Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer - Governance Risk Compliance

$100k - $228k

Xai

Security Engineer - Governance Risk Compliance

New York, NY; Palo Alto, CA; Washington, D.C.

About xAI

xAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

About The Role

We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) team member as we expand into government and public sector applications of AI. This critical role will ensure that xAI operates within regulatory, ethical, operational, and federal boundaries while fostering a culture of integrity and resilience. You will collaborate with cross-functional teams to safeguard our mission-driven work in AI development and deployment, including support for sensitive and classified environments.

Responsibilities
  • Execute security compliance implementation and audits (e.g., ISO 27001/42001, SOC2, FedRAMP HIGH, DoD Cloud Computing SRG IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
  • Work with 3PAOs (Third-Party Assessment Organizations) and federal government Authorizing Officials (AOs) to achieve compliance certifications, reports, and Authorized to Operate (ATO) status.
  • Identify, assess, and prioritize risks related to AI operations, cybersecurity, regulatory compliance, intellectual property, and cloud deployments.
  • Design and implement risk mitigation strategies, including monitoring systems, contingency plans, vulnerability scans, Plan of Action and Milestones (POAMs), and STIGs.
  • Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures throughout the project lifecycle.
  • Serve as a liaison between system owners, security personnel, and cross-functional teams to facilitate effective communication, collaboration, and control implementation.
  • Lead Risk Management Assessment and Authorization (A&A) processes, cloud system risk assessments, compliance reviews for new products/changes/features, and process enhancements.
  • Conduct regular risk assessments, scenario analyses, and proactive evaluations of emerging threats, certifications, requirements, and technologies in the AI landscape.
  • Oversee audits, certifications, third-party assessments, and vulnerability management to maintain compliance and operational credibility.
  • Act as a subject matter expert, providing guidance on risk, compliance, and cybersecurity matters; translate business and technical risks for leadership.
  • Create and present regular reports on GRC performance, risks, and compliance status to senior leadership and stakeholders.
Basic Qualifications
  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field
  • 3+ years of experience in governance, risk management, compliance, or technology audit roles.
  • Experience with vulnerability management, POAMs, STIG implementation, and cloud security controls.
Preferred Skills And Experience
  • 5+ years of security compliance or technology audit-related.
  • Previous systems engineering experience strongly preferred
  • Ability to evaluate control objectives with IT configurations
  • Experience in the tech or AI industry, particularly with startups, innovative organizations, or government/public sector engagements.
  • Proven expertise in regulatory frameworks, data privacy, cybersecurity, and federal compliance standards, preferably in a technology, cloud, or AI-driven environment.
  • Strong understanding of AI ethics, emerging technologies, Risk Management Framework (RMF), and their associated risks.
  • Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to balance innovation, oversight, and taking projects from conception to launch.
  • Excellent communication, stakeholder management, and translation skills, with experience influencing cross-functional teams and communicating risks to leadership.
  • Ability to thrive in a fast-paced, dynamic environment and adapt to evolving priorities.
  • Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.
  • Deep expertise maintaining frameworks such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, and STIG/RMF policies (including validation via ACAS and similar tools).
  • Familiarity with ISO 27001, ISO 42001, NIST, SOC 2, or similar compliance frameworks.
  • Background in managing third-party risk, vendor compliance programs, or federal assessments.
  • Understanding of cybersecurity controls for cloud service providers.
  • Knowledge of government cloud services and evolving certification programs.
Compensation And Benefits

$100,000 - $228,000 USD

Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

xAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Security Engineer - Governance Risk Compliance in Washington DC vacancy
  • $40 - $65 per hour

     ...The Cyber Security Analyst will actively participate in developing, implementing...  .... The Analyst will perform risk assessments, audits, and compliance reviews; maintain documentation; and...  ...enforcing compliance with cybersecurity governance frameworks (e.g., ISO 27001, ISO 4... 
    Suggested
    Work experience placement

    Insight Global

    Washington DC
    1 day ago
  • $18k

     ...Internal Review Security Engineer II (Contract Contingent) ProSidian is a Management...  ...services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness...  ..., Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services... 
    Suggested
    Contract work
    For contractors
    Work at office
    Immediate start

    ProSidian Consulting

    Arlington, VA
    4 days ago
  • $18k

     ...ITSM IT Security Engineer I ProSidian is a Management and Operations Consulting Services...  ...focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness...  ...Companies, Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services... 
    Suggested
    For contractors
    Work experience placement
    Work at office
    Local area
    Immediate start

    ProSidian Consulting

    Washington DC
    4 days ago
  • $107.9k - $195.05k

     ...seeking an experienced M365 Security and Compliance Administrator to join our...  ...environment within a GCC (Government Community Cloud) tenant, particularly...  ...context. This senior engineering role sits at the center of...  ..., outages, and operational risks. The successful candidate... 
    Suggested
    Local area
    Immediate start
    Night shift
    Day shift

    Leidos

    Washington DC
    19 hours ago
  • $218.03k - $256.5k

     ...(IAM) program, housed within Security, is a cross-functional team that designs, builds, and governs workforce identity services, privileged...  ...IAM program, partnering with Engineering, IT, Platform, and business...  ...enablement, reduce insider risk, and satisfy global regulatory... 
    Suggested
    For contractors
    Local area

    Coinbase

    Washington DC
    2 days ago
  •  ...seeking a Cybersecurity Analyst in Alexandria, VA, focused on governance, risk, and compliance (GRC) activities. The ideal candidate should have a...  ...certifications. You will lead compliance efforts, manage security controls, and provide risk analysis reporting to government... 

    Medium

    Alexandria, VA
    1 day ago
  •  ...Mid-Level InfoSec Security Engineer (Focus On Network Security) ProSidian is a Management...  ...focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness...  ...Companies, Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services... 
    Full time
    For contractors
    Internship
    Work at office
    Monday to Friday
    Shift work

    ProSidian Consulting

    Washington DC
    4 days ago
  • $130k - $140k

     ...Security Leadership & Governance Collaborate with senior leadership to align technology, cybersecurity...  ...security documentation and ensure compliance with sponsor and regulatory mandates...  ...an Information System Security Engineer (ISSO) / IT Systems Engineer to serve... 
    Contract work
    Work experience placement
    Local area

    Viterbi School of Engineering

    Arlington, VA
    4 days ago
  •  ...Lead, Cryptographic Security Engineer Mastercard powers economies and...  ...help people, businesses and governments realize their greatest potential...  ...enforcing governance and compliance to the Cryptographic and Key...  ...understanding of information security, risk and data privacy within the... 
    Full time
    Temporary work
    Part time
    Worldwide
    Flexible hours

    Dynamic Yield

    Arlington, VA
    4 days ago
  • $100k - $172.5k

     ...: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture...  ...for a Principal Product Security Engineer to be located in Danvers, MA or...  ...you are eager to leverage your security risk and compliance skills to make a difference and directly... 
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Adelphi, MD
    19 hours ago
  • ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE) POSITION OVERVIEW Zermount Inc...  ...Engineering (SCE) to support system risk analysis and ensure that federal information...  ...experience supporting U.S. Government systems 4+ years performing RMF, ISSO... 
    Remote work

    Zermount, Inc.

    Arlington, VA
    3 days ago
  • $90k - $110k

     ...consulting firm that supports Federal Government clients. We provide consulting...  ...will support the Information Systems Security Officer / Systems Security and...  ...Officer (ISSO/SSPO) in executing Risk Management Framework (RMF) compliance, Security Assessment and Authorization... 
    Contract work
    Temporary work
    For contractors
    Work experience placement
    Remote work

    OCT Consulting, LLC

    Hyattsville, MD
    1 day ago
  •  ...adversarial machine learning, enterprise security architecture, and governance. You will lead the design and...  ...— and translate technical risk into enterprise-aligned...  ...controls Partner closely with engineering, security, and compliance functions Present findings clearly... 

    C-Serv

    Washington DC
    1 day ago
  • $110k - $230k

     .... This role is designed for a staff-level security practitioner with deep Cyber Governance, Risk, and Compliance (GRC) expertise who shapes the vision, strategy...  ...governance automation capabilities. The Staff Security Engineer owns the end-to-end automated cyber governance... 
    Hourly pay
    Work experience placement
    Local area
    Remote work
    Flexible hours

    GEICO

    Bethesda, MD
    4 days ago
  • $109k - $124.4k

    Senior Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what we do at Capital One...  ..., not just a step in the compliance process. You thrive working with...  ...technical understanding of software engineering best practices, cloud infrastructure... 
    Full time
    Part time
    H1b
    Local area

    Capital One National Association

    Mc Lean, VA
    4 days ago
  •  ...Cyber Security Analyst Level 3 will help ensure today is safe and tomorrow is smarter. Our...  ...standards. Identifies security risks and exposures, determines the causes of...  ...conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of... 

    IC-CAP, LLC

    Riverdale, MD
    3 days ago
  • $237.6k - $297k

     ...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and...  ...power the world's leading models, and help enterprises and governments build, deploy, and oversee AI applications that deliver real... 
    Full time

    Scale AI

    Washington DC
    2 days ago
  •  ...Senior Strategic Consultant - DOS Training Security Engineering Dexis is a dynamic professional services firm dedicated to partnering with government and community leaders both in the U.S. and internationally to achieve critical social outcomes in a rapidly changing... 
    Contract work
    Work at office

    Dexis Consulting Group

    Washington DC
    4 days ago
  • $159.3k - $202.4k

     ...Amazon's Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering...  ...evidence of potentially damaging threat activities which pose a risk to Amazon customers and data. - You will work alongside... 
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    3 days ago
  • $178.4k - $226.7k

     ...Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global...  ...work, we provide opportunities for our engineers to pursue projects they are passionate...  ...security. They will clearly articulate risks to technical and non-technical audiences... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    3 days ago
  • $104k - $156k

     ...Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will...  ...security foundations that reduce risk while preserving productivity, partnering...  ...~ Knowledge of Zero Trustprinciplesand compliance standards (e.g., GDPR, HIPAA).... 
    Remote work

    Relativity

    Washington DC
    2 days ago
  • $159.3k - $202.4k

     ...Description Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications...  ...handling healthcare data meet HIPAA compliance and Amazon's security bar while...  ...of AI-specific security risks including prompt injection, model... 
    Flexible hours

    Amazon

    Arlington, VA
    4 days ago
  • $136k - $184k

     ...At Amazon Healthcare Security, we are on a mission to make healthcare...  ...are looking for a Security Engineer to join our team. As a Security...  ...difficult challenges, make risk-based assessments founded on...  ...in information security and compliance - Experience with... 
    Temporary work
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    4 days ago
  •  .... Additionally, will support compliance scanning and troubleshooting...  ...Analyze findings, prioritize risk, and track remediation progress...  ...for program office and engineering partners. Job Qualifications...  ...Bachelor's degree ~3 years security-related experience. ~ Experience... 
    Work at office

    True Zero Technologies, LLC

    Washington DC
    4 days ago
  • A cybersecurity solutions provider is seeking a Cyber Security Analyst - Intermediate to support cybersecurity governance and defense. This role requires expertise in RMF/A&A processes and SOC operations, utilizing tools like Microsoft Sentinel for monitoring. Preferred... 
    Remote job

    DecisionPoint Corporation

    Washington DC
    19 hours ago
  • DecisionPoint Corporation is seeking a Cyber Security Analyst - Intermediate to support cybersecurity governance and operational defense. This role involves RMF/A&A and TRM specialization, alongside frontline SOC support through Microsoft Sentinel monitoring. The applicant... 
    Remote job

    DecisionPoint Corporation

    Washington DC
    19 hours ago
  • Overview The Government Publishing Office (GPO) SecDevOps program provides advanced security, development, and operations support to safeguard federal information systems...  ...operations to ensure continuous security, compliance, and resilience across GPO’s enterprise IT services... 
    Contract work
    For contractors
    Work at office
    Local area
    Remote work

    DecisionPoint Corporation

    Washington DC
    19 hours ago
  • $170k

     ...the legal and policy frameworks that govern technology and digital ecosystems?...  ...and data protection, cybersecurity compliance, digital governance, and risk management, helping them navigate...  ...Responsibilities: Conduct regular security assessments, vulnerability testing,... 
    Permanent employment
    Washington DC
    more than 2 months ago
  • $150k - $180k

    A leading data center organization is seeking a Global Security Policy Architect to develop and maintain a unified security policy framework...  ...should have at least 12 years of experience in security governance, familiarity with global regulations, and strong documentation... 

    Tract Capital Management, LP

    Alexandria, VA
    19 hours ago
  •  ...solutions provider is seeking a Global Security Policy Architect to develop and maintain...  ...years of experience in enterprise security governance and deep familiarity with global...  ...leading reviews and updates based on evolving risks. Competitive compensation and extensive... 

    Fleet Data Centers

    Alexandria, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer - Governance Risk Compliance. Be the first to apply!