GRC Manager responsible for building and managing Baseten's security governance, risk assessment, compliance programs (SOC 2, ISO 27001, FedRAMP, HIPAA), audits, vendor risk, and customer assurance in a fast-growing AI infrastructure startup. Requires 5+ years in GRC or security compliance, preferably in SaaS/cloud environments.
150k – 250k/yr
Hybrid5+ YOESecurity Engineering
About the role
Responsibilities
Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.
Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.
Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations.
Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.
Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.
Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.
Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.
Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.
Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.
Requirements
5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.
Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.
Proven track record managing compliance audits and certification programs end-to-end.
Experience with access management concepts, third-party risk.
Experience working cross-functionally with technical and non-technical stakeholders to implement compliance and security controls.
Excellent organizational, documentation, and communication skills with attention to detail.
Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.
Nice-to-Haves
Experience with cloud security compliance in AWS or GCP environments.
Hands-on experience using GRC tools (e.g., Vanta, Drata, Secureframe, Anecdotes).
Understanding of AI/ML security considerations, data privacy, and model governance.
Previous experience building and scaling compliance programs in an early-stage or rapidly growing startup.
Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer).
Security & Compliance Engineer owning end-to-end security posture and compliance programs (SOC 2, CJIS) for public safety AI tools. Blend of hands-on cloud security engineering (Azure, IAM, logging) and compliance ownership, including questionnaires, policies, and automation.
150k – 215k/yr
On-site5+ YOESecurity Engineering
Software Engineer, Identity
MercorSan Francisco, CA
Build and scale Mercor's novel identity and access management infrastructure across thousands of Slack workspaces and HR systems for a 100k+ expert network. Requires strong product engineering, large-scale distributed systems experience, and security-minded design instincts.
150k – 325k/yr
On-site5+ YOESecurity Engineering
IT Security Operations Engineer
AKASASan Francisco, CA
IT Security Operations Engineer responsible for implementing DLP, email security, endpoint protection, Okta/Google Workspace hardening, automation, compliance evidence collection, and incident response in a hybrid healthcare AI startup.
150k – 190k/yr
Hybrid4+ YOESecurity Engineering
Security Engineer
NovigNew York, NY
Build and maintain security automation pipelines, AI agents, SOAR/SIEM integrations, vulnerability management, and IAM systems for a sports prediction market platform.
150k – 200k/yr
On-site5+ YOESecurity Engineering
Security Engineer (Purple Team)
Applied IntuitionSunnyvale, CA
Performs offensive security testing, penetration assessments, and risk analysis on vehicle software platforms and embedded systems. Collaborates with engineering teams to design secure architectures and implement mitigations for automotive products.