GRC Program Manager, Product and Customer Trust
📍 New York City, United States
📍 San Francisco, United States
📍 Seattle, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 6
Codex @ 6
Communication @ 6
Compliance @ 4
Security @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Governance, Risk, and Compliance (GRC) is foundational to Security's mission at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI's technology, people, and products. The team is technical in what it builds and operational in how it works, partnering with Product, Security, Legal, Privacy, GTM, and Field Security.
The role is a highly cross-functional and operational position focused on product launches, regulatory readiness, and customer trust. It is not focused on SOC or ISO audits. The successful candidate will help ensure products launch with the right controls, external narratives remain accurate, and GTM teams and customers have the information needed to assess OpenAI's security and compliance. The role includes building systems, content, escalation paths, and automation to support enterprise customers, strategic launches, and emerging regulatory expectations.
Responsibilities
- Own and improve the customer trust operating model, including intake, triage, escalations, SLAs, metrics, and quality review.
- Support strategic customer trust needs, including security questionnaires, customer calls, Trust Center updates, and high-priority deal support.
- Partner with Product, Security, Legal, Privacy, and GTM teams to prepare accurate, approved trust materials for launches and regulated product changes.
- Build reusable customer-facing narratives, FAQs, evidence paths, and whitepapers that reduce one-off work while keeping claims controlled.
- Ensure external security and compliance claims are supported by internal processes and controls.
- Ensure product launches support OpenAI's external security and compliance narrative, and scale launch reviews so GRC does not become a bottleneck.
- Develop data handling guidance to provide product teams with a path consistent with external commitments.
- Use automation and AI-native workflows across internal and external tooling, Codex, and related systems to improve speed and consistency.
- Turn recurring customer discovery into reusable content, product feedback, evidence improvements, and control-gap signals.
Requirements
- Experience in product assurance, product launch review, customer trust, security compliance, or enterprise trust in a technical environment.
- Ability to support GTM teams with accurate, approved, customer-facing security and compliance narratives.
- Sound judgment to distinguish what can be answered directly, what requires Product, Security, or Legal review, and what should not be claimed externally.
- Experience building scalable operating models, metrics, content systems, and automation for repeated assurance workflows.
- Excellent written communication and the ability to translate technical security concepts for customers, auditors, regulators, Sales, and Field Security.
- Experience operating as a senior individual contributor in GRC, product assurance, customer trust or assurance, security compliance, enterprise trust, product security assurance, or a closely related function.
- Technical fluency across SaaS, cloud, security controls, product launches, and enterprise assurance workflows.
- Experience scaling product launch reviews.
- Vertical-specific experience in healthcare, financial services, and advertising.
- Experience supporting GTM, Field Security, Sales Engineering, Customer Success, or strategic enterprise customers.
- Ability to build systems, metrics, and escalation paths that scale a high-volume assurance function without sacrificing quality.
- Interest in using Codex and other AI-native tools to reduce manual review, automate launch review processes, and keep approved content current.
Benefits
- Base salary of $216,000–$252,000 per year, plus equity.
- Medical, dental, and vision insurance, with employer contributions to Health Savings Accounts.
- Pre-tax accounts for healthcare, dependent care, and commuter expenses.
- 401(k) retirement plan with employer match.
- Paid parental, medical, and caregiver leave.
- Paid time off and company holidays.
- Mental health and wellness support.
- Employer-paid basic life and disability coverage.
- Annual learning and development stipend.
- Daily meals in offices and eligible meal delivery credits.
- Relocation support for eligible employees.
- Additional taxable fringe benefits may be provided.
- OpenAI is an equal opportunity employer and provides reasonable accommodations to applicants with disabilities.