GRC Lead: AI Compliance & Security Architect
BrainCo
About Brain Co. Brain Co. is an applied AI startup co-founded by Jared Kushner and Elad Gil, and backed by leading Silicon Valley builders including Patrick Collison and Andrej Karpathy. We are building AI applications for the world's most important institutions, delivering impact on real-world problems across governments, healthcare systems, and critical industries. Our progress so far: Automated construction permitting for a sovereign government 80% faster, unlocking $375M+ in value Optimized supply chains for a leading global energy company 30% lower cost, 99% reliability, preventing $100M+ in losses Streamlined hospital patient care across national health systems 40% better outcomes, 80% less admin work Company momentum: Raised a $55M Series A from leading investors Built a team of 70+ AI experts from Tesla, Google DeepMind, NVIDIA, and Databricks About the Role: At Brain Co., we focus on applying frontier AI to real institutional challenges, working alongside governments, healthcare systems, and critical industries to modernize how essential services operate. We are looking for leaders who want to help bring new technology into institutions that impact millions of people. As our GRC Lead, you’ll own the governance, risk, and compliance program end-to-end - and treat it as a strategic advantage, not a checklist. Brain Co. carries one of the most demanding regulatory loads of any company our size: SOC 2 Type II and HIPAA in place today, with ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and US/MENA data residency on the near-term roadmap. That’s what selling to governments, hospitals, and financial institutions costs - and done right, it’s how we win the next ones. This is a 01 builder role. You’ll define the principles, write the policies, run the audits, build the automation, and partner directly with engineering, legal, sales, and customer – not advising from the sidelines. This is a high-ownership role for someone who has built programs like this before and wants to build the next one from first principles. You’ll be an IC on day one with the scope and trust to grow the function as the company scales. What You'll Work On: Own the end-to-end GRC program: SOC 2 Type II and HIPAA today, and the path through ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and MENA-specific regimes that don’t map cleanly to a US playbook. Build the data handling backbone: how customer data is classified, where it lives, who can touch it, and how we prove it - across Azure, on-prem MENA deployments, and the bespoke deployments we run for governments and hospitals. Run audits as a builder, not a project manager: Own evidence, controls, gap remediation, and audit response, and automate the evidence pipeline so we’re not rebuilding workpapers every cycle. Stand up third-party risk as a real program: vendor reviews, data flow inventory, contractual security obligations, and a reassessment cadence that keeps pace with our SaaS footprint. Be the function that unblocks enterprise deals: Build the customer-trust surface — security questionnaires, trust portal, DPAs, BAAs, customer-facing docs — so customers understand how we handle their data before they have to ask. Partner with engineering: Bake compliance into the product: control inheritance from Azure, policy-as-code, automated access reviews, audit-ready logging, and evidence collection that runs without a human in the loop. Run a single risk operating cadence across HR, Finance, Legal, IT, and Engineering: so data handling, vendor approvals, and audit requests always have a clear owner. Be the translator between technical reality and regulatory expectations: the person engineers trust to interpret a control, and the person customers and auditors trust to explain the system behind it. You Might Be a Great Fit If You... Have 8+ years building and running GRC programs in regulated environments including healthcare, financial services, government, or enterprise SaaS where the stakes were real and the audits weren’t theatre. Have taken a company through SOC 2 Type II from a cold start, and lived HIPAA, GLBA, FedRAMP, or equivalent work hands-on, not just signed off on policies someone else wrote. View compliance as a competitive advantage and a forcing function for good engineering, not a checklist and not a bureaucracy to defend. Are a deep executor: you write the policies, draft the white papers, and ship the automation yourself, and can zoom out to design the program around them. Are a high-trust cross-functional partner - you can sit with an engineer reasoning about IAM controls in the morning, walk GTM through a DPA at noon, and brief a customer’s CISO in the afternoon. Translate technical risk for the boardroom and regulatory risk for the engineers fluently in both directions. Are at home in ambiguity and energized by a 01 program. We have a SOC 2 Type II baseline; the rest is yours to define. Have a strong opinion about data: how it’s classified, where it lives, who can see it, and how you prove it. You think in data flows, not policy templates. Bias toward pragmatism over bureaucracy. You know which controls matter, which ones are noise, and which ones you can automate out of existence. Bonus Points For: Direct experience operating across US and MENA (or other multi-jurisdictional) regulatory environments, including on-prem and data residency requirements. FedRAMP/GovRAMP, IL4/IL5, or equivalent government-customer compliance experience. Standing up GRC programs at AI or ML-heavy companies, including the novel evidence and disclosure questions that come with model training data, agent actions, and customer data flowing through AI systems. Hands-on with compliance automation tooling (Vanta, Drata, Secureframe, etc.) and a willingness to replace it when it’s the wrong tool. Comfort reading the technical controls themselves (Terraform, IAM policies, audit logs) well enough to verify what an auditor is being told. Why Join Us: Build the GRC function for an AI platform deployed in governments, hospitals, and critical industries worldwide — where the regulatory bar is real and the work matters. Own the program 01. Define the principles, design the system, and grow the function under you as the company scales. Work alongside senior engineers from Tesla, DeepMind, Databricks, and other top engineering orgs who treat compliance as a partner, not a tax. Shape how compliance is done for AI-native companies, where the frameworks haven’t caught up yet and the right answer is still being written. Earn competitive compensation and meaningful equity in a high-growth company. Benefits Competitive salary plus equity Daily lunches Commuter benefits 401(k) Medical, Dental, and Vision Unlimited PTO #J-18808-Ljbffr BrainCo
- Brain Co. in San Francisco is seeking a GRC Lead to own the governance, risk, and compliance program. This high-ownership role involves defining principles and policies while directly collaborating with engineering and legal teams. The ideal candidate will have 8+ years...Suggested
- A remote-first AI governance company is seeking a Principal AI Security & Risk Researcher to lead security research and build frameworks for assessing AI risks. In this part-time role, you will design adaptive security systems, collaborate on automated testing tools, and...SuggestedPart timeRemote workFlexible hours
$148.5k - $223.9k
Overview The Public Sector GRC Lead role is part of Informatica's Security and Compliance organization, focusing on maintaining and expanding compliance authorizations that enable Informatica's cloud products to serve government customers at scale. The incumbent will serve...Suggested$193.8k - $228k
A leading technology company in San Francisco seeks a Senior GRC Analyst II. In this role, you will manage the Governance, Risk, and Compliance program, ensuring it aligns with security strategies. Candidates should have a strong knowledge of information security frameworks...Suggested- B Capital is seeking a Public Sector GRC Lead in San Francisco to manage FedRAMP compliance and drive security governance in cloud products. You will be responsible for maintaining key documents, engaging with auditors, and supporting sales in targeting public sector compliance...Suggested
$182k - $295k
Hex is seeking a Security GRC Manager in San Francisco, CA, to establish and scale security compliance programs across various frameworks such as SOC 2, ISO 27001, and HIPAA. This pivotal role involves both strategic program development and hands-on tasks like audits and...Flexible hours- Zania is seeking a GRC Engineer in San Francisco to bridge product and customer needs in Governance, Risk, and Compliance. In this role, you will drive customer implementations, establish success goals upfront, and ensure engagements conclude successfully while contributing...Flexible hours
- ...Job Description: Job Title: GRC Security Compliance Leader Location: Remote Duration: 12+ Months (Contract) Work Time zone: PST Hours Responsibilities: ~ Support implementing and managing Information -Security Management Systems by ISO27001 standards...Contract workWork at officeRemote workEarly shift
- ...A leading healthcare company is seeking a Manager of Regulatory Affairs based in remote locations. You will develop and execute regulatory strategies, manage FDA submissions, and ensure compliance for innovative medical devices. The ideal candidate has over 8 years of...Full timeRemote work
- A leading compliance technology company based in San Francisco is looking for a Founding Growth Lead to enhance brand messaging and establish growth... ...environment. Join a team committed to reinventing tax compliance with innovative AI solutions. #J-18808-Ljbffr Sphere, Inc.
- A technology-focused public benefit corporation is seeking a compliance expert to drive HIPAA compliance efforts across its product portfolio. This role requires at least 5 years of relevant experience, proficiency in cloud-native environments, and the ability to build...
- Cash App is seeking a Front Office Brokerage Operations Lead to manage operations and supervise compliance in brokerage services. This role involves leadership over regulatory frameworks while ensuring exceptional customer experiences. You will directly oversee a specialized...Remote work
$236k - $300k
A leading technology firm in San Francisco is looking for a Compliance Counsel Lead to build and manage a global compliance program. Responsibilities include advising teams on regulatory matters, conducting risk assessments, and maintaining compliance policies. Candidates...$205k - $225k
...General Controls across enterprise applications while ensuring compliance with SOX 404. This role requires 10+ years of experience in IT controls... ...with various teams to optimize workflows and integrate AI solutions into controls. The compensation for this role ranges from...Work at office- A leading tax technology company in San Francisco is looking for a highly experienced tax professional to oversee the development of an AI-driven tax engine. This role requires a strong understanding of compliance processes and the ability to bridge tax and engineering...
$204k - $310k
...Principal / Senior Principal, Security Architect San Francisco, CA USA... ...Principal Security Architect to lead the security architecture for... ...FedRAMP and non-FedRAMP systems Compliance-aware designs that minimize... ...most inspiring frontier for AI. Rather than hard-coding...Full timeWork at officeLocal areaFlexible hours- ...Senior Security Architect Bangalore/San Francisco Bay Area About the Role We're looking for a... ...intersection of deep security expertise, AI agent design, and product engineering.... ...their SecOps workflows, tooling stack, and compliance requirements. Monitor the threat...
$250k - $400k
...Security Architect San Francisco, CA About Goodfire Goodfire is a research... ..., learn from, and design AI systems. Our mission is to... ...threats. In this role, you will lead our efforts to keep Goodfire... ...policies, documentation, and compliance frameworks. Manage...Work at officeRemote work- ...Security & Compliance Engineer San Francisco • Hybrid • Full-time About BackOps AI BackOps AI is transforming supply chain operations... ...and remediation tracking Lead recurring access reviews, control... ...in security, compliance, GRC, cloud security, security...Full timeRemote workFlexible hours
$123k - $175k
...BizBuySell - Lead Data Analyst Job Description Company Overview... ...an analytics strategist and architect, partnering closely with... ...business. As we expand our use of AI both internally and in customer... ...Group is also committed to compliance with all fair employment practices...Full time- ...is on a mission to return time. As the leading AI Time platform for professional services... ...working directly with Product, Engineering, Security, and Sales to shape how Laurel uses... ...customer trust. This is not a pure compliance role and not a generalist legal position...Relocation package
$220k - $250k
Who We Are Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build... ...training, and production inference, with security, observability, and control built in. We... ..., and day‑to‑day corporate governance. Lead and manage equity and debt transactions end...Work at officeWork from homeFlexible hours2 days per week- Laurel is seeking a Lead AI & Privacy Counsel in Los Angeles to oversee legal strategies regarding AI and data. This pivotal role involves... ..., establishing data governance frameworks, and ensuring compliance with regulations. Candidates should have 10+ years of experience...
$220.4k - $297.4k
A leading data and AI company in San Francisco is looking for a Senior Data Security Leader to drive security practices and infrastructure improvements. The ideal candidate will possess over 9 years of experience in Data Security, including expertise in areas like Cryptography...$220.4k - $297.4k
A leading data and AI company in San Francisco is seeking a Senior Security Engineer to enhance the safety of its platform. The role demands extensive experience in Data Security and distributed systems. The ideal candidate will have strong leadership and communication...$120k - $175k
...Technology Cyber Security Architect Cooley is seeking a Cyber Security Architect to join the technology... ...and artificial intelligence (AI) security. Working collaboratively with... ...computer platforms Demonstrated experience leading and developing others by providing...Full timeTemporary workWork at officeFlexible hoursWeekend work$180k - $350k
A tech startup is seeking a Security Engineer to own the security posture of their AI training platform. This role involves threat modeling, secure architecture, and managing external security assessments. Ideal candidates will have over 5 years in security roles and deep...Remote job$252.5k
Veeam-Software is seeking a Senior Technical Alliances Lead for Security & AI in San Francisco. The role involves shaping technical strategies, building solutions, and engaging with partner stakeholders to ensure strong integrations and alignment with enterprise customer...$184.87k - $324.19k
...class training facility, and leading market tools, we help our people... ...a Director, SAP Enterprise Architect - Finance for our Consulting... ...strong knowledge of Agentic AI and SAP Business AI preferred... ...information regarding KPMG's compliance with federal, state and local...H1bLocal area$124k - $186k
...model is deliberately agentic AI-first : a multi-agent... ...Dozens of account, contact, and lead signals remain unaddressed. Every... ...promote, drift alerts, and privacy/compliance checks. This role is expected... ...use of AI (including privacy, security, bias awareness, and human-in-...For contractorsWork experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Lead: AI Compliance & Security Architect. Be the first to apply!
- cyber security architect San Francisco, CA
- aws security architect San Francisco, CA
- security architect San Francisco, CA
- mortgage compliance San Francisco, CA
- regulatory compliance associate San Francisco, CA
- regulatory compliance analyst San Francisco, CA
- vendor compliance San Francisco, CA
- ethics compliance San Francisco, CA
- vice president compliance San Francisco, CA
- regulatory compliance engineer San Francisco, CA

