Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Lead: AI Compliance & Security Architect

BrainCo

About Brain Co. Brain Co. is an applied AI startup co-founded by Jared Kushner and Elad Gil, and backed by leading Silicon Valley builders including Patrick Collison and Andrej Karpathy. We are building AI applications for the world's most important institutions, delivering impact on real-world problems across governments, healthcare systems, and critical industries. Our progress so far: Automated construction permitting for a sovereign government 80% faster, unlocking $375M+ in value Optimized supply chains for a leading global energy company 30% lower cost, 99% reliability, preventing $100M+ in losses Streamlined hospital patient care across national health systems 40% better outcomes, 80% less admin work Company momentum: Raised a $55M Series A from leading investors Built a team of 70+ AI experts from Tesla, Google DeepMind, NVIDIA, and Databricks About the Role: At Brain Co., we focus on applying frontier AI to real institutional challenges, working alongside governments, healthcare systems, and critical industries to modernize how essential services operate. We are looking for leaders who want to help bring new technology into institutions that impact millions of people. As our GRC Lead, you’ll own the governance, risk, and compliance program end-to-end - and treat it as a strategic advantage, not a checklist. Brain Co. carries one of the most demanding regulatory loads of any company our size: SOC 2 Type II and HIPAA in place today, with ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and US/MENA data residency on the near-term roadmap. That’s what selling to governments, hospitals, and financial institutions costs - and done right, it’s how we win the next ones. This is a 01 builder role. You’ll define the principles, write the policies, run the audits, build the automation, and partner directly with engineering, legal, sales, and customer – not advising from the sidelines. This is a high-ownership role for someone who has built programs like this before and wants to build the next one from first principles. You’ll be an IC on day one with the scope and trust to grow the function as the company scales. What You'll Work On: Own the end-to-end GRC program: SOC 2 Type II and HIPAA today, and the path through ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and MENA-specific regimes that don’t map cleanly to a US playbook. Build the data handling backbone: how customer data is classified, where it lives, who can touch it, and how we prove it - across Azure, on-prem MENA deployments, and the bespoke deployments we run for governments and hospitals. Run audits as a builder, not a project manager: Own evidence, controls, gap remediation, and audit response, and automate the evidence pipeline so we’re not rebuilding workpapers every cycle. Stand up third-party risk as a real program: vendor reviews, data flow inventory, contractual security obligations, and a reassessment cadence that keeps pace with our SaaS footprint. Be the function that unblocks enterprise deals: Build the customer-trust surface — security questionnaires, trust portal, DPAs, BAAs, customer-facing docs — so customers understand how we handle their data before they have to ask. Partner with engineering: Bake compliance into the product: control inheritance from Azure, policy-as-code, automated access reviews, audit-ready logging, and evidence collection that runs without a human in the loop. Run a single risk operating cadence across HR, Finance, Legal, IT, and Engineering: so data handling, vendor approvals, and audit requests always have a clear owner. Be the translator between technical reality and regulatory expectations: the person engineers trust to interpret a control, and the person customers and auditors trust to explain the system behind it. You Might Be a Great Fit If You... Have 8+ years building and running GRC programs in regulated environments including healthcare, financial services, government, or enterprise SaaS where the stakes were real and the audits weren’t theatre. Have taken a company through SOC 2 Type II from a cold start, and lived HIPAA, GLBA, FedRAMP, or equivalent work hands-on, not just signed off on policies someone else wrote. View compliance as a competitive advantage and a forcing function for good engineering, not a checklist and not a bureaucracy to defend. Are a deep executor: you write the policies, draft the white papers, and ship the automation yourself, and can zoom out to design the program around them. Are a high-trust cross-functional partner - you can sit with an engineer reasoning about IAM controls in the morning, walk GTM through a DPA at noon, and brief a customer’s CISO in the afternoon. Translate technical risk for the boardroom and regulatory risk for the engineers fluently in both directions. Are at home in ambiguity and energized by a 01 program. We have a SOC 2 Type II baseline; the rest is yours to define. Have a strong opinion about data: how it’s classified, where it lives, who can see it, and how you prove it. You think in data flows, not policy templates. Bias toward pragmatism over bureaucracy. You know which controls matter, which ones are noise, and which ones you can automate out of existence. Bonus Points For: Direct experience operating across US and MENA (or other multi-jurisdictional) regulatory environments, including on-prem and data residency requirements. FedRAMP/GovRAMP, IL4/IL5, or equivalent government-customer compliance experience. Standing up GRC programs at AI or ML-heavy companies, including the novel evidence and disclosure questions that come with model training data, agent actions, and customer data flowing through AI systems. Hands-on with compliance automation tooling (Vanta, Drata, Secureframe, etc.) and a willingness to replace it when it’s the wrong tool. Comfort reading the technical controls themselves (Terraform, IAM policies, audit logs) well enough to verify what an auditor is being told. Why Join Us: Build the GRC function for an AI platform deployed in governments, hospitals, and critical industries worldwide — where the regulatory bar is real and the work matters. Own the program 01. Define the principles, design the system, and grow the function under you as the company scales. Work alongside senior engineers from Tesla, DeepMind, Databricks, and other top engineering orgs who treat compliance as a partner, not a tax. Shape how compliance is done for AI-native companies, where the frameworks haven’t caught up yet and the right answer is still being written. Earn competitive compensation and meaningful equity in a high-growth company. Benefits Competitive salary plus equity Daily lunches Commuter benefits 401(k) Medical, Dental, and Vision Unlimited PTO #J-18808-Ljbffr BrainCo

Vacancy posted 16 hours ago
Similar jobs that could be interesting for youBased on the GRC Lead: AI Compliance & Security Architect in San Francisco, CA vacancy
  • Beacon Software in San Francisco is looking for a GRC leader to establish the governance, risk, compliance, and privacy functions across its portfolio of software...  ...strong inclination towards automated processes and AI integration, fostering a scalable operational architecture... 
    Suggested

    Beacon Software

    San Francisco, CA
    16 hours ago
  • Brain Co. in San Francisco is seeking a GRC Lead to own the governance, risk, and compliance programs from start to finish. This high-ownership role requires an individual who will define policies, run audits, and integrate compliance into the engineering process. You'... 
    Suggested

    Brain Co.

    San Francisco, CA
    2 days ago
  •  ...seeking an IT Manager to own the entire IT and security function from scratch. This critical role...  ...device management, security hygiene, compliance programs, and vendor management. The...  ...infrastructure for years to come. Join a fast-growing AI platform impacting Fortune 500 clients.... 
    Suggested

    Aionia Group

    San Francisco, CA
    3 days ago
  • A remote-first AI governance company is seeking a Principal AI Security & Risk Researcher to lead security research and build frameworks for assessing AI risks. In this part-time role, you will design adaptive security systems, collaborate on automated testing tools, and... 
    Suggested
    Part time
    Remote work
    Flexible hours

    Ciph Lab

    San Francisco, CA
    16 hours ago
  • B Capital is seeking a Public Sector GRC Lead in San Francisco to manage FedRAMP compliance and drive security governance in cloud products. You will be responsible for maintaining key documents, engaging with auditors, and supporting sales in targeting public sector compliance... 
    Suggested

    B Capital

    San Francisco, CA
    1 day ago
  • Figma Job is looking for compliance and risk management professionals to join their GRC team. The ideal candidate will lead compliance programs across security frameworks like SOC2 and manage audits. The position offers the opportunity to improve processes and enhance... 
    Remote job
    Full time

    Figma Job

    San Francisco, CA
    1 day ago
  • $193.8k - $228k

    A leading technology company in San Francisco seeks a Senior GRC Analyst II. In this role, you will manage the Governance, Risk, and Compliance program, ensuring it aligns with security strategies. Candidates should have a strong knowledge of information security frameworks... 

    Itlearn360

    San Francisco, CA
    4 days ago
  • $172.5k - $260.1k

    Salesforce, Inc. is seeking a Security GRC Senior Lead in San Francisco to oversee compliance for global CCaaS initiatives. The role involves defining compliance strategy, monitoring regulations, and liaising with Product Management. Ideal candidates will have over 8 years... 
    Remote job

    Salesforce, Inc.

    San Francisco, CA
    1 day ago
  • Zania is seeking a GRC Engineer in San Francisco to bridge product and customer needs in Governance, Risk, and Compliance. In this role, you will drive customer implementations, establish success goals upfront, and ensure engagements conclude successfully while contributing... 
    Flexible hours

    Zania

    San Francisco, CA
    16 hours ago
  • Palo Alto Networks, Inc. is seeking a Sr. Principal Software Engineer to enhance secure cloud environments with an AI-first approach. This role involves leading cloud security automation and implementing innovative infrastructure solutions. The ideal candidate should have... 

    Palo Alto Networks, Inc.

    San Francisco, CA
    2 days ago
  • $185k - $220k

    Apply is seeking a Lead, Internal Audit and SOX Compliance based in San Francisco. This strategic role involves designing internal control programs and leading the SOX lifecycle, aiming for innovative and effective compliance solutions. The ideal candidate will have extensive... 

    Apply

    San Francisco, CA
    1 day ago
  • Anchorage Lending CA, LLC in New York seeks a highly motivated individual for their Compliance team. The role involves supporting the design, implementation, and optimization of compliance programs across all legal entities. You will focus on enhancing efficiency and effectiveness... 

    Anchorage Lending CA, LLC

    San Francisco, CA
    2 days ago
  • HEN Technologies in San Francisco is searching for a security and compliance leader to oversee the organization's security framework across multiple...  ...compliance. You'll work closely with engineering teams, leading SOC 2 audits and developing robust security strategies. The... 

    HEN Technologies

    San Francisco, CA
    16 hours ago
  • $112k

    Sr Manager, InfoSec Governance Risk and Compliance (GRC) Sr Manager, InfoSec Governance Risk...  ...Compliance (GRC) Founded in 2000, Ivalua is a leading global provider of cloud-based...  ...continuously improving Ivalua’s Information Security program globally. We provide peace of... 
    Permanent employment
    Contract work
    For contractors
    For subcontractor
    Work at office
    Worldwide
    3 days per week

    Ivalua

    San Francisco, CA
    4 days ago
  • A leading digital security firm is seeking a GRC Security Compliance Leader for a remote position. Candidates should have 8-10 years of experience in Information Security and Compliance, with expertise in ISO 27001 and other relevant standards. Responsibilities include... 
    Remote job

    Avantdigitalnow

    San Francisco, CA
    16 hours ago
  • A leading healthcare company is seeking a Manager of Regulatory Affairs based in remote locations. You will develop and execute regulatory strategies, manage FDA submissions, and ensure compliance for innovative medical devices. The ideal candidate has over 8 years of... 
    Remote job
    Full time

    El Camino Health

    San Francisco, CA
    16 hours ago
  • A leading compliance technology company based in San Francisco is looking for a Founding Growth Lead to enhance brand messaging and establish growth...  ...environment. Join a team committed to reinventing tax compliance with innovative AI solutions. #J-18808-Ljbffr Sphere, Inc.

    Sphere, Inc.

    San Francisco, CA
    1 day ago
  • B Capital is seeking a Senior and Lead Security Engineer for the Secure AI team. You will assess and maintain AI tooling security, ensuring compliance with Salesforce requirements while identifying emerging threats. Your role encompasses conducting security assessments... 

    B Capital

    San Francisco, CA
    4 days ago
  • Harmonic Security, Inc is seeking a Solutions Architect to bridge technical prospects and internal teams. This role involves engaging customers, executing proof...  ...background in enterprise security and experience with AI tools are essential. The position offers competitive... 

    Harmonic Security, Inc

    San Francisco, CA
    16 hours ago
  •  ...is on a mission to return time. As the leading AI Time platform for professional services...  ...working directly with Product, Engineering, Security, and Sales to shape how Laurel uses...  ...customer trust. This is not a pure compliance role and not a generalist legal position... 
    Relocation package

    Laurel

    San Francisco, CA
    2 days ago
  • $220k - $250k

    Who We Are Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build...  ...training, and production inference, with security, observability, and control built in. We...  ..., and day‑to‑day corporate governance. Lead and manage equity and debt transactions end... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    Neura Market

    San Francisco, CA
    4 days ago
  • A leading technology company is seeking a Governance Specialist to oversee privacy-centric governance related to AI. This role demands a strong legal background, particularly in privacy...  ...incident response processes, and ensuring compliance with international standards. The... 

    Unity

    San Francisco, CA
    6 hours ago
  • Laurel is seeking a Lead AI & Privacy Counsel in Los Angeles to oversee legal strategies regarding AI and data. This pivotal role involves...  ..., establishing data governance frameworks, and ensuring compliance with regulations. Candidates should have 10+ years of experience... 

    Laurel

    San Francisco, CA
    2 days ago
  •  ...Senior Security Architect Bangalore/San Francisco Bay Area About the Role We're looking for a...  ...intersection of deep security expertise, AI agent design, and product engineering....  ...their SecOps workflows, tooling stack, and compliance requirements. Monitor the threat... 

    Tessell

    San Francisco, CA
    a month ago
  • $250k - $400k

     ...Security Architect San Francisco, CA About Goodfire Goodfire is a research...  ..., learn from, and design AI systems. Our mission is to...  ...threats. In this role, you will lead our efforts to keep Goodfire...  ...policies, documentation, and compliance frameworks. Manage... 
    Work at office
    Remote work

    Goodfire

    San Francisco, CA
    19 days ago
  • A leading compliance organization in San Francisco is seeking a Senior Data & AI Compliance Specialist. This role involves managing data compliance functions, providing support for data sharing reviews, and ensuring adherence to HIPAA regulations. The ideal candidate will... 

    ARMA International

    San Francisco, CA
    16 hours ago
  •  ...Company Overview EchoTwin AI is pioneering AI-driven infrastructure intelligence...  ...-time insights into infrastructure, compliance, and safety. By enabling municipalities...  ...customer data. We're seeking a passionate Security Engineer to lead our cybersecurity initiatives and... 
    Flexible hours

    EchoTwin AI

    San Francisco, CA
    16 hours ago
  • Crusoe seeks a Principal Infrastructure Security Engineer to secure our AI cloud infrastructure. You'll lead the architectural shift to a zero-trust fabric and tackle complex challenges across the hardware and cloud stack. The ideal candidate has over 12 years of experience... 
    Shift work

    Crusoe

    San Francisco, CA
    2 days ago
  • $220.4k - $297.4k

    A leading data and AI company in San Francisco is seeking a Senior Security Engineer to enhance the safety of its platform. The role demands extensive experience in Data Security and distributed systems. The ideal candidate will have strong leadership and communication... 

    Databricks Inc.

    San Francisco, CA
    4 days ago
  • $252.5k

    Veeam-Software is seeking a Senior Technical Alliances Lead for Security & AI in San Francisco. The role involves shaping technical strategies, building solutions, and engaging with partner stakeholders to ensure strong integrations and alignment with enterprise customer... 

    Veeam-Software

    San Francisco, CA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Lead: AI Compliance & Security Architect. Be the first to apply!