Security Engineer - Governance Risk Compliance
$100k - $228kXai
Security Engineer - Governance Risk Compliance
New York, NY; Palo Alto, CA; Washington, D.C.
About xAI
xAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
About The Role:
We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) team member as we expand into government and public sector applications of AI. This critical role will ensure that xAI operates within regulatory, ethical, operational, and federal boundaries while fostering a culture of integrity and resilience. You will collaborate with cross-functional teams to safeguard our mission-driven work in AI development and deployment, including support for sensitive and classified environments.
Responsibilities:
- Execute security compliance implementation and audits (e.g., ISO 27001/42001, SOC2, FedRAMP HIGH, DoD Cloud Computing SRG IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
- Work with 3PAOs (Third-Party Assessment Organizations) and federal government Authorizing Officials (AOs) to achieve compliance certifications, reports, and Authorized to Operate (ATO) status.
- Identify, assess, and prioritize risks related to AI operations, cybersecurity, regulatory compliance, intellectual property, and cloud deployments.
- Design and implement risk mitigation strategies, including monitoring systems, contingency plans, vulnerability scans, Plan of Action and Milestones (POAMs), and STIGs.
- Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures throughout the project lifecycle.
- Serve as a liaison between system owners, security personnel, and cross-functional teams to facilitate effective communication, collaboration, and control implementation.
- Lead Risk Management Assessment and Authorization (A&A) processes, cloud system risk assessments, compliance reviews for new products/changes/features, and process enhancements.
- Conduct regular risk assessments, scenario analyses, and proactive evaluations of emerging threats, certifications, requirements, and technologies in the AI landscape.
- Oversee audits, certifications, third-party assessments, and vulnerability management to maintain compliance and operational credibility.
- Act as a subject matter expert, providing guidance on risk, compliance, and cybersecurity matters; translate business and technical risks for leadership.
- Create and present regular reports on GRC performance, risks, and compliance status to senior leadership and stakeholders.
Basic Qualifications:
- Previous systems engineering experience strongly preferred
- Must have the ability to evaluate control objectives with IT configurations
- Bachelor's degree in Computer Science Information Security, Cybersecurity, or a related field
- Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.
- 3+ years of experience in governance, risk management, compliance, or technology audit roles.
- Proven expertise in regulatory frameworks, data privacy, cybersecurity, and federal compliance standards, preferably in a technology, cloud, or AI-driven environment.
- Strong understanding of AI ethics, emerging technologies, Risk Management Framework (RMF), and their associated risks.
- Experience with vulnerability management, POAMs, STIG implementation, and cloud security controls.
- Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to balance innovation, oversight, and taking projects from conception to launch.
- Excellent communication, stakeholder management, and translation skills, with experience influencing cross-functional teams and communicating risks to leadership.
- Ability to thrive in a fast-paced, dynamic environment and adapt to evolving priorities.
Preferred Skills And Experience:
- Experience in the tech or AI industry, particularly with startups, innovative organizations, or government/public sector engagements.
- Deep expertise maintaining frameworks such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, and STIG/RMF policies (including validation via ACAS and similar tools).
- Familiarity with ISO 27001, ISO 42001, NIST, SOC 2, or similar compliance frameworks.
- Background in managing third-party risk, vendor compliance programs, or federal assessments.
- Understanding of cybersecurity controls for cloud service providers.
- Knowledge of government cloud services and evolving certification programs.
- 5+ years of security compliance or technology audit-related.
Compensation And Benefits:
$100,000 - $228,000 USD
Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.
xAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
$18k
...ITSM IT Security Engineer III ProSidian is a Management and Operations Consulting Services... ...focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness... ..., Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services...SuggestedFor contractorsWork experience placementWork at officeLocal areaImmediate start$18k
...Internal Review Security Engineer II (Contract Contingent) ProSidian is a Management... ...services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness... ..., Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services...SuggestedContract workFor contractorsWork at officeImmediate start$218.03k - $256.5k
...(IAM) program, housed within Security, is a cross-functional team that designs, builds, and governs workforce identity services, privileged... ...IAM program, partnering with Engineering, IT, Platform, and business... ...enablement, reduce insider risk, and satisfy global regulatory...SuggestedFor contractorsLocal area- ...Mid-Level InfoSec Security Engineer (Focus On Network Security) ProSidian is a Management... ...focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness... ...Companies, Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services...SuggestedFull timeFor contractorsInternshipWork at officeMonday to FridayShift work
$130k - $140k
...Security Leadership & Governance Collaborate with senior leadership to align technology, cybersecurity... ...security documentation and ensure compliance with sponsor and regulatory mandates... ...an Information System Security Engineer (ISSO) / IT Systems Engineer to serve...SuggestedContract workWork experience placementLocal area$107.9k - $195.05k
...seeking an experienced M365 Security and Compliance Administrator to join our... ...environment within a GCC (Government Community Cloud) tenant, particularly... ...context. This senior engineering role sits at the center of... ..., outages, and operational risks. The successful candidate...Full timeNight shiftDay shift- ...Lead, Cryptographic Security Engineer Mastercard powers economies and... ...help people, businesses and governments realize their greatest potential... ...enforcing governance and compliance to the Cryptographic and Key... ...understanding of information security, risk and data privacy within the...Full timeTemporary workPart timeWorldwideFlexible hours
$100k - $172.5k
...: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture... ...for a Principal Product Security Engineer to be located in Danvers, MA or... ...you are eager to leverage your security risk and compliance skills to make a difference and directly...Full timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week- ...The Vulnerability Analyst II provides cybersecurity risk, vulnerability management, and compliance support services in alignment with the SBA Enterprise... ...vulnerability assessments, supports POA&M development, validates security controls, coordinates remediation efforts, and...
$110k - $230k
.... This role is designed for a staff-level security practitioner with deep Cyber Governance, Risk, and Compliance (GRC) expertise who shapes the vision, strategy... ...governance automation capabilities. The Staff Security Engineer owns the end-to-end automated cyber governance...Hourly payWork experience placementLocal areaRemote workFlexible hours- ...capital cost. As a Senior Azure Cloud Security Engineer, you will be the primary architect... ...architecture, focusing on identity governance, modern endpoint management, and... ...policies incorporating device compliance, location, and risk-based signals. Implement Privileged...For contractorsWork at office
- ...Senior Strategic Consultant - DOS Training Security Engineering Dexis is a dynamic professional services firm dedicated to partnering with government and community leaders both in the U.S. and internationally to achieve critical social outcomes in a rapidly changing...Contract workWork at office
$178.4k - $226.7k
...Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global... ...work, we provide opportunities for our engineers to pursue projects they are passionate... ...security. They will clearly articulate risks to technical and non-technical audiences...InternshipFlexible hours$136k - $184k
...Amazon's Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering... ...data repositories to identify threat activities which pose a risk to Amazon customers and data. - You will work alongside incident...InternshipFlexible hoursShift work$136k - $184k
...At Amazon Healthcare Security, we are on a mission to make healthcare... ...are looking for a Security Engineer to join our team. As a Security... ...difficult challenges, make risk-based assessments founded on... ...in information security and compliance - Experience with...Temporary workInternshipFlexible hours$237.6k - $297k
...Security Engineer, Product Security We are seeking a highly technical Security Engineer to join our Product Security team. This role is... ...power the world's leading models, and help enterprises and governments build, deploy, and oversee AI applications that deliver real...Full time$159.3k - $202.4k
...Description Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications... ...handling healthcare data meet HIPAA compliance and Amazon's security bar while... ...of AI-specific security risks including prompt injection, model...Flexible hours- .... Additionally, will support compliance scanning and troubleshooting... ...Analyze findings, prioritize risk, and track remediation progress... ...for program office and engineering partners. Job Qualifications... ...Bachelor's degree ~3 years security-related experience. ~ Experience...Work at office
$69.4k - $158k
...Share job via: Share Cybersecurity Governance Analyst The Opportunity: When our country's cyber security is on the line, simply reacting is not enough,... ...the coverage of those policies, and areas of risks. You'll evaluate or audit how policies stack up...Full timeContract workPart timeWork at officeLocal areaRemote work- ...integrators in the defense and government services industry. We... ...to enable national security missions worldwide.... ...SOSi is seeking a Risk and Vulnerability Analyst... ...· Support cloud compliance scans and assessment activities... ...with cyber defense engineering and system teams to...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- ...Cyber And It Security Risk Analyst Location: Bethesda, MD Contract: 12 Months Position Summary We are seeking a Cyber and Information... ...and suppliers. Support internal and external audits and compliance efforts. Document implementation statements for security...Contract workFor contractors
- ...Network Security Engineer (Cisco, Palo Alto) About Us: We are a dynamic technology services company based in Washington, DC, specializing in cutting-edge network solutions. We are seeking a skilled Network Engineer to join our team to ensure the seamless operation...Remote work
$60 - $68 per hour
...Overview Novacoast Staffing is currently assisting a financial government institution in its search for an experienced Firewall Security Engineer that is experienced in Palo Alto Firewalls for a contract role that is expected to go a minimum of 2 years with option...Hourly payContract workImmediate start- ...Job Title Responsibilities Support annual information security program risk assessments. Facilitate/Support interviews and evidence gathering. Coordinate risk assessment activities with service provider. Coordinate and prepare documentation, internal...Local areaRemote work
- ...seeking a Cybersecurity Compliance analyst in Arlington,... ...expertise of the Risk Management Framework with... ...justifications, preparing government client for non-... ...IAT-II level (CompTIA Security+, GSEC, SSCP, or CCNA-Security... ...and systems engineering challenges across the...
- ...seeking a Cybersecurity Compliance analyst in Arlington,... ...expertise of the Risk Management Framework with... ...justifications, preparing government client for non-... ...IAT-II level (CompTIA Security+, GSEC, SSCP, or CCNA-Security... ...IT, enterprise IT, engineering services, and professional...
- ...Junior Cyber Risk Data Engineer/Analyst Technomics is a growing employee-owned, decision analytics... ...range of clients across the Federal government, from senior level policy makers to... ...Experience supporting national security organizations. Familiarity with cyber...InternshipShift work
- ...Cybersecurity Systems Engineer/Information Systems Security Engineer (ISSE) Transform technology into opportunity... ...the artifacts that support the Risk Management Framework (RMF) and ICD 5... ...audit liaison activities, and compliance oversight activities to strengthen the...For contractorsInterim role
$166k - $253k
...ABOUT THE JOB We're seeking a Security Software Engineer to develop novel security tooling for... ...Knowledge of security frameworks and compliance standards. Experience in mobile development... ...provider to conduct pre-employment risk, integrity, and due diligence...Full timeWork experience placementImmediate start$71.2k - $158.2k
...Senior Federal Information Systems Security Engineer (ISSE) The Senior Federal Information... ...Ability to obtain and maintain the required government security clearance - U.S.... ...support mission timelines · Maintain compliance with all corporate and federal cybersecurity...Contract workTemporary workWork experience placementRelocationFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer - Governance Risk Compliance. Be the first to apply!
- information system security engineer Washington DC
- senior application security engineer Washington DC
- sr information security engineer Washington DC
- security engineering manager Washington DC
- security operations engineer Washington DC
- cloud security engineer Washington DC
- azure security engineer Washington DC
- endpoint security engineer Washington DC
- physical security engineer Washington DC
- systems security engineer Washington DC




