, CI/CD
New York City or San Francisco or Seattle or United States
$150k-$210k/yrRemoteFull Time
Runway: Develops generative AI software for creative video production.
7+ YOE7+ years in information security, risk or compliance; deep knowledge of NIST/SOC 2/ISO frameworks; hands-on SOC 2 Type II and ISO 27001 audits; GDPR/CCPA operational experience; cloud security and ML/AI understanding.
NIST, SOC 2, ISO 27001, ISO 27701, ISO 42001, FedRAMP, GDPR, CCPA
New York City or Maryland or Massachusetts or Virginia or Georgia or New York
$97k-$184k/yrOnsiteFull Time
Chainalysis: Blockchain data platform for cryptocurrency investigation and compliance.
Experience implementing and operating security and compliance controls in cloud/SaaS environments; built evidence collection, control testing, or remediation workflows; supported SOC 2/ISO 27001 or similar; strong written/verbal communication; US citizenship required.
Hospital for Special Surgery: Provides specialized orthopedic, rheumatologic healthcare and medical research.
Translate security and regulatory requirements into technical control objectives, implement automated control testing and evidence collection, perform technical risk assessments, support audits, and develop policy-as-code and tooling for continuous compliance.