Sr. Security Engineer - GRC Frameworks & AI Governance
$152k - $258kSpaceXAI
Job Description
Job Description
SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
ABOUT THE ROLE:We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments.
This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities.
RESPONSIBILITIES:- Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking.
- Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners.
- Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil.
- Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery.
- Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture.
- Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater.
- Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces).
- Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
- Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them.
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
- 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.
- Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure).
- Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks.
- Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring.
- Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation.
- 10+ years of security compliance, GRC engineering, or technology audit-related experience.
- Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
- Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations.
- Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment.
- Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company.
- Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks.
- Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment.
- Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch.
- Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language.
- Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred.
- Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus.
$152,000 - $258,000 USD
Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.
ITAR REQUIREMENTS:- To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.
SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
- ...Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something... ...a Senior Security Engineer to support a customer's... ...Artificial Intelligence (AI) across their agency's... ...and the Risk Management Framework (RMF).Certifications:...Senior
$166k - $253k
...powered by Lattice OS, an AI-powered operating system... ...ABOUT THE TEAMAnduril's Security Engineering team is looking for a Governance, Risk, and Compliance... ...engineering core of our GRC program: the pipeline and... ...acceptance pathsTranslate frameworks (CMMC, NIST 800-171,...SuggestedFull timeWork experience placementImmediate start$221.2k - $387.1k
...It all started when engineer Fred Luddy wrote code... ...Today, ServiceNow is the AI control tower for business... ...SSO The ServiceNow Security Organization (SSO)... ...anchors the AI Security Governance Program — a board-... ...chain, and AI governance frameworks ~ Strong...SuggestedPermanent employmentFull timeWork at officeImmediate startRemote workFlexible hoursShift work$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity... ...Information System Security Officer (ISSO) to bridge... ...System Security Engineer (ISSE), or Information... ...SPs, Risk Management Framework (RMF), Federal Information... ...prevent fraud.Candidate AI Usage PolicyAI is a...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$90 - $95 per hour
...need for a techno-functional Senior Security Engineer to take the lead on an Optimal ZTA... ...challenges related to cloud security and AI for a federal government client. Responsibilities include,... ...limited to: Develop the security framework and architecture and improve the...SeniorPermanent employmentContract workImmediate start3 days per week- ...On-site in Washington, DC As a Sr. Security Engineer (Trellix), you will serve as the technical... ...aligned to federal cybersecurity frameworks and regulations. Perform analytical... ...Group utilizes artificial intelligence (AI) tools as part of its initial application...SeniorHourly payPermanent employmentFull timeLocal area
- ...— organizational, governance, operational, infrastructure... ..., and data/AI readiness. Every... ...and executes security control assessments... ...Risk Management Framework (RMF) support: Assist... ...system owners and engineers to validate remediation... ...(Representative) GRC and assessment...Contract workFor contractors
$50 - $60 per hour
job summary: Randstad is seeking a Senior Data Security Engineer (Microsoft Purview) to join a high-visibility... ...technical lead role, you will design, deploy, and govern end-to-end data protection, compliance, and AI governance capabilities across M365, Azure, endpoints...SeniorHourly payContract workTemporary workWork experience placement$112k - $209k
...Gates LLP is seeking a Senior Security Engineer to join the firm. The Senior... ...leadership. It utilizes AI-driven tools to improve security... ...intelligence and industry frameworks, including MITRE ATT&CK, to... ..., or local law. This policy governs all aspects of employment including...SeniorFull timeTemporary workWork experience placementLocal areaRemote work- A leading resource firm is looking for a Senior Security Engineer in Bethesda, MD, to implement Zero Trust Architecture... .... Responsibilities include developing security frameworks, ensuring compliance, and researching AI-driven security solutions. This is a 6-month contract...SeniorContract work
- ...Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something... ...analysis, and threat detection and engineering to strengthen organizational... ...Azure enterprise-scale frameworks Role-Based Access Control (...SeniorFlexible hours
$131.3k - $237.35k
...logistics optimization, security operations, and... ...nation secure. Ready to engineer solutions that matter?... ..., implementation, and governance of cloud security solutions... ..., and automation frameworks. Lead threat modeling... ...mapping (e.g., PM, RA, PL, SR families). Develop...SeniorFull time$102.5k - $187.9k
...With rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who... ...in alignment with defined risk frameworks Supporting SAP audit activities... ...technologies such as BTP, SAC, AI, or RPA What we offer you...SeniorSummer holidayFlexible hoursShift work- ...Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something... ...a Mid-Level Security Engineer to support a customer's... ...Artificial Intelligence (AI) across the agency's... ...and the Risk Management Framework (RMF).Certifications:...Contract work
$244k - $390k
..., making transactions secure, simple, smart and accessible... ..., businesses and governments realize their greatest... ...Information Security Engineering Overview The... ...machine, and emerging AI-based identities. This... ...enforcing governance frameworks, operational standards...Full timePart timeLocal areaWorldwideFlexible hours- ...strategy and architectural direction across Security Engineering domains. Build security foundations for emerging AI technologies, agentic use cases, internal automation... ..., LLM integrations, or agentic automation frameworks. Benefits Performance-driven...SeniorWork at officeFlexible hours
$102.5k - $187.9k
...With rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who... ...in alignment with defined risk frameworks Supporting SAP audit activities... ...technologies such as BTP, SAC, AI, or RPA What we offer you...SeniorSummer holidayFlexible hoursShift work$99k - $225k
...Enterprise Cybersecurity Security ArchitectThe... ...Cybersecurity (ECS) Governance, Risk and Compliance (GRC) plays a pivotal role... ...architecture and engineering execution. You will... ...), Risk Management Framework (RMF), DevSecOps principles... ...fraud.Candidate AI Usage PolicyAI is a...Full timeContract workPart timeWork at officeLocal areaRemote work$140k - $170k
Security & Compliance Engineer Join to apply for the Security & Compliance Engineer... ...(Security) and governance, risk, and compliance (GRC), you’ll be responsible... ...maintaining compliance frameworks such as CMMC, NIST 800‑... ...artificial intelligence (AI) tools to support parts...Permanent employmentH1bVisa sponsorshipWork visa- ...the first 25 applicants Get AI-powered advice on this job and... ...optimal system performance and security. As an Endpoint Security... ...to bring heightened focus and governance to our data protection policies... ...Safety, Security & Privacy, Engineering, User & Product Ops, Corporate...Full timeTemporary workRemote work
- RIVA Solutions is seeking a Senior Data Security Solution Architect to lead architecture across AI governance, data security, cloud security, and FedRAMP-enabled technologies for a USPTO task order. The role requires analyzing and integrating security technologies, leading...Senior
- RIVA Solutions is seeking a Senior Data Security Solution Architect to support a USPTO task order focused on securing the agency's evolving AI and data environment. You will lead solution architecture across AI governance, data security, cloud security, and FedRAMP-enabled...Senior
$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global... ...work, we provide opportunities for our engineers to pursue projects they are passionate... ...code for security issues, building a new framework to help our software developers build...SeniorInternshipFlexible hours- Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services... ...such as API Security, WAF, etc.In-depth knowledge of AI/LLM and machine learning architectures and best practices...SeniorTemporary workWork at officeRemote workWork from homeFlexible hours
- ...teams support the federal government’s most critical national security and defense priorities,... ...Web Developer Security Engineer to join our team. This... ...with federal cybersecurity frameworks including NIST SP 800-53,... ...Experience leveraging AI-assisted development tools...Full timeLocal areaRemote workFlexible hours
- ...Senior Security Engineer (Security Operations)Sword Health is shifting healthcare... ...from human-first to AI-first through its AI Care platform... ...-driven, scalable triage framework, aligned with business... ...required to obtain and maintain a government security clearance.US -...SeniorFull timeRemote workFlexible hoursShift work
$320k - $405k
...Security Engineer, Corporate Security San Francisco, CA | Seattle, WA... ...interpretable, and steerable AI systems. We want AI to be safe... ...Lead SaaS and identity governance, including third-party OAuth... ...extensions and endpoint security frameworks, or their platform...Visa sponsorshipFlexible hours$99k - $225k
Cloud Security Engineer, SeniorThe Opportunity:Define, communicate, and implement cybersecurity... ...cloud environments against Risk Management Framework (RMF) controls and DoD Security... ...your identity and prevent fraud.Candidate AI Usage PolicyAI is a part of our daily work...SeniorFull timeContract workPart timeWork at officeLocal areaRemote work$138k - $166k
As a Sr. Endpoint Security Engineer (Trellix) I, you’ll serve as the technical lead for the organization's endpoint security and data protection... ...implementing security controls aligned with federal cybersecurity frameworks and regulations; strong analytical, troubleshooting, and...SeniorFull timeLocal area- ...Job Description Job Description Dexian Government Solutions is recruiting for a Senior Security Risk Management Engineer to support our proposal effort for the DHS CIETS... ...senior technical lead for Risk Management Framework (RMF) implementation, Assessment &...SeniorContract workTemporary workLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Security Engineer - GRC Frameworks & AI Governance. Be the first to apply!
- security infrastructure engineer Washington DC
- information system security engineer Washington DC
- sr information security engineer Washington DC
- senior cloud security engineer Washington DC
- security engineer Washington DC
- senior security operations engineer Washington DC
- information technology security engineer Washington DC
- application security engineer Washington DC
- offensive security engineer Washington DC
- network security engineer Washington DC



