# Security GRC Specialist

**Company:** [Phylo](https://hotfix.jobs/companies/phylo)
**Location:** South San Francisco, CA, Toronto, Canada
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** SOC 2, ISO 27001, GDPR, HIPAA, FedRAMP, Nist, GRC, Cloud Security, Risk Assessment, Audit Management, Compliance Automation
**Posted:** 2026-07-30

> Build and scale the security, privacy, and compliance program at an AI-biomedical startup. Lead SOC 2, ISO 27001, HIPAA and FedRAMP readiness, partner with engineering on technical controls, run risk assessments, and handle customer security reviews in a hands-on early-stage environment.

## Job Description

## Responsibilities
- Own Phylo’s security and compliance roadmap.
- Lead SOC 2, ISO 27001 and GDPR readiness, audits, evidence collection, and remediation.
- Build HIPAA-ready processes for workloads involving protected health information.
- Assess and plan for FedRAMP, NIST, privacy, and life-sciences requirements where applicable.
- Partner with engineers to implement scalable controls across cloud infrastructure, applications, and AI systems.
- Lead customer questionnaires, RFPs, due diligence, and security conversations.
- Run risk assessments and drive remediation across systems, vendors, and processes.
- Maintain lightweight policies, customer-facing security documentation, and compliance reporting.
- Automate evidence collection, monitoring, and other compliance workflows.

## Requirements
- 5+ years in security GRC, compliance, or a security engineering-adjacent role.
- Experience leading SOC 2, ISO 27001, HIPAA, FedRAMP, or similar programs.
- Strong understanding of cloud and application security.
- Ability to translate regulatory requirements into technical controls.
- Experience supporting audits and enterprise customer security reviews.
- Strong cross-functional communication and program ownership.
- A pragmatic, hands-on approach suited to an early-stage company.

## Nice-to-Haves
- Experience building a security program from an early stage.
- Background in healthcare, life sciences, enterprise AI, or cloud infrastructure.
- Experience with HIPAA, FedRAMP, NIST SP 800-53, HITRUST, or GDPR.
- Familiarity with AI governance frameworks such as NIST AI RMF or ISO 42001.
- Experience automating GRC and compliance workflows.

## Compensation and Benefits
- Competitive salary and equity share.
- Full medical, dental, and vision coverage, including free therapy sessions and eyewear stipend.
- 401(k) to help you build long-term financial security (US only).
- Unlimited PTO to recharge when you need it (US only).
- Lunch and snacks when you're in the office.
- Regular team offsites and company events.

## Similar jobs

- [Security Engineer, Threat Intelligence](https://hotfix.jobs/jobs/a9d333c0-2242-416f-a470-d3a19f982046) - Fluidstack - New York, NY - $220k – $280k/yr
- [Red Team Security Engineer](https://hotfix.jobs/jobs/fbcac126-2696-46a5-af87-5710cbb8c904) - Motive - Remote - CA$146k – CA$190k/yr
- [Security Scientist](https://hotfix.jobs/jobs/36a4a0c9-f833-41fb-bd29-ad40c4d5050f) - Figma - Remote - $140k – $348k/yr
- [Security Engineer](https://hotfix.jobs/jobs/061a2617-4d6a-4cf3-96a0-ad832100d55f) - hud - San Francisco, CA
- [Abuse Research Engineer](https://hotfix.jobs/jobs/2f1effd6-b955-48c7-9d30-3d0aed220264) - Stripe - Remote

**Apply:** https://hotfix.jobs/jobs/83680384-3ec6-4d4d-8623-ec9b53820805
**Canonical:** https://hotfix.jobs/jobs/83680384-3ec6-4d4d-8623-ec9b53820805