Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Governance, Risk, Compliance (GRC) Lead

association of arab universities

ABOUT AARU

Aaru operates at the frontier of predictive intelligence, using AI to simulate and predict human behavior at scale. By generating and deploying instances of artificial intelligence that mirror humans, called agents, Aaru simulates entire populations with unprecedented accuracy. Our partners use Aaru to refine strategic positioning, identify and understand high-value audiences, validate concepts and messaging before launch, optimize pricing decisions, and build a continuously richer understanding of their customers through simulation. We provide organizations with invaluable foresight, empowering them to anticipate outcomes and proactively make the right decisions at the right time, every time. We're a small, dedicated, mission-driven team and we intend to stay that way. We believe the best work happens when exceptionally talented people are given ownership, trust and the space to operate without bureaucratic friction. We work with urgency and intellectual honesty and expect new team members to match our velocity. We seek individuals who thrive at the frontier, who push beyond conventional limits, who bring curiosity and conviction in equal measure, and who want their work to have demonstrable impact in the world. If you're energized by the idea of a small team doing things that feel impossible, let’s build together.

ABOUT THE ROLE

Aaru is building out its governance, risk, and compliance function and is hiring its first dedicated GRC Lead to own it. Our customers are large enterprises that use Aaru to pressure-test high-stakes decisions before they make them. They hold us to a serious standard on how we handle their data and how our systems are controlled, and every deal we sign runs through that scrutiny. Because of what we build, that scrutiny goes further than it does for most software vendors — into how our models are trained, how personal data does and does not inform agent construction, and how simulated outputs relate to real individuals. You will own that surface end to end: enterprise security review, audit readiness, evidence and policy governance, vendor risk, and AI governance. This is a build role rather than a maintenance one. You will not be inheriting a legacy program, and you will be expected to automate the work rather than absorb it.

RESPONSIBILITIES

Customer trust and enterprise security review. Own the response to security questionnaires, due diligence requests, and RFP security sections, and represent Aaru's security posture directly in customer security conversations and vendor risk reviews. Build and maintain a canonical answer library so the same questions are never solved twice. Audit management. Serve as primary point of contact for external auditors across readiness, fieldwork, and surveillance cycles. Manage RFI response, control walkthroughs, and finding remediation to closure. Control testing and monitoring. Run recurring control checks, access reviews, and periodic testing. Document effectiveness, identify gaps, and drive remediation with owners on defined timelines. Policy and evidence governance. Keep policies current, versioned, distributed, and attested. Automate evidence collection in our GRC platform so that artifacts are generated by integration rather than gathered by hand. Third-party risk. Build and manage the vendor assessment lifecycle: questionnaires, SOC 2 and ISO review, risk scoring, and policy enforcement across procurement and renewals. AI governance. Own how Aaru answers for the governance of its own models and agents, working alongside engineering, product, and legal.

YOU MAY BE A FIT IF

You have 5-8 years in GRC, security compliance, or IT audit, ideally at a company selling into enterprise. Big 4 and specialist assurance backgrounds are well suited to this role. You have working knowledge of SOC 2 and familiarity with ISO 27001, NIST CSF, HIPAA, or PCI-DSS. You have used Vanta, Drata, OneTrust, or similar to automate evidence collection and manage controls, and you default to building a workflow over doing the task by hand. You use AI tools for substantive work — drafting, research, gap analysis, evidence review — and you have a clear practice of validating output before it ships. You have supported live sales cycles through security review, and you believe this function should never be the reason a deal slips. You write with precision, and can explain a control requirement to an engineer, a customer's security team, and a commercial buyer without changing the substance. You build repeatable process in environments where the process does not yet exist and you are expected to propose one.

STRONG CANDIDATES MAY ALSO

Have taken a company through a first SOC 2 Type II or ISO 27001 certification and know what tends to break. Have worked with AI governance frameworks such as ISO 42001, NIST AI RMF, or the EU AI Act, or have answered hard diligence questions about model training data and provenance. Have supported regulated financial services or public sector procurement and the documentation burden that comes with it. Have handled multi-jurisdiction privacy and data residency questions, including US state privacy law, GDPR, and Singapore's PDPA. Read architecture documentation comfortably and ask good questions of engineers about how a control actually works. Script or automate — Python, JavaScript, or low-code — applied to compliance workflows. Hold CISA, CRISC, CISM, or ISO 27001 Lead Auditor / Lead Implementer.

LOCATION

This role is based in New York City. Aaru is an in-person company, working 5 days a week in office. Candidates are expected to be located within the New York City metropolitan area or open to relocation.

BENEFITS

At Aaru, we take care of our people. competitive base salary and equity participation comprehensive medical, vision, and dental coverage visa sponsorship and relocation support various other benefits and perks #J-18808-Ljbffr association of arab universities

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Governance, Risk, Compliance (GRC) Lead in New York, NY vacancy
  • The Opportunity Adobe’s Technology Governance, Risk & Compliance Organization plays a meaningful role in maintaining customer trust...  ...while enabling innovation at scale. We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our GRC program. This... 
    Suggested
    Local area
    Shift work

    Adobe

    New York, NY
    3 days ago
  • A leading consulting firm seeks a Governance, Risk, and Compliance (GRC) leader to advance their programs. This remote role requires 5-7 years of experience in GRC with relevant certifications like CISSP or CISM. The successful candidate will lead policy development, perform... 
    Suggested
    Remote job

    Franklin Fitch

    New York, NY
    1 day ago
  • United States Digital Space LLC is seeking a Senior InfoSec GRC Analyst for a fully remote, international role. You will own governance, risk, and compliance across the ISMS, drive ISO 27001 and SOC 2 audits, and review customer security requirements to enable safe production... 
    Suggested
    Remote job

    United States Digital Space LLC

    New York, NY
    3 days ago
  • $300k - $400k

     ...financial technology organization in New York is seeking a Chief Information Security Officer to lead security functions including governance, risk management, and compliance. The ideal candidate has strong experience in fintech, leadership in building security programs,... 
    Suggested

    DriveWealth

    New York, NY
    1 day ago
  • Owner.com is seeking a GRC Specialist to navigate complex Risk, Compliance, and Vulnerability Management as we grow. You will drive compliance efforts, secure systems, and advise senior leadership in security risks. Requires 3+ years in compliance frameworks and 5+ years... 
    Suggested
    Remote job

    Owner.com

    New York, NY
    3 days ago
  • Aaru in New York City is seeking a GRC Lead to own governance, risk, and compliance end-to-end. This is a build role focused on automating evidence collection, security reviews, and control testing for enterprise customers. You will collaborate with engineering, product... 

    association of arab universities

    New York, NY
    4 days ago
  • Legora is seeking a senior GRC/Security professional to own our assurance program end to end, including certifications, AI governance, and risk leadership. You’ll interface with auditors, regulators, and customer security teams, shaping controls that scale across products... 

    Legora

    New York, NY
    13 hours ago
  • United States Digital Space LLC is seeking a Senior Governance & Risk Compliance Program Manager on the GRC team. You will design, implement, and coordinate programs...  ...Engineering, Product, Design, and Sales. You will lead AI governance and compliance initiatives, advance... 
    Remote job

    United States Digital Space LLC

    New York, NY
    4 days ago
  • Aaru in New York City is expanding its governance, risk, and compliance team and is seeking a dedicated GRC Lead to own the program. You will drive enterprise security reviews, audit readiness, and policy governance with an emphasis on automation and scalable processes.... 

    Aaru

    New York, NY
    2 days ago
  • $182.75k - $215k

     ...unlock the opportunities of tomorrow. As a Lead Product Marketing Manager focused on our Carta Law segment, you'll work to:Governance, Compliance & Market Presence: Apply a deep focus on governance, risk, and compliance (GRC) to product positioning, while serving as a... 
    Full time

    Carta

    New York, NY
    2 days ago
  • $100k - $180k

    A leading FinTech company in New York is looking for a Senior GRC Analyst to strengthen their Governance, Risk, and Compliance function. The successful candidate will have over 10 years of experience in GRC, expertise in federal security frameworks, and a proactive approach... 

    Quantexa

    New York, NY
    1 day ago
  •  ...DescriptionBring your expertise to JPMorganChase. As part of Risk Management and Compliance, you play a crucial role in maintaining JPMorganChase's...  ....As a Quant Model Risk Vice President in the Model Risk Governance and Review team, you will be responsible for assessing... 

    JP Morgan Chase

    New York, NY
    2 days ago
  •  ...AI Governance Lead Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like...  ...initiatives to: Account plan FS client priorities (risk, compliance, ops efficiency, growth) I&D service offerings Ensure... 
    Permanent employment
    Full time
    Contract work
    Local area

    Capgemini

    New York, NY
    3 days ago
  •  ...Quant Model Risk Vice PresidentBring your expertise to JPMorganChase. As part of Risk Management and Compliance, you play a crucial role in maintaining JPMorganChase's strength...  ...Risk Vice President in the Model Risk Governance and Review team, you will be responsible... 

    Chase

    New York, NY
    1 day ago
  • $147.25k - $215k

     ...Description Bring your expertise to JPMorganChase. As part of Risk Management and Compliance, you play a crucial role in maintaining JPMorganChase's...  ...As a Quant Model Risk Vice President in the Model Risk Governance and Review team, you will be responsible for assessing... 

    JPMorgan Chase Bank, N.A.

    New York, NY
    18 hours ago
  • The FCC Compliance Analytics Lead will support the implementation, governance, and ongoing optimization of Financial Crimes Compliance (FCC) monitoring solutions and...  ...expertise in compliance analytics, financial crime risk management, and regulatory reporting. The role... 

    Compunnel, Inc.

    New York, NY
    4 days ago
  • Alliant Insurance Services seeks a procurement governance professional focused on enterprise third parties. You will manage relationships across IT, Legal and Risk, driving compliance and contract governance for enterprise tools and vendors. The role emphasizes ownership... 
    Contract work

    Alliant Insurance Services

    New York, NY
    3 days ago
  • AXA XL is seeking a Transversal Underwriting and Governance Lead for the Americas to develop and monitor governance frameworks, KPIs,...  ...and controls across underwriting. You will collaborate with risk, compliance, audit, and underwriting teams to ensure adherence to global... 

    AXA Group

    New York, NY
    1 day ago
  • TPG in New York seeks a detail-oriented IT Audit/ GRC professional to lead the day-to-day SOX IT program and assist with risk assessments. You will coordinate with external and internal auditors and co-sourcing partners to ensure timely evidence delivery and effective remediation... 

    Tenth Revolution Group

    New York, NY
    4 days ago
  • AXA XL is seeking a Transversal Underwriting & Governance Lead for the Americas to develop and monitor governance frameworks, policies...  ...across underwriting. You will collaborate with underwriting, risk, compliance and audit teams to uphold governance standards and enable... 

    AXA XL

    New York, NY
    4 days ago
  •  ...Quant Model Risk Vice PresidentBring your expertise to JPMorganChase. As part of Risk Management and Compliance, you play a crucial role in maintaining JPMorganChase's strength...  ...Risk Vice President in the Model Risk Governance and Review team, you will be responsible... 

    Hackajob

    New York, NY
    4 days ago
  • TKO Group Holdings, Inc. in New Jersey is seeking an IT Governance, Risk and Compliance Manager to lead day-to-day IT compliance, including SOX and ITGC controls, audit readiness, and governance documentation. This role partners with Legal, IT, Security, Internal Audit,... 

    TKO

    New York, NY
    2 days ago
  • $145k - $185k

     ...Manager (GPM) is a senior player/coach responsible for leading a team of Product Managers across a suite of Origami products...  ...a cohesive vision and execution strategy. The GPM for Governance, Risk, & Compliance (GRC) is responsible for ensuring the products they own... 
    Full time
    Temporary work
    Work experience placement
    Remote work
    Flexible hours

    Origami Risk LLC.

    New York, NY
    1 day ago
  • $130k - $160k

     ...an incredible career at a leading science and technology company...  ...possible. The Policy and Compliance Lead is responsible for...  ...on policy interpretation, risk mitigation strategies, and...  ...experience in:Experience with governance, risk, and compliance (GRC) platforms and policy... 
    Full time
    Remote work
    Work from home
    Flexible hours

    Danaher Corporation

    New York, NY
    1 day ago
  • Carta is seeking a Lead Product Marketing Manager focused on Carta Law in New York. You’ll own governance, risk, and market presence, shaping product positioning and driving launches with cross-functional teams. You’ll craft compelling collateral, coordinate with Creative... 

    cartage.co

    New York, NY
    3 days ago
  •  ...This is a professional individual contributor role within the first-line-of-defense (1LoD) that supports the execution of model risk governance activities across the model lifecycle. This role is responsible for the day-to-day operational tasks that underpin the... 
    Work at office

    Citi

    New York, NY
    1 day ago
  • United States Digital Space LLC is seeking a Lead Product Marketing Manager focused on our Law segment. You will drive governance, risk, and compliance-focused product positioning and own end-to-end launch strategy with cross-functional teams to ensure successful market... 

    United States Digital Space LLC

    New York, NY
    4 days ago
  • Carta seeks a Lead Product Marketing Manager for Carta Law to shape governance, risk, and compliance-focused product positioning and to serve as a subject matter expert at company events. You will drive end-to-end launches, craft sales assets, and align GTM with demand... 

    Carta Healthcare

    New York, NY
    3 days ago
  •  ...Job Description Job Description GRC Lead requires: Hands-on experience implementing or managing audit technology platforms...  ...tools such as Power BI, Tableau, or advanced Excel. Governance, Risk, and Compliance Teaching or Technical Lead Bachelor's degree in... 

    Globalchannelmanagement

    New York, NY
    8 days ago
  • ABB Inc. seeks a Senior Leader to oversee the U.S. Trade Compliance Program, supporting the Country Trade Compliance Officer. This remote role drives governance, risk management, and regulatory compliance across ABB’s U.S. operations, coordinating with LTCOs and business... 
    Remote job

    ABB Inc.

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Governance, Risk, Compliance (GRC) Lead. Be the first to apply!