Skip to content
OpenAIOpenAI

GRC Program Manager, US Government Compliance

Leads US government compliance programs, driving FedRAMP and agency ATOs for OpenAI products. Collaborates with engineers on security controls, documentation, and audits in highly regulated environments. Requires 5+ years compliance experience and deep USG framework knowledge.

About the job

Responsibilities

  • Drive the ATO process for FedRAMP and across multiple government clients in restricted environments with minimal oversight.
  • Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.
  • Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.
  • Act as a subject matter expert during audits and assessments, representing the organization with credibility and expertise.
  • Continuously refine processes to improve the efficiency and quality of compliance efforts.

Requirements

  • Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors.
  • Deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP).
  • Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders.
  • Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure.

Nice-to-Haves

  • Active US security clearance.
  • 5+ years of compliance experience in positions involving information security, data security, or infrastructure or network security.
  • Familiarity with deployment models, including to cloud platforms (Azure, AWS) and the underlying infrastructure primitives (Kubernetes, Terraform).
  • Strong familiarity with core security concepts and technologies, such as authentication, encryption, vulnerability management, and audit logging.
  • Ability to work collaboratively and effectively in a cross-functional team environment.
  • Thrive in dynamic environments and can navigate ambiguity with ease.

Skills

FedRAMP, Nist, Rmf, Kubernetes, Terraform, AWS, Azure, Authentication, Encryption, Vulnerability Management, Audit Logging

Vannevar

Vannevar

United States

Application Security Engineer
$160k+/yrRemote5+ YOESecurity Engineering

The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.

Wiz

Wiz

Washington, DC

Cyber Threat Intel Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.

Fireworks AI

Fireworks AI

San Mateo, CA

GRC Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.

Zoox

Zoox

Foster City, CA

Sensing and Perception System Safety Engineer
$170k+/yrHybrid3+ YOESecurity Engineering

Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.

Greptile

Greptile

San Francisco, CA

Security Engineer
$170k+/yrOn-site3+ YOESecurity Engineering

Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.