Senior Compliance Engineer, AI Governance
True Anomaly
Senior Compliance Engineer, AI Governance
True Anomaly seeks those with the talent and ambition to build the technology that secures space. True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.
Your Mission
We are seeking a rare combination of disciplines: an experienced Sr. Compliance Engineer with deep AI Subject Matter Expertise (SME) and export compliance background to join our Governance, Risk, and Compliance (GRC) team. This role is responsible for building, implementing, and sustaining the organizational compliance posture across key regulatory and security frameworks — with a primary emphasis on RMF (NIST 800-53 Rev. 5 + Classified Overlays), CMMC Level 3, NIST 800-171 Rev. 3, EAR/ITAR cyber regulations, and — critically - the governance, risk management, and compliance controls surrounding AI/ML systems and large language models (LLMs) deployed across the enterprise.
As AI becomes embedded in True Anomaly's operations, mission systems, and products, this role serves as the organizational authority on how AI capabilities are adopted, audited, and controlled responsibly. You will architect and operationalize compliance checkpoints and governance gates within LLM pipelines, evaluate AI vendors and platforms (including OpenAI, Anthropic Claude, and others) against classified and unclassified compliance requirements, and ensure AI-driven workflows satisfy both regulatory obligations and internal risk tolerance.
The ideal candidate brings deep GRC knowledge, hands-on AI/LLM engineering fluency, and the ability to engage credibly with compliance assessors, government partners, and internal AI/ML engineering teams alike.
Responsibilities
Compliance Program Execution
- Lead and support compliance assessment readiness across key organizational frameworks including NIST SP 800-171 Rev. 2 and 3, CMMC Level 3, NIST SP 800-53 Rev. 5, and the NIST Cybersecurity Framework (CSF).
- Provide direction on cybersecurity readiness to address EAR and ITAR-related controls and requirements.
- Drive CMMC readiness activities across the organization, including scoping, gap analysis, control implementation validation, evidence collection, and pre-assessment preparation.
- Review, maintain, and mature System Security Plans (SSPs) to accurately reflect organizational control implementations, system boundaries, and operational practices — including AI/ML system boundaries and data flows.
- Manage Plans of Actions and Milestones (POA&Ms), tracking open findings to resolution, communicating status to GRC leadership, and coordinating remediation efforts across responsible teams.
- Conduct internal compliance audits and control effectiveness reviews to ensure ongoing adherence to applicable frameworks and to surface emerging gaps before external assessments.
- Maintain audit-ready evidence repositories and documentation packages, ensuring traceability between controls, evidence, and framework requirements.
AI Governance, Risk & Compliance (AI-GRC)
- Serve as the organizational AI compliance SME — the primary authority on how AI/LLM systems (including OpenAI GPT models, Anthropic Claude, open-source models, and internally developed models) are evaluated, onboarded, and continuously governed within True Anomaly's compliance boundaries.
- Design, implement, and maintain compliance checkpoints and enforcement gates within LLM pipelines, including:
- Input/output filtering and content policy enforcement layers
- Prompt injection detection and mitigation controls
- Data classification guardrails to prevent CUI, ITAR-controlled, or classified data from flowing into non-authorized AI systems or endpoints
- Automated audit logging of AI interactions for traceability and incident investigation
- Model access control and role-based permissions within AI platforms
- Conduct AI-specific risk assessments, including evaluation of AI vendor data handling practices, model training data provenance, and third-party AI API security postures against NIST AI RMF, NIST SP 800-53 AI overlays, and internal standards.
- Develop and enforce an AI System Acceptable Use Policy and supporting standards that govern how employees and systems interact with LLMs, including permissible data inputs, output handling, human-in-the-loop requirements, and escalation procedures.
- Evaluate proposed AI/ML use cases for regulatory risk (EAR/ITAR, CMMC, data privacy) and provide compliance go/no-go determinations with documented rationale.
- Collaborate with AI/ML engineers and DevSecOps teams to integrate compliance gates into CI/CD pipelines and MLOps workflows, ensuring model changes and prompt changes undergo review before production deployment.
- Maintain an AI system inventory, tracking all deployed models, APIs, integrations, and associated risk and compliance status.
- Monitor emerging AI regulatory developments (e.g., EO 14110, NIST AI RMF, DoD AI Ethics Principles, EU AI Act implications for U.S. defense partners) and assess organizational impact.
Cross-Functional Compliance Enablement
- Serve as a primary GRC team resource for compliance questions, control guidance, and framework interpretation across engineering, IT, operations, legal, and security teams.
- Partner with IT and security operations teams to verify that technical controls — including access management, logging, configuration baselines, and incident response procedures — meet CMMC and NIST requirements at an organizational level.
- Partner with AI/ML engineers, data scientists, and product teams to embed compliance thinking into AI system design, model selection, and deployment architecture.
- Collaborate with the Enterprise Risk Manager and broader GRC leadership to ensure compliance findings — including AI-specific risks — are reflected in the enterprise risk register and remediation priorities.
- Support the development of compliance training and awareness materials, including AI-specific training that builds organizational understanding of responsible AI use, LLM risk, and CMMC obligations.
- Coordinate with external assessors, third-party auditors, and government partners during assessment engagements, serving as a knowledgeable point of contact for evidence walkthroughs and control discussions.
Qualifications
- 7+ years of experience in IT security compliance, GRC, or a closely related discipline, with direct ownership of compliance program activities.
- Demonstrated expertise in NIST SP 800-171, CMMC (Level 2 or 3), and NIST SP 800-53, with hands-on experience conducting gap assessments, implementing controls, and preparing organizations for external audits.
- Extensive, hands-on experience with AI/LLM systems, including practical knowledge of platforms such as OpenAI (GPT-4/o-series), Anthropic Claude, Meta Llama, Microsoft Azure OpenAI Service, and/or comparable commercial and open-source LLM ecosystems.
- Demonstrated ability to design, implement, and operationalize compliance controls within LLM pipelines, including guardrail layers, content filtering, audit logging hooks, and data classification enforcement.
- Working knowledge of AI security risks, including prompt injection, jailbreaking, data exfiltration via LLM outputs, model inversion, and supply chain risks associated with third-party AI APIs.
- Familiarity with NIST AI Risk Management Framework (AI RMF) and its application to enterprise and defense AI deployments.
- Strong understanding of SSP development and maintenance, POA&M management, and audit evidence lifecycle practices in an organizational (non-product) compliance context.
- Proven experience developing and operationalizing information security policies, standards, and procedures across a multi-disciplinary organization.
- Strong communication skills with the ability to explain compliance requirements — including AI risk concepts — clearly to both technical practitioners and non-technical business stakeholders.
- Highly organized, with demonstrated ability to manage multiple concurrent compliance workstreams and deadlines in a fast-paced environment.
- Active or ability to obtain SECRET or TS/SCI security clearance.
- Must be a U.S. citizen, lawful permanent resident, or protected individual per ITAR requirements (8 U.S.C. 1324b(a)(3)).
Preferred Qualifications
- Strong EAR/ITAR background as it pertains to cybersecurity, AI-generated outputs, and policy development.
- J.D. focusing on technology law, export compliance (EAR and ITAR), AI regulation, or cyber law.
- Experience building MLOps or AI DevSecOps pipelines with integrated compliance gates, including automated policy enforcement, prompt review workflows, or model change management processes.
- Hands-on experience with AI safety
- Cloudflare seeks a Senior Principal, Sales Compensation Design & Strategy to shape and govern global sales compensation programs across Sales, Technical Sales, Partner Sales... ...and COO to align incentives with the company’s AI-first strategy and GTM priorities. You will...Senior
- ...in real-time compensation data, seeks a Corporate Security Engineer to own identity, access, endpoint protection, and SaaS security... ...SOC 2 Type II and ISO 27001 controls while automating governance with AI-driven tooling. You’ll collaborate with IT/helpdesk and security...Senior
- Trulioo Information Services Inc. is seeking a Senior Director of Corporate Strategy & Development to shape the company’s strategic direction... ...priorities. You will own evolving strategic blueprint, drive governance, and lead major strategic initiatives across risk, product, and...Senior
- .... You will drive alignment across Product, Engineering, Data Science, Design and Go‑to‑Market teams... ...metrics forward. You will champion AI‑driven workflow improvements, establish governance, and report outcomes to senior leaders. A strong background in program management...Senior
- ...is seeking an experienced Information Technology Governance Manager to advance governance frameworks for AI/ML systems. The role involves developing audit processes... ..., and collaborating with various teams to ensure compliance with data protection laws. Candidates should have...Senior
- OneTrust in San Francisco, CA is seeking a Staff Product Specialist to lead AI Governance initiatives within the Design Partner Program. You will partner with AI leaders, privacy, legal, and engineering to transform insights into product strategy and roadmap investments for...Senior
- ...Associate General Counsel in San Francisco to lead the Privacy & Security team. This role requires advising on privacy laws, managing compliance programs, and developing training while working cross-functionally with various departments. The successful candidate will have a...Senior
- Sierra is hiring a Senior Privacy Counsel to be a core member of... ...privacy programs, and develop AI governance frameworks to ensure responsible... ...contributing to strategic compliance initiatives. You will collaborate with product, engineering, operations, and GTM teams, mentoring...Senior
- Perplexity is seeking a governance, risk, and compliance analyst to shape and lead our program. You will drive... ...focused on trustworthy search and AI‑assisted experiences. The role emphasizes... ...across IT, Security, GTM, and Engineering in a data‑driven environment. #J-188...Senior
- ...seasoned Product Marketing leader to own AI Governance marketing, including Unity AI Gateway.... ...global markets. Reporting to the Senior Director of Product Marketing, you’ll collaborate with product, marketing and engineering to launch governed AI products, drive adoption...Senior
- Alterion in San Francisco seeks a Senior Product Manager to lead the development of security and governance products for AI agents. You will be responsible for translating user needs into actionable product features and engaging with enterprise leaders to structure pilot...Senior
- Abby Care in San Francisco is seeking a Senior Privacy & AI Counsel to lead their privacy and AI governance programs. This role is vital as the company navigates the evolving regulatory environment and enhances its AI initiatives. The ideal candidate will have at least...SeniorFull time
- ...Space LLC is seeking an Identity Engineer to design and implement core... ..., authorization, and governance across enterprise environments... ...provides exposure to leading AI and distributed systems in a... ...a strong emphasis on policy compliance and security standards. Strong...Senior
$162.5k - $220k
....Job OverviewWe are seeking a Senior Data Scientist to help build and... ...insights and segmentation engine — turning day-to-day member behavior... ..., definition, and governance; holistic business-management... ...modelingExperience leveraging AI tools (e.g., Claude, ChatGPT)...SeniorSeasonal workWorldwide- ...a Manager to lead client engagements focused on data-driven and AI-enabled strategies for large enterprises. You will collaborate with... ...efficiency, and measurable impact through advanced analytics, governance, and technology transformation initiatives. In this role you...SeniorRemote job
- Scale AI in San Francisco is seeking an experienced engineer to design and implement identity infrastructure for secure authentication and authorization across... ...identity solutions, and help scale identity governance in a fast-growing AI platform. Ideal candidates have...Senior
- Arena Intelligence is seeking a senior privacy and product counsel to embed with our product and engineering teams. You will drive privacy governance, advise on regulatory developments, and shape data usage across our AI evaluation platform. With 8+ years in privacy law...Senior
- Gusto is seeking a Security, Governance, Risk & Compliance professional to advance governance, risk, and compliance initiatives across... ...practices. The role collaborates with Legal, IT, Engineering, and Sales, leveraging AI to automate controls and evidence collection, and...Senior
- Autodesk in San Francisco is seeking a Senior Manager, Learning Technology & Innovation to lead... ...learning technology ecosystem and advance AI-enabled learning across the enterprise. You will define strategy, roadmaps, governance, and partnerships with Talent Development,...Senior
- ...a leading tech company, seeks a Senior Privacy Counsel to join our San... ...team. You will advise product, engineering, operations, and marketing on GDPR, CCPA, and AI-related regulations while shaping privacy policy and program governance. You will draft and negotiate DPAs...Senior
$120k - $175k
Senior Legal Process EngineerCooley is seeking a Senior Legal Process Engineer to join the Practice Engineering team.Position summary: As... ...leverages document automation, AI, and data integrations.This... ...standards, best practices, and governance in the development, delivery,...SeniorFull timeTemporary workWork at officeFlexible hoursShift workWeekend work- Future Matters is seeking a Senior Strategist to coordinate the US AI governance field and align diverse groups around joint strategies and foresight. The role focuses on building and leading US coordination initiatives, cultivating stakeholder relationships, and driving...SeniorPermanent employmentFull timeRemote work
- Asana is seeking a Product Manager to join our AI team in San Francisco, driving AI-powered product strategy end-to-end across infrastructure, governance, and user experiences. This role sits in the Product Management team, delivering cross-functional impact to help customers...SeniorWork at officeRemote work
- ...the San Francisco Bay Area seeks a Senior Consultant, Data Governance to lead enterprise platform initiatives... ...strong collaboration with risk, compliance, and business teams. You will guide... ...and lifecycle controls, while driving AI-enabled governance and #J-18808-Ljbffr...Senior
- Mercury is seeking a Senior Model Risk Manager - AI/ML to define and enhance model governance for AI/ML. This role involves owning the validation and governance... ...will work closely with data scientists, engineers, and compliance teams to set standards for rigorous model...Senior
- Salesforce is seeking a Product Manager / Senior Product Manager for Tableau Next to shape the future of Analytics. You will define the vision and strategy for the product, partnering with engineers, designers, and product teams to deliver an intelligent analytics experience...Senior
- CTGT, Inc., a $7M Seed-funded AI safety startup backed by Gradient Ventures, YC, and General Catalyst, is seeking a Senior Software Engineer in San Francisco. You will own the architectural evolution of a high-performance governance platform, designing core services and...Senior
- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program... ...in audit/compliance, automation using AI, and collaboration across IT, Security, GTM, and Engineering. You will help drive customer trust by staying...Senior
$225k - $290k
...data quality, contracts, and governance; designing scalable reliability... ...the data landscape. As a senior technical leader, you will also... ...investments, define best-in-class data engineering practices, and lead complex,... ...leveraging AI tools and methodologies to design...SeniorFlexible hours$137k - $188k
...several IP-centric businesses, and leads government relations. Based out of our... ..., and reporting to the Forensic Engineering Manager, the Senior Compliance Engineer is a key member of the technical... ..., and gather intelligence. Use AI‑assisted tools to support product...SeniorFull timeWork at officeLocal areaRemote workWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Compliance Engineer, AI Governance. Be the first to apply!
- senior network engineer remote San Francisco, CA
- senior app developer San Francisco, CA
- senior manager legal San Francisco, CA
- senior retail sales associate San Francisco, CA
- sr project manager San Francisco, CA
- senior account executive San Francisco, CA
- senior manager strategic initiatives San Francisco, CA
- senior staff systems engineer San Francisco, CA
- senior commercial counsel San Francisco, CA
- senior data manager San Francisco, CA

