Security Engineer - Governance Risk Compliance
$100k - $228kXai
Security Engineer - Governance Risk Compliance
New York, NY; Palo Alto, CA; Washington, D.C.
About xAI
xAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
About The Role
We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) team member as we expand into government and public sector applications of AI. This critical role will ensure that xAI operates within regulatory, ethical, operational, and federal boundaries while fostering a culture of integrity and resilience. You will collaborate with cross-functional teams to safeguard our mission-driven work in AI development and deployment, including support for sensitive and classified environments.
Responsibilities
- Execute security compliance implementation and audits (e.g., ISO 27001/42001, SOC2, FedRAMP HIGH, DoD Cloud Computing SRG IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
- Work with 3PAOs (Third-Party Assessment Organizations) and federal government Authorizing Officials (AOs) to achieve compliance certifications, reports, and Authorized to Operate (ATO) status.
- Identify, assess, and prioritize risks related to AI operations, cybersecurity, regulatory compliance, intellectual property, and cloud deployments.
- Design and implement risk mitigation strategies, including monitoring systems, contingency plans, vulnerability scans, Plan of Action and Milestones (POAMs), and STIGs.
- Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures throughout the project lifecycle.
- Serve as a liaison between system owners, security personnel, and cross-functional teams to facilitate effective communication, collaboration, and control implementation.
- Lead Risk Management Assessment and Authorization (A&A) processes, cloud system risk assessments, compliance reviews for new products/changes/features, and process enhancements.
- Conduct regular risk assessments, scenario analyses, and proactive evaluations of emerging threats, certifications, requirements, and technologies in the AI landscape.
- Oversee audits, certifications, third-party assessments, and vulnerability management to maintain compliance and operational credibility.
- Act as a subject matter expert, providing guidance on risk, compliance, and cybersecurity matters; translate business and technical risks for leadership.
- Create and present regular reports on GRC performance, risks, and compliance status to senior leadership and stakeholders.
Basic Qualifications
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field
- 3+ years of experience in governance, risk management, compliance, or technology audit roles.
- Experience with vulnerability management, POAMs, STIG implementation, and cloud security controls.
Preferred Skills And Experience
- 5+ years of security compliance or technology audit-related.
- Previous systems engineering experience strongly preferred
- Ability to evaluate control objectives with IT configurations
- Experience in the tech or AI industry, particularly with startups, innovative organizations, or government/public sector engagements.
- Proven expertise in regulatory frameworks, data privacy, cybersecurity, and federal compliance standards, preferably in a technology, cloud, or AI-driven environment.
- Strong understanding of AI ethics, emerging technologies, Risk Management Framework (RMF), and their associated risks.
- Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to balance innovation, oversight, and taking projects from conception to launch.
- Excellent communication, stakeholder management, and translation skills, with experience influencing cross-functional teams and communicating risks to leadership.
- Ability to thrive in a fast-paced, dynamic environment and adapt to evolving priorities.
- Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.
- Deep expertise maintaining frameworks such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, and STIG/RMF policies (including validation via ACAS and similar tools).
- Familiarity with ISO 27001, ISO 42001, NIST, SOC 2, or similar compliance frameworks.
- Background in managing third-party risk, vendor compliance programs, or federal assessments.
- Understanding of cybersecurity controls for cloud service providers.
- Knowledge of government cloud services and evolving certification programs.
Compensation And Benefits
$100,000 - $228,000 USD
Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.
xAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
$40 - $65 per hour
...The Cyber Security Analyst will actively participate in developing, implementing... .... The Analyst will perform risk assessments, audits, and compliance reviews; maintain documentation; and... ...enforcing compliance with cybersecurity governance frameworks (e.g., ISO 27001, ISO 4...SuggestedWork experience placement$18k
...Internal Review Security Engineer II (Contract Contingent) ProSidian is a Management... ...services focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness... ..., Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services...SuggestedContract workFor contractorsWork at officeImmediate start$18k
...ITSM IT Security Engineer I ProSidian is a Management and Operations Consulting Services... ...focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness... ...Companies, Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services...SuggestedFor contractorsWork experience placementWork at officeLocal areaImmediate start$107.9k - $195.05k
...seeking an experienced M365 Security and Compliance Administrator to join our... ...environment within a GCC (Government Community Cloud) tenant, particularly... ...context. This senior engineering role sits at the center of... ..., outages, and operational risks. The successful candidate...SuggestedLocal areaImmediate startNight shiftDay shift$218.03k - $256.5k
...(IAM) program, housed within Security, is a cross-functional team that designs, builds, and governs workforce identity services, privileged... ...IAM program, partnering with Engineering, IT, Platform, and business... ...enablement, reduce insider risk, and satisfy global regulatory...SuggestedFor contractorsLocal area- ...seeking a Cybersecurity Analyst in Alexandria, VA, focused on governance, risk, and compliance (GRC) activities. The ideal candidate should have a... ...certifications. You will lead compliance efforts, manage security controls, and provide risk analysis reporting to government...
- ...Mid-Level InfoSec Security Engineer (Focus On Network Security) ProSidian is a Management... ...focus on the broad spectrum of Risk Management, Compliance, Business Process, IT Effectiveness... ...Companies, Fortune 1,000 Enterprises, and Government Agencies of all sizes. Our Services...Full timeFor contractorsInternshipWork at officeMonday to FridayShift work
$130k - $140k
...Security Leadership & Governance Collaborate with senior leadership to align technology, cybersecurity... ...security documentation and ensure compliance with sponsor and regulatory mandates... ...an Information System Security Engineer (ISSO) / IT Systems Engineer to serve...Contract workWork experience placementLocal area- ...Lead, Cryptographic Security Engineer Mastercard powers economies and... ...help people, businesses and governments realize their greatest potential... ...enforcing governance and compliance to the Cryptographic and Key... ...understanding of information security, risk and data privacy within the...Full timeTemporary workPart timeWorldwideFlexible hours
$100k - $172.5k
...: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture... ...for a Principal Product Security Engineer to be located in Danvers, MA or... ...you are eager to leverage your security risk and compliance skills to make a difference and directly...Full timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week- ZERMOUNT POSITION DESCRIPTION (PD) SECURITY & COMPLIANCE ENGINEERING (SCE) POSITION OVERVIEW Zermount Inc... ...Engineering (SCE) to support system risk analysis and ensure that federal information... ...experience supporting U.S. Government systems 4+ years performing RMF, ISSO...Remote work
$90k - $110k
...consulting firm that supports Federal Government clients. We provide consulting... ...will support the Information Systems Security Officer / Systems Security and... ...Officer (ISSO/SSPO) in executing Risk Management Framework (RMF) compliance, Security Assessment and Authorization...Contract workTemporary workFor contractorsWork experience placementRemote work- ...adversarial machine learning, enterprise security architecture, and governance. You will lead the design and... ...— and translate technical risk into enterprise-aligned... ...controls Partner closely with engineering, security, and compliance functions Present findings clearly...
$110k - $230k
.... This role is designed for a staff-level security practitioner with deep Cyber Governance, Risk, and Compliance (GRC) expertise who shapes the vision, strategy... ...governance automation capabilities. The Staff Security Engineer owns the end-to-end automated cyber governance...Hourly payWork experience placementLocal areaRemote workFlexible hours$109k - $124.4k
Senior Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what we do at Capital One... ..., not just a step in the compliance process. You thrive working with... ...technical understanding of software engineering best practices, cloud infrastructure...Full timePart timeH1bLocal area- ...Cyber Security Analyst Level 3 will help ensure today is safe and tomorrow is smarter. Our... ...standards. Identifies security risks and exposures, determines the causes of... ...conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of...
$237.6k - $297k
...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and... ...power the world's leading models, and help enterprises and governments build, deploy, and oversee AI applications that deliver real...Full time- ...Senior Strategic Consultant - DOS Training Security Engineering Dexis is a dynamic professional services firm dedicated to partnering with government and community leaders both in the U.S. and internationally to achieve critical social outcomes in a rapidly changing...Contract workWork at office
$159.3k - $202.4k
...Amazon's Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering... ...evidence of potentially damaging threat activities which pose a risk to Amazon customers and data. - You will work alongside...Flexible hoursShift work$178.4k - $226.7k
...Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global... ...work, we provide opportunities for our engineers to pursue projects they are passionate... ...security. They will clearly articulate risks to technical and non-technical audiences...InternshipFlexible hours$104k - $156k
...Hybrid Job Overview As an Advanced Security Engineer focused on Endpoint Security, you will... ...security foundations that reduce risk while preserving productivity, partnering... ...~ Knowledge of Zero Trustprinciplesand compliance standards (e.g., GDPR, HIPAA)....Remote work$159.3k - $202.4k
...Description Amazon Healthcare Security's (HealthSec) AI team is hiring a Security Engineer II to secure GenAI applications... ...handling healthcare data meet HIPAA compliance and Amazon's security bar while... ...of AI-specific security risks including prompt injection, model...Flexible hours$136k - $184k
...At Amazon Healthcare Security, we are on a mission to make healthcare... ...are looking for a Security Engineer to join our team. As a Security... ...difficult challenges, make risk-based assessments founded on... ...in information security and compliance - Experience with...Temporary workInternshipFlexible hours- .... Additionally, will support compliance scanning and troubleshooting... ...Analyze findings, prioritize risk, and track remediation progress... ...for program office and engineering partners. Job Qualifications... ...Bachelor's degree ~3 years security-related experience. ~ Experience...Work at office
- A cybersecurity solutions provider is seeking a Cyber Security Analyst - Intermediate to support cybersecurity governance and defense. This role requires expertise in RMF/A&A processes and SOC operations, utilizing tools like Microsoft Sentinel for monitoring. Preferred...Remote job
- DecisionPoint Corporation is seeking a Cyber Security Analyst - Intermediate to support cybersecurity governance and operational defense. This role involves RMF/A&A and TRM specialization, alongside frontline SOC support through Microsoft Sentinel monitoring. The applicant...Remote job
- Overview The Government Publishing Office (GPO) SecDevOps program provides advanced security, development, and operations support to safeguard federal information systems... ...operations to ensure continuous security, compliance, and resilience across GPO’s enterprise IT services...Contract workFor contractorsWork at officeLocal areaRemote work
$170k
...the legal and policy frameworks that govern technology and digital ecosystems?... ...and data protection, cybersecurity compliance, digital governance, and risk management, helping them navigate... ...Responsibilities: Conduct regular security assessments, vulnerability testing,...Permanent employment$150k - $180k
A leading data center organization is seeking a Global Security Policy Architect to develop and maintain a unified security policy framework... ...should have at least 12 years of experience in security governance, familiarity with global regulations, and strong documentation...- ...solutions provider is seeking a Global Security Policy Architect to develop and maintain... ...years of experience in enterprise security governance and deep familiarity with global... ...leading reviews and updates based on evolving risks. Competitive compensation and extensive...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer - Governance Risk Compliance. Be the first to apply!
- sr information security engineer Washington DC
- senior application security engineer Washington DC
- associate security engineer Washington DC
- azure security engineer Washington DC
- principal security engineer Washington DC
- security engineering manager Washington DC
- aws cloud security engineer Washington DC
- dlp security engineer Washington DC
- entry level security engineer Washington DC
- sr security engineer Washington DC


