Skip to content
MercorMercor

Security GRC Lead

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

About the job

Responsibilities

  • Build and operate the company’s compliance cadence for continuous SOC 2 Type 2 monitoring, ISO 27001 certification, and future frameworks such as HIPAA, FedRAMP Moderate, and EU AI Act conformity.
  • Own enterprise customer audits, security questionnaires, evidence packs, and a questionnaire response SLA under 48 hours.
  • Establish and operate a third-party risk management program, including vendor intake, recurring reviews, evidence requirements, and procurement integration.
  • Own the policy lifecycle, including versioning, attestations, exceptions, and review cycles.
  • Implement controls-as-code and automated evidence collection using Vanta integrations, Wiz policy packs, and Panther rules mapped to SOC 2 controls.
  • Develop data-handling procedures covering customer-data deletion, DSARs, scheduled KMS destruction, and offboarding.
  • Maintain customer trust materials, including trust pages, security one-pagers, and executive disclosure templates.
  • Translate cloud-security findings, detection rules, and IAM policies into audit controls.
  • Use Python, SQL, shell scripting, and LLMs to automate evidence review, control mapping, and questionnaire responses.

Requirements

  • 7+ years of experience in security GRC, compliance engineering, or audit.
  • At least 2 years owning a SOC 2 Type 2 program end-to-end at a company audited by enterprise customers.
  • Experience delivering an ISO 27001 certification from kickoff through Stage 1 and Stage 2 with a real registrar.
  • Advanced Vanta, Drata, Secureframe, or Sprinto experience, including connector configuration, custom tests, and evidence troubleshooting.
  • Experience participating on the company side of an enterprise customer audit conducted by a Big Four firm.
  • Ability to map Wiz findings, Panther rules, IAM policies, and cloud-security evidence to controls.
  • Experience writing controls as code or querying evidence with SQL, Python, or shell.
  • Experience with SIG, CAIQ, custom enterprise questionnaires, on-site auditor sessions, and disclosure letters.

Nice-to-haves

  • GRC experience at an AI lab, ML platform, or company serving frontier AI labs.
  • Familiarity with NIST AI RMF, EU AI Act conformity, or ISO 42001.
  • Experience with FedRAMP Moderate, HIPAA, PCI DSS, or SOC 2 and HITRUST dual scope.
  • Experience automating questionnaire responses with LLMs.
  • Experience establishing a third-party risk program from scratch.
  • Experience writing a public customer trust page.

Compensation and Benefits

  • Annual salary of $350,000–$425,000.
  • Biannual performance bonus structure.
  • Generous equity grant vesting over four years.
  • Up to $15,000 relocation bonus.
  • $10,000 housing bonus for employees living within 0.5 miles of the office.
  • $1,500 monthly meal stipend.
  • Equinox membership.
  • $200 monthly laundry reimbursement.
  • $200 monthly personal wellness reimbursement.
  • Health, dental, and vision insurance.

Skills

SOC 2, ISO 27001, Vanta, Drata, Secureframe, Sprinto, Wiz, Panther, Python, SQL, Shell Scripting, Nist Ai Rmf, Eu Ai Act, Iso 42001, FedRAMP

Anthropic

Anthropic

San Francisco, CA
Platform Security Engineer, DRTM / Secure Launch
$320k+/yrHybrid8+ YOESecurity Engineering

Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Anthropic

Anthropic

Washington, DC
Safeguards Enforcement Lead, Cyber Harms
$285k+/yrHybridSecurity Engineering

Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.

OpenAI

OpenAI

San Francisco, CA

Software Security Architect, Operating Systems | Consumer Devices
$268k+/yrOn-site7+ YOESecurity Engineering

Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.

OpenAI

OpenAI

San Francisco, CA

Cyber Operations Lead, Critical Harm Operations
$252k+/yrHybrid8+ YOESecurity Engineering

Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.