Skip to content
PhyloPhylo

Security GRC Specialist

Build and scale the security, privacy, and compliance program at an AI-biomedical startup. Lead SOC 2, ISO 27001, HIPAA and FedRAMP readiness, partner with engineering on technical controls, run risk assessments, and handle customer security reviews in a hands-on early-stage environment.

About the job

Responsibilities

  • Own Phylo’s security and compliance roadmap.
  • Lead SOC 2, ISO 27001 and GDPR readiness, audits, evidence collection, and remediation.
  • Build HIPAA-ready processes for workloads involving protected health information.
  • Assess and plan for FedRAMP, NIST, privacy, and life-sciences requirements where applicable.
  • Partner with engineers to implement scalable controls across cloud infrastructure, applications, and AI systems.
  • Lead customer questionnaires, RFPs, due diligence, and security conversations.
  • Run risk assessments and drive remediation across systems, vendors, and processes.
  • Maintain lightweight policies, customer-facing security documentation, and compliance reporting.
  • Automate evidence collection, monitoring, and other compliance workflows.

Requirements

  • 5+ years in security GRC, compliance, or a security engineering-adjacent role.
  • Experience leading SOC 2, ISO 27001, HIPAA, FedRAMP, or similar programs.
  • Strong understanding of cloud and application security.
  • Ability to translate regulatory requirements into technical controls.
  • Experience supporting audits and enterprise customer security reviews.
  • Strong cross-functional communication and program ownership.
  • A pragmatic, hands-on approach suited to an early-stage company.

Nice-to-Haves

  • Experience building a security program from an early stage.
  • Background in healthcare, life sciences, enterprise AI, or cloud infrastructure.
  • Experience with HIPAA, FedRAMP, NIST SP 800-53, HITRUST, or GDPR.
  • Familiarity with AI governance frameworks such as NIST AI RMF or ISO 42001.
  • Experience automating GRC and compliance workflows.

Compensation and Benefits

  • Competitive salary and equity share.
  • Full medical, dental, and vision coverage, including free therapy sessions and eyewear stipend.
  • 401(k) to help you build long-term financial security (US only).
  • Unlimited PTO to recharge when you need it (US only).
  • Lunch and snacks when you're in the office.
  • Regular team offsites and company events.

Skills

SOC 2, ISO 27001, GDPR, HIPAA, FedRAMP, Nist, GRC, Cloud Security, Risk Assessment, Audit Management, Compliance Automation

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Motive

Motive

Canada

Red Team Security Engineer
CA$146k+/yrRemote5+ YOESecurity Engineering

Conduct cloud-focused red team operations, adversary simulations, and offensive security assessments while validating detection coverage and driving remediation. Requires at least five years of offensive security experience and familiarity with attacker techniques, cloud environments, and MITRE ATT&CK.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.