# Security GRC Lead

**Company:** [Mercor](https://hotfix.jobs/companies/mercor)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Salary:** $350k – $425k/yr
**Experience:** 7+ years
**Skills:** SOC 2, ISO 27001, Vanta, Drata, Secureframe, Sprinto, Wiz, Panther, Python, SQL, Shell Scripting, Nist Ai Rmf, Eu Ai Act, Iso 42001, FedRAMP
**Posted:** 2026-09-09

> Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

## Job Description

## Responsibilities
- Build and operate the company’s compliance cadence for continuous SOC 2 Type 2 monitoring, ISO 27001 certification, and future frameworks such as HIPAA, FedRAMP Moderate, and EU AI Act conformity.
- Own enterprise customer audits, security questionnaires, evidence packs, and a questionnaire response SLA under 48 hours.
- Establish and operate a third-party risk management program, including vendor intake, recurring reviews, evidence requirements, and procurement integration.
- Own the policy lifecycle, including versioning, attestations, exceptions, and review cycles.
- Implement controls-as-code and automated evidence collection using Vanta integrations, Wiz policy packs, and Panther rules mapped to SOC 2 controls.
- Develop data-handling procedures covering customer-data deletion, DSARs, scheduled KMS destruction, and offboarding.
- Maintain customer trust materials, including trust pages, security one-pagers, and executive disclosure templates.
- Translate cloud-security findings, detection rules, and IAM policies into audit controls.
- Use Python, SQL, shell scripting, and LLMs to automate evidence review, control mapping, and questionnaire responses.

## Requirements
- 7+ years of experience in security GRC, compliance engineering, or audit.
- At least 2 years owning a SOC 2 Type 2 program end-to-end at a company audited by enterprise customers.
- Experience delivering an ISO 27001 certification from kickoff through Stage 1 and Stage 2 with a real registrar.
- Advanced Vanta, Drata, Secureframe, or Sprinto experience, including connector configuration, custom tests, and evidence troubleshooting.
- Experience participating on the company side of an enterprise customer audit conducted by a Big Four firm.
- Ability to map Wiz findings, Panther rules, IAM policies, and cloud-security evidence to controls.
- Experience writing controls as code or querying evidence with SQL, Python, or shell.
- Experience with SIG, CAIQ, custom enterprise questionnaires, on-site auditor sessions, and disclosure letters.

## Nice-to-haves
- GRC experience at an AI lab, ML platform, or company serving frontier AI labs.
- Familiarity with NIST AI RMF, EU AI Act conformity, or ISO 42001.
- Experience with FedRAMP Moderate, HIPAA, PCI DSS, or SOC 2 and HITRUST dual scope.
- Experience automating questionnaire responses with LLMs.
- Experience establishing a third-party risk program from scratch.
- Experience writing a public customer trust page.

## Compensation and Benefits
- Annual salary of $350,000–$425,000.
- Biannual performance bonus structure.
- Generous equity grant vesting over four years.
- Up to $15,000 relocation bonus.
- $10,000 housing bonus for employees living within 0.5 miles of the office.
- $1,500 monthly meal stipend.
- Equinox membership.
- $200 monthly laundry reimbursement.
- $200 monthly personal wellness reimbursement.
- Health, dental, and vision insurance.

## Similar jobs

- [Platform Security Engineer, DRTM / Secure Launch](https://hotfix.jobs/jobs/52321fb7-76c2-4b9b-b900-53a63bb68154) - Anthropic - San Francisco, CA - $320k – $405k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Safeguards Enforcement Lead, Cyber Harms](https://hotfix.jobs/jobs/c042fb99-fa5c-4740-9908-e14324222bde) - Anthropic - Washington, DC - $285k – $330k/yr
- [Software Security Architect, Operating Systems | Consumer Devices](https://hotfix.jobs/jobs/eae7f6bf-7cf9-495a-9c46-fb88a4620a0f) - OpenAI - San Francisco, CA - $268k – $342k/yr
- [Cyber Operations Lead, Critical Harm Operations](https://hotfix.jobs/jobs/aece8b0b-4900-4762-87e1-025b2cbe75c9) - OpenAI - San Francisco, CA - $252k – $335k/yr

**Apply:** https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1
**Canonical:** https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1