Senior Security Engineer - GRC Frameworks & AI Governance

USD 152,000-258,000 per year
SENIOR
✅ On-site

Tech Stack

AI @ 4 AWS @ 4 Audit @ 7 Azure @ 4 CCPA @ 4 CI/CD @ 4 Communication @ 7 Compliance @ 4 GCP @ 4 GDPR @ 4 Machine Learning Project Management @ 7 Security @ 4

Details

SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale its security and AI governance compliance posture. The role involves setting organizational standards, designing and implementing controls, automating compliance processes, and embedding compliance into architecture and CI/CD workflows. The successful candidate will collaborate with engineering, legal, product, leadership, auditors, assessors, and regulators to keep AI systems audit-ready across enterprise, commercial, and public-sector environments.

Responsibilities

  • Own and execute security compliance implementation and audits across SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking.
  • Build and maintain Compliance-as-Code and continuous compliance capabilities, including policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows.
  • Operate and extend GRC platforms such as Vanta as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling.
  • Partner with engineering and architecture teams to embed compliance requirements into design reviews and translate framework obligations into technical control narratives.
  • Develop, maintain, and improve corporate policies, standards, and procedures supporting the company’s governance and AI management system posture.
  • Identify, assess, and prioritize risks involving AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments.
  • Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks including data handling, model governance, and agentic and conversational surfaces.
  • Manage relationships with external auditors, assessors, and regulators, serving as a bridge between auditors and internal teams.
  • Promote a culture of security and compliance by educating teams on the purpose of controls.

Requirements

  • Bachelor’s degree in computer science, information security, cybersecurity, or an engineering/STEM field.
  • At least 8 years of experience in GRC, security compliance, or technology audit roles, including hands-on GRC engineering responsibilities.
  • Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments such as AWS, GCP, or Azure.
  • Expert-level working knowledge of several of SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001, including building and operating controls.
  • Experience with Compliance-as-Code practices and GRC automation tools such as Vanta, Drata, or similar platforms.
  • Ability to evaluate control objectives against real IT and cloud configurations and work with engineers on remediation.
  • Preferred experience includes 10 or more years in security compliance, GRC engineering, or technology audit; implementing technical controls such as IAM, logging and monitoring, encryption, and infrastructure hardening; and integrating compliance checks into CI/CD pipelines.
  • Experience in the technology or AI/ML industry, particularly with startups or high-growth product organizations, is preferred.
  • Working knowledge of HIPAA privacy and security rules, SOX/ITGC, AI ethics and governance frameworks such as NIST AI RMF, ISO 42001, and the EU AI Act, and data privacy frameworks such as GDPR and CCPA.
  • Experience with public-sector or federal compliance programs such as FedRAMP, NIST 800-171, or CMMC is a plus.
  • Strong analytical, problem-solving, organizational, project management, communication, and stakeholder management skills.
  • Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar are preferred.

Benefits

  • Equity.
  • Medical, vision, and dental coverage.
  • 401(k) retirement plan.
  • Short- and long-term disability insurance.
  • Life insurance.
  • Various discounts and perks.

ITAR Requirements

To conform to U.S. Government export regulations, applicants must be U.S. citizens or nationals, U.S. lawful permanent residents, refugees under 8 U.S.C. § 1157, asylees under 8 U.S.C. § 1158, or eligible to obtain the required authorizations from the U.S. Department of State.

More jobs at SpaceXAI

Similar jobs