# GRC Manager

**Company:** [Baseten](https://hotfix.jobs/companies/baseten)
**Location:** San Francisco, CA, New York, NY
**Role:** Security Engineering
**Salary:** $150k – $250k/yr
**Experience:** 5+ years
**Skills:** SOC 2, ISO 27001, iso 27701, FedRAMP, HIPAA, nist, GDPR, AWS, GCP, vanta, drata, secureframe, cisa, cissp, cism
**Posted:** 2026-07-24

> GRC Manager responsible for building and managing Baseten's security governance, risk assessment, compliance programs (SOC 2, ISO 27001, FedRAMP, HIPAA), audits, vendor risk, and customer assurance in a fast-growing AI infrastructure startup. Requires 5+ years in GRC or security compliance, preferably in SaaS/cloud environments.

## Job Description

## Responsibilities
- Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.
- Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.
- Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations.
- Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.
- Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.
- Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.
- Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.
- Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.
- Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.

## Requirements
- 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.
- Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.
- Proven track record managing compliance audits and certification programs end-to-end.
- Experience with access management concepts, third-party risk.
- Experience working cross-functionally with technical and non-technical stakeholders to implement compliance and security controls.
- Excellent organizational, documentation, and communication skills with attention to detail.
- Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.

## Nice-to-Haves
- Experience with cloud security compliance in AWS or GCP environments.
- Hands-on experience using GRC tools (e.g., Vanta, Drata, Secureframe, Anecdotes).
- Understanding of AI/ML security considerations, data privacy, and model governance.
- Previous experience building and scaling compliance programs in an early-stage or rapidly growing startup.
- Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer).

## Similar roles

- [Security & Compliance Engineer](https://hotfix.jobs/jobs/0fe396b6-3353-482d-9e15-168119079999) - Aurelian - Seattle, WA - $150k – $215k/yr
- [Software Engineer, Identity](https://hotfix.jobs/jobs/95795ec8-bfd1-44c8-a7a1-b16c9be3d31b) - Mercor - San Francisco, CA - $150k – $325k/yr
- [IT Security Operations Engineer](https://hotfix.jobs/jobs/ab8df8f3-05c1-4b41-a516-c95445575498) - AKASA - San Francisco, CA - $150k – $190k/yr
- [Security Engineer](https://hotfix.jobs/jobs/79d32979-efc0-42db-8089-267517d351aa) - Novig - New York, NY - $150k – $200k/yr
- [Security Engineer (Purple Team)](https://hotfix.jobs/jobs/a555c8c6-de26-4174-8934-a2a145176469) - Applied Intuition - Sunnyvale, CA - $150k – $220k/yr

**Apply:** https://hotfix.jobs/jobs/68a03d3e-1579-49d0-ab74-5a8e2b7e975b
**Canonical:** https://hotfix.jobs/jobs/68a03d3e-1579-49d0-ab74-5a8e2b7e975b