Member of Technical Staff, Governance Risk Compliance
Lead GRC initiatives ensuring xAI meets federal compliance standards (FedRAMP, NIST, CMMC) while managing risk for AI systems and cloud deployments. Requires 3+ years in security compliance, a bachelor's degree, and expertise in federal frameworks.
About the job
Responsibilities
- Execute security compliance implementation and audits (e.g., ISO 27001/42001, SOC2, FedRAMP HIGH, DoD Cloud Computing SRG IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
- Work with 3PAOs and federal government Authorizing Officials to achieve compliance certifications, reports, and ATO status.
- Identify, assess, and prioritize risks related to AI operations, cybersecurity, regulatory compliance, intellectual property, and cloud deployments.
- Design and implement risk mitigation strategies, including monitoring systems, contingency plans, vulnerability scans, POAMs, and STIGs.
- Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures throughout the project lifecycle.
- Serve as a liaison between system owners, security personnel, and cross-functional teams.
- Lead Risk Management Assessment and Authorization (A&A) processes, cloud system risk assessments, compliance reviews for new products/changes/features.
- Conduct regular risk assessments, scenario analyses, and proactive evaluations of emerging threats.
- Oversee audits, certifications, third-party assessments, and vulnerability management.
- Act as a subject matter expert, providing guidance on risk, compliance, and cybersecurity matters.
- Create and present regular reports on GRC performance, risks, and compliance status to senior leadership.
Requirements
- 3+ years of experience in governance, risk management, compliance, or technology audit roles.
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field.
- Proven expertise in regulatory frameworks, data privacy, cybersecurity, and federal compliance standards.
- Strong understanding of AI ethics, Risk Management Framework (RMF), and associated risks.
- Experience with vulnerability management, POAMs, STIG implementation, and cloud security controls.
- Ability to evaluate control objectives with IT configurations.
- Exceptional analytical, problem-solving, organizational, and project management skills.
- Excellent communication, stakeholder management, and translation skills.
Nice-to-Haves
- Previous systems engineering experience.
- Certifications like CISA, CRISC, CGEIT, Security+, CASP+.
- Experience in the tech or AI industry, particularly with startups or government/public sector engagements.
- Deep expertise maintaining frameworks such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, and STIG/RMF policies.
- Familiarity with ISO 27001, ISO 42001, NIST, SOC 2.
- Background in managing third-party risk, vendor compliance programs, or federal assessments.
- 5+ years of security compliance or technology audit-related experience.
Skills
FedRAMP, Nist 800-53, Nist 800-171, Cmmc, SOC 2, ISO 27001, Risk Management Framework, Stig, Poam, Vulnerability Management, Cloud Security, Cisa, Crisc
Similar jobs
Security Engineering jobsDevelop and operate global physical security systems, controls, and compliance processes across data centers and other facilities. The role manages investigations, risk mitigation, audits, vendor deployments, and cross-functional security initiatives, with approximately 35% travel required.
Security Engineer responsible for building detection and prevention controls, automating security operations, conducting threat hunts, and supporting incident response across a remote-first organization. Requires 3+ years of security or software development experience, cloud-native security expertise, and automation skills.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.