GRC Lead: AI Compliance & Security Architect
BrainCo
About Brain Co. Brain Co. is an applied AI startup co-founded by Jared Kushner and Elad Gil, and backed by leading Silicon Valley builders including Patrick Collison and Andrej Karpathy. We are building AI applications for the world's most important institutions, delivering impact on real-world problems across governments, healthcare systems, and critical industries. Our progress so far: Automated construction permitting for a sovereign government 80% faster, unlocking $375M+ in value Optimized supply chains for a leading global energy company 30% lower cost, 99% reliability, preventing $100M+ in losses Streamlined hospital patient care across national health systems 40% better outcomes, 80% less admin work Company momentum: Raised a $55M Series A from leading investors Built a team of 70+ AI experts from Tesla, Google DeepMind, NVIDIA, and Databricks About the Role: At Brain Co., we focus on applying frontier AI to real institutional challenges, working alongside governments, healthcare systems, and critical industries to modernize how essential services operate. We are looking for leaders who want to help bring new technology into institutions that impact millions of people. As our GRC Lead, you’ll own the governance, risk, and compliance program end-to-end - and treat it as a strategic advantage, not a checklist. Brain Co. carries one of the most demanding regulatory loads of any company our size: SOC 2 Type II and HIPAA in place today, with ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and US/MENA data residency on the near-term roadmap. That’s what selling to governments, hospitals, and financial institutions costs - and done right, it’s how we win the next ones. This is a 01 builder role. You’ll define the principles, write the policies, run the audits, build the automation, and partner directly with engineering, legal, sales, and customer – not advising from the sidelines. This is a high-ownership role for someone who has built programs like this before and wants to build the next one from first principles. You’ll be an IC on day one with the scope and trust to grow the function as the company scales. What You'll Work On: Own the end-to-end GRC program: SOC 2 Type II and HIPAA today, and the path through ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and MENA-specific regimes that don’t map cleanly to a US playbook. Build the data handling backbone: how customer data is classified, where it lives, who can touch it, and how we prove it - across Azure, on-prem MENA deployments, and the bespoke deployments we run for governments and hospitals. Run audits as a builder, not a project manager: Own evidence, controls, gap remediation, and audit response, and automate the evidence pipeline so we’re not rebuilding workpapers every cycle. Stand up third-party risk as a real program: vendor reviews, data flow inventory, contractual security obligations, and a reassessment cadence that keeps pace with our SaaS footprint. Be the function that unblocks enterprise deals: Build the customer-trust surface — security questionnaires, trust portal, DPAs, BAAs, customer-facing docs — so customers understand how we handle their data before they have to ask. Partner with engineering: Bake compliance into the product: control inheritance from Azure, policy-as-code, automated access reviews, audit-ready logging, and evidence collection that runs without a human in the loop. Run a single risk operating cadence across HR, Finance, Legal, IT, and Engineering: so data handling, vendor approvals, and audit requests always have a clear owner. Be the translator between technical reality and regulatory expectations: the person engineers trust to interpret a control, and the person customers and auditors trust to explain the system behind it. You Might Be a Great Fit If You... Have 8+ years building and running GRC programs in regulated environments including healthcare, financial services, government, or enterprise SaaS where the stakes were real and the audits weren’t theatre. Have taken a company through SOC 2 Type II from a cold start, and lived HIPAA, GLBA, FedRAMP, or equivalent work hands-on, not just signed off on policies someone else wrote. View compliance as a competitive advantage and a forcing function for good engineering, not a checklist and not a bureaucracy to defend. Are a deep executor: you write the policies, draft the white papers, and ship the automation yourself, and can zoom out to design the program around them. Are a high-trust cross-functional partner - you can sit with an engineer reasoning about IAM controls in the morning, walk GTM through a DPA at noon, and brief a customer’s CISO in the afternoon. Translate technical risk for the boardroom and regulatory risk for the engineers fluently in both directions. Are at home in ambiguity and energized by a 01 program. We have a SOC 2 Type II baseline; the rest is yours to define. Have a strong opinion about data: how it’s classified, where it lives, who can see it, and how you prove it. You think in data flows, not policy templates. Bias toward pragmatism over bureaucracy. You know which controls matter, which ones are noise, and which ones you can automate out of existence. Bonus Points For: Direct experience operating across US and MENA (or other multi-jurisdictional) regulatory environments, including on-prem and data residency requirements. FedRAMP/GovRAMP, IL4/IL5, or equivalent government-customer compliance experience. Standing up GRC programs at AI or ML-heavy companies, including the novel evidence and disclosure questions that come with model training data, agent actions, and customer data flowing through AI systems. Hands-on with compliance automation tooling (Vanta, Drata, Secureframe, etc.) and a willingness to replace it when it’s the wrong tool. Comfort reading the technical controls themselves (Terraform, IAM policies, audit logs) well enough to verify what an auditor is being told. Why Join Us: Build the GRC function for an AI platform deployed in governments, hospitals, and critical industries worldwide — where the regulatory bar is real and the work matters. Own the program 01. Define the principles, design the system, and grow the function under you as the company scales. Work alongside senior engineers from Tesla, DeepMind, Databricks, and other top engineering orgs who treat compliance as a partner, not a tax. Shape how compliance is done for AI-native companies, where the frameworks haven’t caught up yet and the right answer is still being written. Earn competitive compensation and meaningful equity in a high-growth company. Benefits Competitive salary plus equity Daily lunches Commuter benefits 401(k) Medical, Dental, and Vision Unlimited PTO #J-18808-Ljbffr BrainCo
- ...is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team. You will shape... ...CCPA/CPRA compliance, design scalable audit processes and a robust GRC platform, and help lead regulatory strategy for AI safety. #J-18808-Ljbffr PerplexitySuggested
- ...Washington D.C., London and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security... ...-agents-as-code in the SDLC, AI- and agent-driven workflows, and machine... ...readable evidence.Responsibilities:Architect GRC's Engineering Foundation: Build...SuggestedWork experience placementWork at officeLocal areaShift work
- ...is seeking a governance, risk, and compliance analyst to shape and lead our program. You will drive frameworks... ...focused on trustworthy search and AI‑assisted experiences. The role emphasizes... ...functional collaboration across IT, Security, GTM, and Engineering in a data‑...Suggested
- ...seeking an IT Manager to own the entire IT and security function from scratch. This critical role... ...device management, security hygiene, compliance programs, and vendor management. The... ...infrastructure for years to come. Join a fast-growing AI platform impacting Fortune 500 clients....Suggested
- Alembic Technologies seeks a lead-level Security Engineer and Architect to own end-to-end security for our rapidly growing on-prem, Kubernetes-based AI factory. This hands-on role reports to the CTO/CISO and partners with Technical Operations, Corp IT, Platform Engineering...Suggested
- A remote-first AI governance company is seeking a Principal AI Security & Risk Researcher to lead security research and build frameworks for assessing AI risks. In this part-time role, you will design adaptive security systems, collaborate on automated testing tools, and...Part timeRemote workFlexible hours
- Alembic is seeking a lead-level Security Engineer and Architect in San Francisco to oversee security for our AI factory. In this hands-on role, you'll design security controls, manage incident responses, and ensure the protection of high-value client data while respecting...
- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our... ...risk management program. You will lead the implementation of frameworks, oversee... ...audit/compliance, automation using AI, and collaboration across IT, Security, GTM, and Engineering. You will...
- ...Palo Alto Networks, Inc. is seeking a Sr. Principal Software Engineer to enhance secure cloud environments with an AI-first approach. This role involves leading cloud security automation and implementing innovative infrastructure solutions. The ideal candidate should...
- ...based in San Francisco, CA, seeks a GRC Lead to own SOC 2, ISO 27001, FedRAMP certifications... ...with auditors, coordinating with security, legal, safety, and engineering. You will manage recurring compliance processes, track GDPR and EU AI Act requirements, identify gaps, and...
- Runway is seeking a seasoned GRC professional to lead governance, risk, and compliance across the US, with remote options. You will shape frameworks that balance security and responsible AI, working closely with product, engineering, and legal teams. Responsibilities include...Remote job
$193.8k - $228k
A leading technology company in San Francisco seeks a Senior GRC Analyst II. In this role, you will manage the Governance, Risk, and Compliance program, ensuring it aligns with security strategies. Candidates should have a strong knowledge of information security frameworks...- Pallet is seeking a dedicated GRC leader to manage compliance with regulations like SOC 1, SOC 2, GDPR, and CCPA. This role involves building the compliance operating model from the ground up while collaborating closely with engineering, product, sales, and legal teams....Flexible hours
- Thinking Machines Lab is seeking a GRC Lead to own certifications end-to-... ...audit close, and to run compliance processes day to day. You... ...auditors directly, working with security, legal, safety, and engineering... ..., monitor GDPR and AI Act requirements, and identify...
- Figma Job is looking for compliance and risk management professionals to join their GRC team. The ideal candidate will lead compliance programs across security frameworks like SOC2 and manage audits. The position offers the opportunity to improve processes and enhance...Remote jobFull time
- ...Manufacturing Co is seeking a Sr Manager for InfoSec Governance Risk and Compliance (GRC) in San Francisco, California. The role involves managing a... ...efforts, while serving as a subject matter expert on security frameworks. The ideal candidate will have over 7 years...
- ...Staff Enterprise Data Architect defines the overarching... ...competitive position. You will lead enterprise-wide... ...operational excellence and compliance. By translating high-... ..., reporting, and AI/ML use cases.Cultivate... ..., HR, Engineering, IT, GRC) to translate business...Work at officeLocal areaRemote workFlexible hours
$275k - $300k
...Postman is the world’s leading API platform, used by... ...the TeamThe Information Security organization at... ...pillars: Governance Risk & Compliance (GRC), Product Security, and... ...security validation, AI-augmented adversary emulation... ...-agent architectures.Architect Autonomous Testing:...Work at officeFlexible hours3 days per week$164.7k - $266k
...contract lifecycle management (CLM).What you'll doWe are seeking a Lead AI Architect to turn enterprise data, metadata, relationships, and... ...AI data architectures with enterprise governance, privacy, compliance, and responsible AI standardsPartner with Enterprise Architecture...Contract workWork at officeLocal areaRemote work2 days per week- Pave is hiring a Corporate Security Engineer to own identity and access management, endpoint protection, and SaaS security across a growing... ...global team. You will automate SOC2/ISO27001 controls and build AI-powered processes that reduce toil while strengthening...
- ...Staff Enterprise Data Architect defines the overarching... ...competitive position. You will lead enterprise‑wide... ...operational excellence and compliance. By translating high‑... ..., reporting, and AI/ML use cases. Cultivate... ..., HR, Engineering, IT, GRC) to translate business...Work at officeLocal areaFlexible hours
$153k - $296k
Figma is looking for a security, risk, and compliance professional, ideally with over 4 years of experience, to join their team. The role involves leading compliance initiatives across major frameworks and managing audits. The successful candidate will improve processes...Remote jobFull time$112k
Sr Manager, InfoSec Governance Risk and Compliance (GRC) Sr Manager, InfoSec Governance Risk... ...Compliance (GRC) Founded in 2000, Ivalua is a leading global provider of cloud-based... ...continuously improving Ivalua’s Information Security program globally. We provide peace of...Permanent employmentContract workFor contractorsFor subcontractorWork at officeWorldwide3 days per week- Rippling, the leading workforce automation company, is seeking a Product Lead to drive the evolution of Workflow Studio into a comprehensive... ...and agents—from onboarding and IT provisioning to payroll, compliance, and financial automation—while collaborating with engineering...
- GRC Security compliance leader Job Description: Job Title: GRC Security Compliance Leader Location: Remote Duration: 12+ Months (Contract) Responsibilities: Support implementing and managing Information -Security Management Systems by ISO27001 standards. 3rd party...Contract workWork at officeRemote workEarly shift
- Plaid is seeking a Security Contracts Manager to oversee contract reviews and ensure compliance with security standards. You will lead reviews for customer MSAs and security addenda while developing... ...pay, and opportunities for AI implementation in security processes....Contract work
- HEN Technologies in San Francisco is searching for a security and compliance leader to oversee the organization's security framework across multiple... ...compliance. You'll work closely with engineering teams, leading SOC 2 audits and developing robust security strategies. The...
- A leading digital security firm is seeking a GRC Security Compliance Leader for a remote position. Candidates should have 8-10 years of experience in Information Security and Compliance, with expertise in ISO 27001 and other relevant standards. Responsibilities include...Remote job
- Block, Inc. seeks an AI Legal Program Manager to navigate the legal and regulatory landscape of our AI initiatives. You will partner with legal, engineering, product, and compliance to build frameworks ensuring responsible AI innovation and regulatory risk management across...
- Coinbase is seeking a senior leader to drive AI-informed capacity planning across Compliance and new product launches. This remote-first company values rigor and impact, and the role demands clear, decision-ready narratives for executive audiences. You will build trusted...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Lead: AI Compliance & Security Architect. Be the first to apply!
- security architect San Francisco, CA
- cyber security architect San Francisco, CA
- dot compliance San Francisco, CA
- compliance auditor San Francisco, CA
- pharmaceutical regulatory affairs San Francisco, CA
- code compliance San Francisco, CA
- regulatory affairs part time San Francisco, CA
- compliance investigator San Francisco, CA
- vendor compliance San Francisco, CA
- environmental compliance San Francisco, CA

