Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Security Engineer - GRC Frameworks & AI Governance

$152k - $258k

SpaceXAI

Job Description

Job Description

SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments.

This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities.

RESPONSIBILITIES:
  • Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking.
  • Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners.
  • Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil.
  • Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery.
  • Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture.
  • Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater.
  • Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces).
  • Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them.
BASIC QUALIFICATIONS:
  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.
  • Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure).
  • Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks.
  • Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring.
  • Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation.
PREFERRED SKILLS AND EXPERIENCE:
  • 10+ years of security compliance, GRC engineering, or technology audit-related experience.
  • Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
  • Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations.
  • Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment.
  • Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company.
  • Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks.
  • Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment.
  • Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch.
  • Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language.
  • Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred.
  • Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus.
COMPENSATION AND BENEFITS:

$152,000 - $258,000 USD

Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

ITAR REQUIREMENTS:
  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Sr. Security Engineer - GRC Frameworks & AI Governance in Washington DC vacancy
  • $152k - $258k

     ...mission is to create AI systems that can...  ...motivated, and focused on engineering excellence. This...  ...seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance...  ...modern security and AI frameworks with GRC engineering... 
    Senior
    Permanent employment
    Temporary work

    SpaceXAI

    Washington DC
    21 days ago
  •  ...Job Summary (Senior Data Security Engineer Microsoft Purview): - Serve as the hands...  ...for data protection, compliance, and AI governance within M365, Azure, endpoints, and multi...  ...knowledge of Zero Trust and broad regulatory frameworks (HIPAA, PCI-DSS, SOX, CCPA).
    Senior

    Expert Technology Services

    Washington DC
    2 days ago
  •  ...Randstad is seeking a Senior Data Security Engineer (Microsoft Purview) to join a...  ..., you will design, deploy, and govern end-to-end data protection, compliance, and AI governance capabilities across...  ...Familiarity with Zero Trust frameworks and broad regulatory frameworks... 
    Senior

    Blue Ribbon Global Technologies

    Washington DC
    2 days ago
  •  ...Description Job Title: Senior Data Security Engineer – Microsoft Purview Location:...  .... You will design, deploy, and govern data protection, compliance, and AI governance controls across...  ...Familiarity with Zero Trust and additional frameworks (HIPAA, PCI-DSS, SOX, CCPA).... 
    Senior
    Contract work

    ZipStaff Inc.

    Washington DC
    2 days ago
  • $166k - $253k

     ...powered by Lattice OS, an AI-powered operating system...  ...ABOUT THE TEAMAnduril's Security Engineering team is looking for a Governance, Risk, and Compliance...  ...engineering core of our GRC program: the pipeline and...  ...acceptance pathsTranslate frameworks (CMMC, NIST 800-171,... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    2 days ago
  •  ...On-site in Washington, DC   As a Sr. Security Engineer (Trellix), you will serve as the technical...  ...aligned to federal cybersecurity frameworks and regulations. Perform analytical...  ...Group utilizes artificial intelligence (AI) tools as part of its initial application... 
    Senior
    Hourly pay
    Permanent employment
    Full time
    Local area

    Eliassen Group

    Washington DC
    27 days ago
  • $115k - $203k

    Sr. Security Engineer Job Description Overview CoStar Group is a leading...  ...experience in Network, SaaS, and AI Security to help evolve and...  ...to include SaaS security governance and AI security risk...  ...abuse patterns, and control frameworks, translating them into actionable... 
    Senior
    Hourly pay
    Full time
    Work at office
    Work from home
    Monday to Thursday

    CoStar Group

    Arlington, VA
    4 days ago
  •  ...cryptographic infrastructure and secure hardware directly...  ...the globe. As a Sr Lead Security Engineer at JPMorganChase...  ...-authorized AI capabilities within the...  ...broader cybersecurity frameworks and their application...  ...corporate, institutional and government clients under the J.P... 
    Senior

    JPMorgan Chase & Co.

    Washington DC
    12 days ago
  • $104.3k - $193.7k

     ...experienced Senior Application Security Engineer to join our team in the...  ...the organization builds and governs secure software. What You...  ...govern the secure use of agentic AI coding tools across...  ...management, and compliance frameworks ~ Proficiency with CI/CD tools... 
    Senior
    Full time
    Immediate start
    Remote work
    Flexible hours

    American Express Global Business Travel

    Washington DC
    3 days ago
  • $140k - $185k

     ...Job Description Senior Information Security Engineer The Senior Information Security Engineer...  ...systems, cloud environments, data, and AI-enabled technologies. This role...  ...solutions. ~ Knowledge of cybersecurity frameworks, regulations, and security best practices... 
    Senior
    Local area

    LHH US

    Washington DC
    15 days ago
  •  ...Consulting - Risk Technology - Sap Grc & Security - Senior ConsultantLocation:...  ...rapid growth across SAP and Governance, Risk, and Compliance (GRC),...  ...alignment with defined risk frameworks Supporting SAP audit...  ...of emerging SAP technologies such as BTP, SAC, AI, or RPA... 
    Senior
    Shift work

    EY

    McLean, VA
    2 days ago
  •  ...- organizational, governance, operational, infrastructure...  ..., and data/AI readiness. Every...  ...and executes security control assessments...  .... Risk Management Framework (RMF) support: Assist...  ...system owners and engineers to validate remediation...  ...(Representative) GRC and assessment... 
    Contract work
    For contractors

    Pitech Solutions, Inc.

    Washington DC
    5 days ago
  • $140k - $170k

     ...Security & Compliance Engineer Join to apply for the Security & Compliance Engineer...  ...(Security) and governance, risk, and compliance (GRC), you’ll be responsible...  ...maintaining compliance frameworks such as CMMC, NIST 800‑...  ...artificial intelligence (AI) tools to support parts... 
    Permanent employment
    H1b
    Visa sponsorship
    Work visa

    Nominal

    Washington DC
    2 days ago
  •  ...Senior Security Engineer Location: Bethesda, MD (Requires Onsite 3–5...  ...with the federal cybersecurity framework (FISMA), and supporting...  ..., SIEM, and bringing in new AI-based tooling to strengthen...  ...&M), and navigating complex governance and compliance requirements.... 
    Senior
    Full time
    Work experience placement
    Work at office
    Shift work
    3 days per week

    August Schell

    Bethesda, MD
    6 days ago
  •  ...Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something...  ..., and threat detection and engineering to strengthen organizational cybersecurity...  ...Azure enterprise-scale frameworks Role-Based Access Control (... 
    Senior
    Flexible hours

    Halvik

    Washington DC
    2 days ago
  • $180k - $220k

     ...Job Description Aircall is a unicorn, AI-powered customer communications platform...  ....   About the Role As a Senior Security Engineer, Detection and Response you will develop...  ..., threat actor behavior, ATT&CK framework. ~ Proven experience building detections... 
    Senior
    Full time
    Worldwide

    Aircall.io, Inc.

    Washington DC
    14 days ago
  • $126k - $188k

     ...applications and services by identifying security risks early, partnering closely with product and engineering teams, and guiding practical...  ...security principles, frameworks, and technologies such as OWASP...  ...submitting a resume for that opening. AI Notice Indeed is committed to... 
    Senior
    Work experience placement
    Local area
    Remote work

    Indeed

    Washington DC
    4 days ago
  • $102.5k - $187.9k

     ...With rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who...  ...in alignment with defined risk frameworks Supporting SAP audit activities...  ...technologies such as BTP, SAC, AI, or RPA What we offer you... 
    Senior
    Summer holiday
    Flexible hours
    Shift work

    EY

    McLean, VA
    2 days ago
  • $95 - $125 per hour

     ...Summary: Our client is seeking a Security Infrastructure Support Senior Security Engineer to join their team! This position...  ...comply with federal cybersecurity frameworks, including FISMA, NIST, and CDM...  ...job, you agree to receive calls, AI-generated calls, text messages, or... 
    Senior
    Local area

    KellyMitchell Group

    Bethesda, MD
    4 days ago
  • Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services...  ...such as API Security, WAF, etc.In-depth knowledge of AI/LLM and machine learning architectures and best practices... 
    Senior
    Temporary work
    Work at office
    Remote work
    Work from home
    Flexible hours

    Aledade

    Washington DC
    2 days ago
  • $170k - $265k

     ..., with the ultimate goal of enabling human life on Mars.SR. AI SECURITY SOFTWARE ENGINEER (STARSHIELD)Starshield leverages SpaceX’s Starlink technology...  ...consumer and commercial use, Starshield is designed for government use, with an initial focus on earth observation,... 
    Senior
    Permanent employment
    Temporary work
    Immediate start
    Flexible hours
    Weekend work

    SpaceX

    Washington DC
    13 hours ago
  •  ...Senior Analyst, Cybersecurity GRC, Washington, DC The Senior...  ...client requests to assess security policies and procedures. The...  ...Party Risk Management (TPRM) and Governance and Risk functions in...  ...Risk Management (ITRM) program framework and associated policies, standards... 
    Senior
    Work experience placement

    NextStep

    Washington DC
    37 minutes ago
  •  ...Purview architecture, governance models, policies, and...  ...Design and implement data security and governance...  ...Microsoft 365 Copilot and AI-enabled workloads....  ...Compliance, and Cloud Engineering teams to translate regulatory...  ...and compliance frameworks such as NIST, ISO 2700... 
    Senior
    Temporary work

    2T Consulting

    Washington DC
    22 days ago
  • $99k - $225k

    Cloud Security Engineer, SeniorThe Opportunity:Define, communicate, and implement cybersecurity...  ...cloud environments against Risk Management Framework (RMF) controls and DoD Security...  ...your identity and prevent fraud.Candidate AI Usage PolicyAI is a part of our daily work... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Alexandria, VA
    2 days ago
  • $99k - $206k

     ...Nightwing is supporting a U.S. Government customer to provide support...  ...Nightwing is seeking a Cloud Security Analyst to support this critical...  ...Knowledge of cloud security frameworks and best practices Experience...  ..., Kubernetes) Knowledge of AI/ML security considerations Experience... 
    Senior
    Contract work
    Local area
    Immediate start

    Nightwing

    Arlington, VA
    3 days ago
  • $138k - $166k

    As a Sr. Security Engineer (Trellix) I, you’ll serve as the technical lead for the organization's endpoint security and data protection ecosystem...  ...security controls aligned with federal cybersecurity frameworks and regulations; strong analytical, troubleshooting, and root... 
    Senior
    Full time
    Local area

    MetroStar Systems

    Washington DC
    4 days ago
  • $140k - $155k

     ...position is located in the Network Engineering and Operations (Networking)...  ...Information Systems/Network Security; Information Technology...  ...secure and maintain Federal Government security clearances as deemed...  ...differentialsCDW is committed to being an AI-fluent organizationWe’re... 
    Senior
    Full time
    Contract work
    Work experience placement
    Work at office
    Local area

    CDW Government

    Washington DC
    1 day ago
  • $113k - $188k

     ...Assess and implement NIST Cybersecurity Framework (CSF) guidelines, standards, and best practices for cyber security and risk management to strengthen an...  ...respond to cyber threats.Understand of Governance Risk and Compliance (GRC) requirements, standards, and guidelines... 
    Senior
    Full time
    Flexible hours

    Guidehouse

    Washington DC
    1 day ago
  • $131.3k - $237.35k

     ...Our team of hackers and engineers have experience...  ...We are looking for a Security Engineer to own the security...  ...and deliver advanced AI-cyber capabilities. You...  ...and release management frameworks. ~ Experience...  ...technology leader serving government and commercial customers... 
    Senior
    Local area
    Immediate start
    Remote work

    Leidos

    Falls Church, VA
    5 days ago
  • $172k - $202.5k

     ...technology innovation — notably the impact of AI and other HR technologies on HR, and the...  ...including (but not limited to) data governance and management across a range of HR use...  ...to effectively apply patterns and frameworks while drawing and defending conclusions... 
    Senior
    Full time
    Remote work
    Worldwide
    Shift work

    Gartner

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Security Engineer - GRC Frameworks & AI Governance. Be the first to apply!