Skip to content
JasperJasper

Senior GRC Lead

Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.

About the job

Responsibilities

  • Own Jasper’s governance, risk, and compliance program end-to-end.
  • Drive SOC 2, ISO 27001, and similar compliance audits from readiness through certification, with a path toward ISO 42001.
  • Support GDPR and broader privacy compliance alongside Legal.
  • Rationalize requirements across frameworks and maintain a single source of truth for control ownership.
  • Serve as the subject-matter expert on control mapping for audits, RFPs, and enterprise sales engagements.
  • Respond to customer security questionnaires and support sales and legal due diligence.
  • Maintain the risk register, including risk identification, scoring, and remediation tracking.
  • Manage vendor and third-party risk assessments and the vendor security review process.
  • Own security and compliance policy management.
  • Partner with Security, Legal, Product, Engineering, GTM, and People to embed governance requirements into company operations.
  • Automate compliance workflows, audit artifact collection, internal reviews, and continuous monitoring.
  • Drive and improve AI governance across the company and product.

Requirements

  • 8+ years of experience in Governance, Risk & Compliance, ideally at a SaaS company.
  • Working knowledge of AI concepts including LLMs, agents, copilots, tokens, credits, context windows, RAG, and data governance.
  • Deep expertise in multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, and NIST CSF.
  • Experience with at least one regulatory framework such as GDPR, CCPA, or HIPAA.
  • Knowledge of modern cloud-native web application development and security practices, particularly GCP and frontier AI platforms.
  • Experience with GRC tools such as Vanta, Drata, OneTrust, or similar.
  • Experience managing risk registers and vendor risk programs.
  • Strong cross-functional communication skills and the ability to translate technical issues for non-technical teams.
  • Experience using AI agents, tools, and platforms to automate workflows responsibly.
  • Experience at a startup or fast-growing SaaS company.
  • CISA, CISSP, CRISC, or similar certification.
  • Experience scoping or pursuing ISO 42001 or other AI governance frameworks.
  • Hands-on experience with agentic coding tools such as Cursor, Claude Code, or Copilot.
  • Working knowledge of Python sufficient to modify and run scripts, build automations, and ship small tools.

Compensation & Benefits

  • Base salary: $174,250–$205,000 USD.
  • Comprehensive health, dental, and vision coverage beginning on the first day for employees and their families.
  • 401(k) program with up to 2% company matching.
  • Equity grant participation.
  • Flexible PTO with a $900 annual FlexExperience budget.
  • $1,800 annual FlexWellness budget.
  • $1,500 home office setup budget.
  • Annual learning and development stipend.
  • 16 weeks of paid parental leave.

Skills

Governance, Risk & Compliance, Soc 2 Type Ii, ISO 27001, Nist Csf, GDPR, GCP, Ai Governance, Vanta, Drata, Onetrust, Python, RAG, Vendor Risk Management

Jasper

Jasper

United States

Senior Security Engineer
$174k+/yrRemote8+ YOESecurity Engineering

The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.

Wiz

Wiz

United States

Compliance Engineer - Public Sector
$174k+/yrRemote6+ YOESecurity Engineering

Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.

Starburst

Starburst

Boston, MA

Senior Application Security Engineer
$175k+/yrOn-site5+ YOESecurity Engineering

Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.

Snowflake

Snowflake

United States

Senior Security Engineer, Incident Response
$176k+/yrRemote5+ YOESecurity Engineering

Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.

Snowflake

Snowflake

Menlo Park, CA
Senior Security Engineer, AI Incident Response
$176k+/yrHybrid5+ YOESecurity Engineering

Leads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.