Skip to content
Thinking Machines LabThinking Machines LabSan Francisco, CA

Governance, Risk and Compliance Lead

Lead end-to-end certifications (SOC 2, ISO 27001, FedRAMP) and day-to-day GRC processes for an AI company. Drive compliance roadmap, manage audits/risk, answer technical questions from engineering teams, and build automation/tools while growing the function.

225k – 350k/yr
On-site7+ YOEOther

About the role

What You'll Do

  • Own our certification roadmap end to end: scope each certification, build the control set, collect and organize evidence, and represent TML directly to auditors through to close.
  • Manage recurring compliance processes on a set cadence: control testing, audit prep and response, risk register maintenance, and policy attestations.
  • Answer compliance and risk questions from engineering, security, and product teams directly, by building enough technical fluency across our infrastructure, model deployment, and data handling to do so without escalating every question.
  • Track regulatory and framework requirements relevant to an AI company (GDPR, EU AI Act, and similar) and translate them into specific, actionable controls.
  • Identify gaps in current compliance coverage as the company adds new products, infrastructure, or jurisdictions, and propose what needs to change before it becomes a blocker.
  • Build and maintain the tooling and documentation that make the next audit cycle faster than the last one.
  • Plan a multi-quarter roadmap for the GRC function itself, while continuing to personally run the certifications and audits already on the books.

Skills and Qualifications

Minimum qualifications:

  • 7+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.
  • Experience leading a SOC 2, ISO 27001, FedRAMP or comparable certification from scoping through audit close.
  • Hands-on experience collecting audit evidence and writing control documentation.
  • Experience managing a recurring compliance process, such as control testing, risk register maintenance, or policy attestations.
  • Experience learning new technical domains quickly and translating them for non-technical stakeholders.

Preferred qualifications:

  • Background as a software engineer or in a technical engineering role, now applied to GRC, evidenced by scripts, tools, or automations you've personally built for evidence collection, control testing, or audit workflows.
  • Experience translating complex compliance requirements into scalable automation using AI agents and custom built tooling.
  • Experience growing a GRC function's capability (new certifications, tooling, or processes) as a company scaled.

You'll Thrive in This Role if

  • You want to run the certification yourself, end to end.
  • You're the one in the room with the auditor, walking through evidence.
  • You can hold this week's deadlines and next year's roadmap at the same time.

Logistics

Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $225,000 - $350,000.

Skills

GRCSOC 2ISO 27001FedRAMPGDPReu ai actRisk Assessmentaudit managementcontrol documentationcompliance automationCybersecurityAI Agents

Similar roles

Sigma

Governance, Risk & Compliance Manager

SigmaSan Francisco, CA

Build and lead Sigma's Trust & Assurance function as Director, owning end-to-end GRC (SOC 2/ISO audits, policies, vendor risk), maturing it into enterprise risk management. Requires 8+ years GRC/risk experience including people management and personally running a SOC 2 program.

225k – 265k/yrOn-site8+ YOEOther
Fluidstack

Design Management Lead

FluidstackAustin, TX

Lead design management for Fluidstack's multi-gigawatt AI data center builds. Set and enforce aggressive design schedules across multiple firms, run high-velocity review processes for constructability/cost/reference conformance, and close the design-field loop on RFIs to enable months-not-years delivery at 50GW+ scale.

222k – 307k/yrOn-site7+ YOEOther
Cohere

Lead, Global External Affairs

CohereWashington, DC

Lead Global External Affairs at Cohere by building and executing strategy for partnerships with think tanks, academics, NGOs, and coalitions to validate and amplify the company's responsible enterprise AI policy narrative. Requires 10+ years in external affairs/public policy with a deep global network and AI policy expertise.

220k – 330k/yrRemote10+ YOEOther
Fluidstack

Site Manager, Datacenter Operations

FluidstackBuffalo, NY +1

Lead 24/7 operations of critical data center infrastructure for AI compute sites, including electrical, mechanical, cooling, safety, hardware/network repair, incident response, and team leadership while sites are still under construction. Requires deep experience running contractual-availability facilities, technical infrastructure knowledge, and building high-performing teams.

234k – 340k/yrOn-site7+ YOEOther
OpenAI

Visual Storytelling & AI Innovation Lead, Office of the CFO

OpenAISan Francisco, CA

Hands-on IC partnering with the CFO's Chief of Staff to create executive presentations, board materials, and AI transformation stories that showcase Finance's AI adoption and support broader company messaging.

216k – 310k/yrHybridOther