Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Lead: AI Compliance & Security Architect

BrainCo

About Brain Co. Brain Co. is an applied AI startup co-founded by Jared Kushner and Elad Gil, and backed by leading Silicon Valley builders including Patrick Collison and Andrej Karpathy. We are building AI applications for the world's most important institutions, delivering impact on real-world problems across governments, healthcare systems, and critical industries. Our progress so far: Automated construction permitting for a sovereign government 80% faster, unlocking $375M+ in value Optimized supply chains for a leading global energy company 30% lower cost, 99% reliability, preventing $100M+ in losses Streamlined hospital patient care across national health systems 40% better outcomes, 80% less admin work Company momentum: Raised a $55M Series A from leading investors Built a team of 70+ AI experts from Tesla, Google DeepMind, NVIDIA, and Databricks About the Role: At Brain Co., we focus on applying frontier AI to real institutional challenges, working alongside governments, healthcare systems, and critical industries to modernize how essential services operate. We are looking for leaders who want to help bring new technology into institutions that impact millions of people. As our GRC Lead, you’ll own the governance, risk, and compliance program end-to-end - and treat it as a strategic advantage, not a checklist. Brain Co. carries one of the most demanding regulatory loads of any company our size: SOC 2 Type II and HIPAA in place today, with ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and US/MENA data residency on the near-term roadmap. That’s what selling to governments, hospitals, and financial institutions costs - and done right, it’s how we win the next ones. This is a 01 builder role. You’ll define the principles, write the policies, run the audits, build the automation, and partner directly with engineering, legal, sales, and customer – not advising from the sidelines. This is a high-ownership role for someone who has built programs like this before and wants to build the next one from first principles. You’ll be an IC on day one with the scope and trust to grow the function as the company scales. What You'll Work On: Own the end-to-end GRC program: SOC 2 Type II and HIPAA today, and the path through ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and MENA-specific regimes that don’t map cleanly to a US playbook. Build the data handling backbone: how customer data is classified, where it lives, who can touch it, and how we prove it - across Azure, on-prem MENA deployments, and the bespoke deployments we run for governments and hospitals. Run audits as a builder, not a project manager: Own evidence, controls, gap remediation, and audit response, and automate the evidence pipeline so we’re not rebuilding workpapers every cycle. Stand up third-party risk as a real program: vendor reviews, data flow inventory, contractual security obligations, and a reassessment cadence that keeps pace with our SaaS footprint. Be the function that unblocks enterprise deals: Build the customer-trust surface — security questionnaires, trust portal, DPAs, BAAs, customer-facing docs — so customers understand how we handle their data before they have to ask. Partner with engineering: Bake compliance into the product: control inheritance from Azure, policy-as-code, automated access reviews, audit-ready logging, and evidence collection that runs without a human in the loop. Run a single risk operating cadence across HR, Finance, Legal, IT, and Engineering: so data handling, vendor approvals, and audit requests always have a clear owner. Be the translator between technical reality and regulatory expectations: the person engineers trust to interpret a control, and the person customers and auditors trust to explain the system behind it. You Might Be a Great Fit If You... Have 8+ years building and running GRC programs in regulated environments including healthcare, financial services, government, or enterprise SaaS where the stakes were real and the audits weren’t theatre. Have taken a company through SOC 2 Type II from a cold start, and lived HIPAA, GLBA, FedRAMP, or equivalent work hands-on, not just signed off on policies someone else wrote. View compliance as a competitive advantage and a forcing function for good engineering, not a checklist and not a bureaucracy to defend. Are a deep executor: you write the policies, draft the white papers, and ship the automation yourself, and can zoom out to design the program around them. Are a high-trust cross-functional partner - you can sit with an engineer reasoning about IAM controls in the morning, walk GTM through a DPA at noon, and brief a customer’s CISO in the afternoon. Translate technical risk for the boardroom and regulatory risk for the engineers fluently in both directions. Are at home in ambiguity and energized by a 01 program. We have a SOC 2 Type II baseline; the rest is yours to define. Have a strong opinion about data: how it’s classified, where it lives, who can see it, and how you prove it. You think in data flows, not policy templates. Bias toward pragmatism over bureaucracy. You know which controls matter, which ones are noise, and which ones you can automate out of existence. Bonus Points For: Direct experience operating across US and MENA (or other multi-jurisdictional) regulatory environments, including on-prem and data residency requirements. FedRAMP/GovRAMP, IL4/IL5, or equivalent government-customer compliance experience. Standing up GRC programs at AI or ML-heavy companies, including the novel evidence and disclosure questions that come with model training data, agent actions, and customer data flowing through AI systems. Hands-on with compliance automation tooling (Vanta, Drata, Secureframe, etc.) and a willingness to replace it when it’s the wrong tool. Comfort reading the technical controls themselves (Terraform, IAM policies, audit logs) well enough to verify what an auditor is being told. Why Join Us: Build the GRC function for an AI platform deployed in governments, hospitals, and critical industries worldwide — where the regulatory bar is real and the work matters. Own the program 01. Define the principles, design the system, and grow the function under you as the company scales. Work alongside senior engineers from Tesla, DeepMind, Databricks, and other top engineering orgs who treat compliance as a partner, not a tax. Shape how compliance is done for AI-native companies, where the frameworks haven’t caught up yet and the right answer is still being written. Earn competitive compensation and meaningful equity in a high-growth company. Benefits Competitive salary plus equity Daily lunches Commuter benefits 401(k) Medical, Dental, and Vision Unlimited PTO #J-18808-Ljbffr BrainCo

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the GRC Lead: AI Compliance & Security Architect in San Francisco, CA vacancy
  •  ...is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team. You will shape...  ...CCPA/CPRA compliance, design scalable audit processes and a robust GRC platform, and help lead regulatory strategy for AI safety. #J-18808-Ljbffr Perplexity
    Suggested

    Perplexity

    San Francisco, CA
    12 hours ago
  •  ...Washington D.C., London and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security...  ...-agents-as-code in the SDLC, AI- and agent-driven workflows, and machine...  ...readable evidence.Responsibilities:Architect GRC's Engineering Foundation: Build... 
    Suggested
    Work experience placement
    Work at office
    Local area
    Shift work

    Plaid Financial

    San Francisco, CA
    4 days ago
  •  ...is seeking a governance, risk, and compliance analyst to shape and lead our program. You will drive frameworks...  ...focused on trustworthy search and AI‑assisted experiences. The role emphasizes...  ...functional collaboration across IT, Security, GTM, and Engineering in a data‑... 
    Suggested

    Perplexity

    San Francisco, CA
    2 days ago
  •  ...seeking an IT Manager to own the entire IT and security function from scratch. This critical role...  ...device management, security hygiene, compliance programs, and vendor management. The...  ...infrastructure for years to come. Join a fast-growing AI platform impacting Fortune 500 clients.... 
    Suggested

    Aionia Group

    San Francisco, CA
    4 days ago
  • A remote-first AI governance company is seeking a Principal AI Security & Risk Researcher to lead security research and build frameworks for assessing AI risks. In this part-time role, you will design adaptive security systems, collaborate on automated testing tools, and... 
    Suggested
    Part time
    Remote work
    Flexible hours

    Ciph Lab

    San Francisco, CA
    1 day ago
  • Alembic is seeking a lead-level Security Engineer and Architect in San Francisco to oversee security for our AI factory. In this hands-on role, you'll design security controls, manage incident responses, and ensure the protection of high-value client data while respecting... 

    Alembic

    San Francisco, CA
    1 day ago
  • Alembic Technologies seeks a lead-level Security Engineer and Architect to own end-to-end security for our rapidly growing on-prem, Kubernetes-based AI factory. This hands-on role reports to the CTO/CISO and partners with Technical Operations, Corp IT, Platform Engineering... 

    Alembic Technologies

    San Francisco, CA
    1 day ago
  • Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our...  ...risk management program. You will lead the implementation of frameworks, oversee...  ...audit/compliance, automation using AI, and collaboration across IT, Security, GTM, and Engineering. You will... 

    Apply

    San Francisco, CA
    3 days ago
  •  ...based in San Francisco, CA, seeks a GRC Lead to own SOC 2, ISO 27001, FedRAMP certifications...  ...with auditors, coordinating with security, legal, safety, and engineering. You will manage recurring compliance processes, track GDPR and EU AI Act requirements, identify gaps, and... 

    Thinkingmachines

    San Francisco, CA
    1 day ago
  • Runway is seeking a seasoned GRC professional to lead governance, risk, and compliance across the US, with remote options. You will shape frameworks that balance security and responsible AI, working closely with product, engineering, and legal teams. Responsibilities include... 
    Remote job

    Runway Financial

    San Francisco, CA
    22 hours ago
  • Figma Job is looking for compliance and risk management professionals to join their GRC team. The ideal candidate will lead compliance programs across security frameworks like SOC2 and manage audits. The position offers the opportunity to improve processes and enhance... 
    Remote job
    Full time

    Figma Job

    San Francisco, CA
    2 days ago
  • Thinking Machines Lab is seeking a GRC Lead to own certifications end-to-...  ...audit close, and to run compliance processes day to day. You...  ...auditors directly, working with security, legal, safety, and engineering...  ..., monitor GDPR and AI Act requirements, and identify... 

    Doist

    San Francisco, CA
    2 days ago
  • $193.8k - $228k

    A leading technology company in San Francisco seeks a Senior GRC Analyst II. In this role, you will manage the Governance, Risk, and Compliance program, ensuring it aligns with security strategies. Candidates should have a strong knowledge of information security frameworks... 

    Itlearn360

    San Francisco, CA
    12 hours ago
  • Pallet is seeking a dedicated GRC leader to manage compliance with regulations like SOC 1, SOC 2, GDPR, and CCPA. This role involves building the compliance operating model from the ground up while collaborating closely with engineering, product, sales, and legal teams.... 
    Flexible hours

    Pallet

    San Francisco, CA
    4 days ago
  •  ...Palo Alto Networks, Inc. is seeking a Sr. Principal Software Engineer to enhance secure cloud environments with an AI-first approach. This role involves leading cloud security automation and implementing innovative infrastructure solutions. The ideal candidate should... 

    Palo Alto Networks, Inc.

    San Francisco, CA
    4 days ago
  •  ...Manufacturing Co is seeking a Sr Manager for InfoSec Governance Risk and Compliance (GRC) in San Francisco, California. The role involves managing a...  ...efforts, while serving as a subject matter expert on security frameworks. The ideal candidate will have over 7 years... 

    Dormont Manufacturing Company

    San Francisco, CA
    3 days ago
  •  ...Staff Enterprise Data Architect defines the overarching...  ...competitive position. You will lead enterprise-wide...  ...operational excellence and compliance. By translating high-...  ..., reporting, and AI/ML use cases.Cultivate...  ..., HR, Engineering, IT, GRC) to translate business... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Oura

    San Francisco, CA
    2 days ago
  • $275k - $300k

     ...Postman is the world’s leading API platform, used by...  ...the TeamThe Information Security organization at...  ...pillars: Governance Risk & Compliance (GRC), Product Security, and...  ...security validation, AI-augmented adversary emulation...  ...-agent architectures.Architect Autonomous Testing:... 
    Work at office
    Flexible hours
    3 days per week

    Postman

    San Francisco, CA
    1 day ago
  • $164.7k - $266k

     ...contract lifecycle management (CLM).What you'll doWe are seeking a Lead AI Architect to turn enterprise data, metadata, relationships, and...  ...AI data architectures with enterprise governance, privacy, compliance, and responsible AI standardsPartner with Enterprise Architecture... 
    Contract work
    Work at office
    Local area
    Remote work
    2 days per week

    DocuSign

    San Francisco, CA
    2 days ago
  • Pave is hiring a Corporate Security Engineer to own identity and access management, endpoint protection, and SaaS security across a growing...  ...global team. You will automate SOC2/ISO27001 controls and build AI-powered processes that reduce toil while strengthening... 

    Pave

    San Francisco, CA
    2 days ago
  •  ...Staff Enterprise Data Architect defines the overarching...  ...competitive position. You will lead enterprise‑wide...  ...operational excellence and compliance. By translating high‑...  ..., reporting, and AI/ML use cases. Cultivate...  ..., HR, Engineering, IT, GRC) to translate business... 
    Work at office
    Local area
    Flexible hours

    ŌURA

    San Francisco, CA
    3 days ago
  • $153k - $296k

    Figma is looking for a security, risk, and compliance professional, ideally with over 4 years of experience, to join their team. The role involves leading compliance initiatives across major frameworks and managing audits. The successful candidate will improve processes... 
    Remote job
    Full time

    Figma

    San Francisco, CA
    1 day ago
  • $112k

    Sr Manager, InfoSec Governance Risk and Compliance (GRC) Sr Manager, InfoSec Governance Risk...  ...Compliance (GRC) Founded in 2000, Ivalua is a leading global provider of cloud-based...  ...continuously improving Ivalua’s Information Security program globally. We provide peace of... 
    Permanent employment
    Contract work
    For contractors
    For subcontractor
    Work at office
    Worldwide
    3 days per week

    Ivalua

    San Francisco, CA
    22 hours ago
  • Block, Inc. seeks an AI Legal Program Manager to navigate the legal and regulatory landscape of our AI initiatives. You will partner with legal, engineering, product, and compliance to build frameworks ensuring responsible AI innovation and regulatory risk management across... 

    Block, Inc.

    San Francisco, CA
    1 day ago
  • A leading digital security firm is seeking a GRC Security Compliance Leader for a remote position. Candidates should have 8-10 years of experience in Information Security and Compliance, with expertise in ISO 27001 and other relevant standards. Responsibilities include... 
    Remote job

    Avantdigitalnow

    San Francisco, CA
    1 day ago
  • Superpower seeks a Privacy & Compliance Specialist to build and run its privacy program, protecting member health data across HIPAA, SOC 2...  ...data, manage vendor agreements, run DPIAs, advise product teams on AI data use, and keep our program compliant as we scale to 50 #J-1... 

    Superpower,-Inc

    San Francisco, CA
    12 hours ago
  • Coinbase is seeking a senior leader to drive AI-informed capacity planning across Compliance and new product launches. This remote-first company values rigor and impact, and the role demands clear, decision-ready narratives for executive audiences. You will build trusted... 
    Remote job

    Coinbase

    San Francisco, CA
    1 day ago
  • Rippling, the leading workforce automation company, is seeking a Product Lead to drive the evolution of Workflow Studio into a comprehensive...  ...and agents—from onboarding and IT provisioning to payroll, compliance, and financial automation—while collaborating with engineering... 

    Rippling

    San Francisco, CA
    3 days ago
  • GRC Security compliance leader Job Description: Job Title: GRC Security Compliance Leader Location: Remote Duration: 12+ Months (Contract) Responsibilities: Support implementing and managing Information -Security Management Systems by ISO27001 standards. 3rd party... 
    Contract work
    Work at office
    Remote work
    Early shift

    Avantdigitalnow

    San Francisco, CA
    1 day ago
  • Plaid is seeking a Security Contracts Manager to oversee contract reviews and ensure compliance with security standards. You will lead reviews for customer MSAs and security addenda while developing...  ...pay, and opportunities for AI implementation in security processes.... 
    Contract work

    Plaid

    San Francisco, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Lead: AI Compliance & Security Architect. Be the first to apply!