Senior GRC Lead
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.
About the job
Responsibilities
- Own Jasper’s governance, risk, and compliance program end-to-end.
- Drive SOC 2, ISO 27001, and similar compliance audits from readiness through certification, with a path toward ISO 42001.
- Support GDPR and broader privacy compliance alongside Legal.
- Rationalize requirements across frameworks and maintain a single source of truth for control ownership.
- Serve as the subject-matter expert on control mapping for audits, RFPs, and enterprise sales engagements.
- Respond to customer security questionnaires and support sales and legal due diligence.
- Maintain the risk register, including risk identification, scoring, and remediation tracking.
- Manage vendor and third-party risk assessments and the vendor security review process.
- Own security and compliance policy management.
- Partner with Security, Legal, Product, Engineering, GTM, and People to embed governance requirements into company operations.
- Automate compliance workflows, audit artifact collection, internal reviews, and continuous monitoring.
- Drive and improve AI governance across the company and product.
Requirements
- 8+ years of experience in Governance, Risk & Compliance, ideally at a SaaS company.
- Working knowledge of AI concepts including LLMs, agents, copilots, tokens, credits, context windows, RAG, and data governance.
- Deep expertise in multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, and NIST CSF.
- Experience with at least one regulatory framework such as GDPR, CCPA, or HIPAA.
- Knowledge of modern cloud-native web application development and security practices, particularly GCP and frontier AI platforms.
- Experience with GRC tools such as Vanta, Drata, OneTrust, or similar.
- Experience managing risk registers and vendor risk programs.
- Strong cross-functional communication skills and the ability to translate technical issues for non-technical teams.
- Experience using AI agents, tools, and platforms to automate workflows responsibly.
- Experience at a startup or fast-growing SaaS company.
- CISA, CISSP, CRISC, or similar certification.
- Experience scoping or pursuing ISO 42001 or other AI governance frameworks.
- Hands-on experience with agentic coding tools such as Cursor, Claude Code, or Copilot.
- Working knowledge of Python sufficient to modify and run scripts, build automations, and ship small tools.
Compensation & Benefits
- Base salary: $174,250–$205,000 USD.
- Comprehensive health, dental, and vision coverage beginning on the first day for employees and their families.
- 401(k) program with up to 2% company matching.
- Equity grant participation.
- Flexible PTO with a $900 annual FlexExperience budget.
- $1,800 annual FlexWellness budget.
- $1,500 home office setup budget.
- Annual learning and development stipend.
- 16 weeks of paid parental leave.
Skills
Governance, Risk & Compliance, Soc 2 Type Ii, ISO 27001, Nist Csf, GDPR, GCP, Ai Governance, Vanta, Drata, Onetrust, Python, RAG, Vendor Risk Management
Similar jobs
Security Engineering jobsThe Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.
Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.
Leads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.