Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Security Engineer - GRC Frameworks & AI Governance

$152k - $258k

SpaceXAI

Job Description

Job Description

SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments.

This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities.

RESPONSIBILITIES:
  • Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking.
  • Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners.
  • Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil.
  • Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery.
  • Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture.
  • Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater.
  • Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces).
  • Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them.
BASIC QUALIFICATIONS:
  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.
  • Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure).
  • Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks.
  • Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring.
  • Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation.
PREFERRED SKILLS AND EXPERIENCE:
  • 10+ years of security compliance, GRC engineering, or technology audit-related experience.
  • Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
  • Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations.
  • Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment.
  • Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company.
  • Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks.
  • Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment.
  • Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch.
  • Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language.
  • Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred.
  • Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus.
COMPENSATION AND BENEFITS:

$152,000 - $258,000 USD

Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

ITAR REQUIREMENTS:
  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

Vacancy posted 13 days ago
Similar jobs that could be interesting for youBased on the Sr. Security Engineer - GRC Frameworks & AI Governance in Washington DC vacancy
  •  ...Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something...  ...a Senior Security Engineer to support a customer's...  ...Artificial Intelligence (AI) across their agency's...  ...and the Risk Management Framework (RMF).Certifications:... 
    Senior

    Halvik

    Alexandria, VA
    15 days ago
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance AnalystThe Opportunity...  ...Information System Security Officer (ISSO) to bridge...  ...System Security Engineer (ISSE), or Information...  ...SPs, Risk Management Framework (RMF), Federal Information...  ...prevent fraud.Candidate AI Usage PolicyAI is a... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  •  ...Services contracts to support cybersecurity governance and compliance across critical networks...  ...policies, internal controls, and security procedures. The successful candidate will...  ...with cyber adversary tactics and frameworks (such as ATT&CK and D3FEND) Knowledge of... 
    Senior
    Work at office

    ASRC Federal Holding Company

    Alexandria, VA
    1 day ago
  • $112k - $209k

     ...Gates LLP is seeking a Senior Security Engineer to join the firm. The Senior...  ...leadership. It utilizes AI-driven tools to improve security...  ...intelligence and industry frameworks, including MITRE ATT&CK, to...  ..., or local law. This policy governs all aspects of employment including... 
    Senior
    Full time
    Temporary work
    Work experience placement
    Local area
    Remote work

    K&L Gates

    Washington DC
    3 days ago
  • $90 - $95 per hour

     ...need for a techno-functional Senior Security Engineer to take the lead on an Optimal ZTA...  ...challenges related to cloud security and AI for a federal government client. Responsibilities include,...  ...limited to: Develop the security framework and architecture and improve the... 
    Senior
    Permanent employment
    Contract work
    Immediate start
    3 days per week

    Peyton Resource Group

    Bethesda, MD
    3 days ago
  • $145k - $192.5k

     ...America’s Global Information Security (GIS) team is seeking a Cyber Threat Defense AI Security Senior Engineer to drive the integration of...  ..., including model governance, bias mitigation, and explainability...  ...architectures, and MLOps frameworks.Demonstrated ability to drive... 
    Senior
    Full time
    Work at office
    Shift work
    Day shift

    Bank of America

    Washington DC
    4 days ago
  • $126k - $212k

     ...experienced Information Systems Security Engineer (ISSE) - Sr to support a mission-...  ...in Risk Management Framework (RMF) implementation, security...  ...developers, engineers, ISSOs, and government stakeholders to ensure...  ..., Risk, and Compliance (GRC) platforms and security automation... 
    Senior
    Contract work
    Work experience placement
    H1b

    SMX

    Washington DC
    8 hours ago
  • $131.3k - $237.35k

     ...logistics optimization, security operations, and...  ...nation secure. ​Ready to engineer solutions that matter?...  ..., implementation, and governance of cloud security solutions...  ..., and automation frameworks. ​Lead threat modeling...  ...mapping (e.g., PM, RA, PL, SR families). ​Develop... 
    Senior
    Full time

    Leidos

    Alexandria, VA
    1 day ago
  • $140k - $170k

     ...Security & Compliance Engineer Join to apply for the Security & Compliance Engineer...  ...(Security) and governance, risk, and compliance (GRC), you’ll be responsible...  ...maintaining compliance frameworks such as CMMC, NIST 800‑...  ...artificial intelligence (AI) tools to support parts... 
    Permanent employment
    H1b
    Visa sponsorship
    Work visa

    Nominal

    Washington DC
    5 days ago
  • $140k - $173.29k

     ...Senior Information Systems Security Engineer to support cybersecurity, compliance...  ...posture, compliance framework, and risk management initiatives...  ...and strengthens security governance for enterprise workspace...  ...cloud environments, including AI integration and low-code desktop... 
    Senior
    Currently hiring

    Govcio LLC

    Alexandria, VA
    4 days ago
  • $95 - $125 per hour

     ...Summary: Our client is seeking a Security Infrastructure Support Senior Security Engineer to join their team! This position...  ...with federal cybersecurity frameworks, including FISMA, NIST, and CDM standards...  ...job, you agree to receive calls, AI-generated calls, text messages,... 
    Senior
    Local area

    KellyMitchell Group

    Bethesda, MD
    1 day ago
  • $152k - $258k

     ...Sr. Security Engineer - GRC Fintech & Financial Services New York, New York, United...  ...’s mission is to create AI systems that can accurately...  ...are seeking an experienced Governance, Risk, and Compliance (GRC)...  ...), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering... 
    Permanent employment
    Temporary work

    SpaceXAI

    Washington DC
    1 day ago
  • $99k - $225k

     ...Enterprise Cybersecurity Security ArchitectThe...  ...Cybersecurity (ECS) Governance, Risk and Compliance (GRC) plays a pivotal role...  ...architecture and engineering execution. You will...  ...), Risk Management Framework (RMF), DevSecOps principles...  ...fraud.Candidate AI Usage PolicyAI is a... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $178.4k - $226.7k

    Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global...  ...work, we provide opportunities for our engineers to pursue projects they are passionate...  ...code for security issues, building a new framework to help our software developers build... 
    Senior
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    2 days ago
  •  ...Senior Analyst, Cybersecurity GRC, Washington, DC The Senior...  ...client requests to assess security policies and procedures. The...  ...Party Risk Management (TPRM) and Governance and Risk functions in...  ...Risk Management (ITRM) program framework and associated policies, standards... 
    Senior
    Work experience placement

    NextStep

    Washington DC
    3 days ago
  • $104k - $156k

     ...Remote/Hybrid Job Overview The Advanced Security Engineer is a technically deep, hands-on...  ...deployment, implementation and optimization of AI-enabled security technologies at all...  ...controls are aligned to industry recognized frameworks. Validate that telemetry from each... 
    Remote work

    Relativity

    Washington DC
    1 day ago
  • $113k - $188k

     ...Assess and implement NIST Cybersecurity Framework (CSF) guidelines, standards, and best practices for cyber security and risk management to strengthen an...  ...respond to cyber threats.Understand of Governance Risk and Compliance (GRC) requirements, standards, and guidelines... 
    Senior
    Full time
    Flexible hours

    Guidehouse

    Washington DC
    4 days ago
  • $100k - $120k

     ...a waiting period. Job Summary The Cybersecurity Analyst (Security & AI Governance) is responsible for protecting the organization's information...  ..., regulatory requirements, and emerging AI governance frameworks. This position will work closely with the CIO and CISO functions... 
    Temporary work

    C.C.D. Cogent Communications Deutschland GmbH

    Washington DC
    2 days ago
  • $147.3k - $193.3k

     ...this team The Data & AI Security team is responsible for...  ...with Data & Analytics, Engineering, Legal, Privacy, and GRC teams to embed security...  ...partners closely with Data Governance, Platform Engineering, and...  ...security development frameworks Demonstrated ability... 
    Senior
    Permanent employment
    Part time
    Work at office
    Work visa

    lululemon

    Washington DC
    24 days ago
  •  ...Job DescriptionSr. Cyber Security Analyst Locations:...  ...the RoleWe are seeking a Sr. Cybersecurity Analyst...  ...security standards and frameworks.Investigate security incidents...  ....Adopt and extend AI-assisted security tooling...  ....Collaborate with engineering teams to embed security... 
    Senior
    Ongoing contract
    Full time
    Temporary work
    Work at office
    Remote work

    SS&C Technologies

    Washington DC
    2 days ago
  • $138k - $166k

    As a Sr. Endpoint Security Engineer (Trellix) I, you’ll serve as the technical lead for the organization's endpoint security and data protection...  ...implementing security controls aligned with federal cybersecurity frameworks and regulations; strong analytical, troubleshooting, and... 
    Senior
    Full time
    Local area

    MetroStar Systems

    Washington DC
    3 days ago
  •  ...Manager, the Web Developer Embeds security across the SDLC for mission-...  ...~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl...  ..., REST APIs, SQL; ~ AI-assisted dev tools (Copilot,...  ...Preferred: Federal framework authorization (NIST 800-53/FISMA... 
    Full time

    Base Camp Consulting

    Washington DC
    12 hours ago
  •  ...teams support the federal government’s most critical national security and defense priorities,...  ...Web Developer Security Engineer to join our team. This...  ...with federal cybersecurity frameworks including NIST SP 800-53,...  ...Experience leveraging AI-assisted development tools... 
    Full time
    Local area
    Remote work
    Flexible hours

    Ardentmc

    Washington DC
    12 hours ago
  • $72k - $184.44k

     ...As a Senior Associate on the AI Governance team within the Digital...  ...on developing AI governance frameworks that align with industry standards...  ..., Cybersecurity, Economics, Engineering, Finance, Mathematics/...  ...thoughtfully to establish a secure and trusted workplace for all... 
    Senior
    H1b

    PwC

    Washington DC
    5 days ago
  • $72k - $184.44k

     ...As a Senior Associate on the AI Governance team within the Digital...  ...be developing AI governance frameworks that align with industry standards...  ..., Cybersecurity, Economics, Engineering, Finance, Mathematics/...  ...thoughtfully to establish a secure and trusted workplace for all... 
    Senior
    H1b

    PricewaterhouseCoopers

    Washington DC
    2 days ago
  • $220k - $350k

     ...enabling human life on Mars.SR. AI ENGINEER, SPECIAL PROGRAMS - TOP SECRET...  ..., infrastructure, and legal/governance teams to deliver high-stakes...  ...and develop evaluation frameworks to assess performance and address...  ...-tuning, with an eye toward secure and scalable deployment.... 
    Senior
    Permanent employment
    Temporary work
    For contractors
    Shift work
    Weekend work

    SpaceX

    Washington DC
    3 days ago
  •  ...helping them harness AI to drive outcomes at a...  ...Solutions, DXC modernises, secures, and operates some of...  ...the Security Engineering Team who work within the...  ...and Australian Federal Government Security Clearance at...  ...considered within the framework of the DXC Accommodation... 
    Full time
    Local area

    DXC Technology

    Washington DC
    2 days ago
  • $99k - $225k

    Cyber Machine Learning Engineer, SeniorThe Opportunity: Are you interested...  ...of compromises within security logs, including endpoint and...  ...investigationsExperience with MITRE ATT&CK framework, MISP threat sharing, or...  ...and prevent fraud.Candidate AI Usage PolicyAI is a part of... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    3 days ago
  • $72k - $184.44k

     ...As a Senior Associate on the AI Governance team within the Digital...  ...on developing AI governance frameworks that align with industry standards...  ..., Cybersecurity, Economics, Engineering, Finance, Mathematics/...  ...thoughtfully to establish a secure and trusted workplace for all... 
    Senior
    H1b

    PwC

    Washington DC
    1 day ago
  • $120k - $180k

     ...to join our talented Team.Job Title: AI Cyber Engineer (Enterprise Security & Autonomous Remediation) Job...  ...leverage advanced AI models, agentic frameworks, and security tooling to:Continuously...  ...engineering teamsSecurity operations and GRC teamsTranslate security findings... 
    Shift work

    Ampcus

    Washington DC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Security Engineer - GRC Frameworks & AI Governance. Be the first to apply!