Governance, Risk and Compliance Lead
Thinking MachinesData & company
San Francisco, United States$225,000 - $350,000Lead
Andreessen Horowitz
NVIDIA
Accel
ServiceNow
Cisco
AMD
Legal & Compliance
About the role
TL;DR
Lead GRC certifications and manage day-to-day compliance processes for an AI company.
- •Thinking Machines Lab is building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals.
- •We are seeking a GRC Lead to drive our certifications (SOC 2, ISO 27001, FedRAMP and others) from scoping through audit close, and manage day-to-day compliance processes.
- •You will collect evidence, write control documentation, and interact directly with auditors.
- •Key Responsibilities Own the certification roadmap end-to-end, including scoping, control building, evidence collection, and auditor representation.
- •Manage recurring compliance processes such as control testing, risk register maintenance, and policy attestations.
- •Translate regulatory and framework requirements relevant to AI companies into actionable controls.
- •Identify and propose solutions for compliance gaps as the company grows.
- •Build and maintain tooling and documentation to improve audit cycles.
- •Requirements 7+ years of experience in technology and cybersecurity Governance, Risk, and Compliance (GRC).
- •Proven experience leading SOC 2, ISO 27001, FedRAMP, or comparable certifications.
- •Hands-on experience collecting audit evidence and writing control documentation.
- •Experience managing recurring compliance processes.
- •Ability to quickly learn new technical domains and translate them for non-technical stakeholders.
Required skills
SOC 2GDPR
Nice-to-have skills
PythonJavaScriptAWSGoogle CloudAzure
Domain expertise
aicybersecurity
Benefits & perks
health, dental, and vision benefits, unlimited PTO, paid parental leave, relocation support
Tech stack
SOC 2GDPR