Security Engineer - GRC Frameworks & AI Governance
$152k - $228kSpaceXAI
Job Description
Job Description
SpaceXAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
ABOUT THE ROLE:We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments.
RESPONSIBILITIES:- Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking.
- Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners.
- Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil.
- Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery.
- Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture.
- Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater.
- Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces).
- Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
- Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them.
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
- 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.
- Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure).
- Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks.
- Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring.
- Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation.
- 10+ years of security compliance, GRC engineering, or technology audit-related experience.
- Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
- Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations.
- Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment.
- Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company.
- Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks.
- Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment.
- Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch.
- Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language.
- Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred.
- Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus.
$152,000 - $228,000 USD
Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.
ITAR REQUIREMENTS:- To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.
SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
$140k - $170k
Security & Compliance Engineer Join to apply for the Security & Compliance Engineer... ...(Security) and governance, risk, and compliance (GRC), you’ll be responsible... ...maintaining compliance frameworks such as CMMC, NIST 800‑... ...artificial intelligence (AI) tools to support parts...SuggestedPermanent employmentH1bVisa sponsorshipWork visa- ...Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something... ...a Senior Security Engineer to support a customer's... ...Artificial Intelligence (AI) across their agency's... ...and the Risk Management Framework (RMF). Certifications...SuggestedFlexible hours
$104k - $156k
...Remote/Hybrid Job Overview The Advanced Security Engineer is a technically deep, hands-on... ...deployment, implementation and optimization of AI-enabled security technologies at all... ...controls are aligned to industry recognized frameworks. Validate that telemetry from each...SuggestedRemote work$100k - $120k
...a waiting period. Job Summary The Cybersecurity Analyst (Security & AI Governance) is responsible for protecting the organization's information... ..., regulatory requirements, and emerging AI governance frameworks. This position will work closely with the CIO and CISO functions...SuggestedTemporary work- ...teams support the federal government’s most critical national security and defense priorities,... ...Web Developer Security Engineer to join our team. This... ...with federal cybersecurity frameworks including NIST SP 800-53,... ...Experience leveraging AI-assisted development tools...SuggestedFull timeLocal areaRemote workFlexible hours
$147.3k - $193.3k
...this team The Data & AI Security team is responsible for... ...with Data & Analytics, Engineering, Legal, Privacy, and GRC teams to embed security... ...partners closely with Data Governance, Platform Engineering, and... ...security development frameworks Demonstrated ability...Permanent employmentPart timeWork at officeWork visa- Join to apply for the Security Engineer role at Jobright.ai 3 days ago Be among the first 25 applicants Join to... ...security tools (e.g., McAfee (NSM), GRC tool (CSAM)) • Perform system... ...with industry partners to advise the government regarding those security vulnerabilities...Full timeRemote work
- Join to apply for the Security Engineer role at HireCapital Join to apply for the Security Engineer... ..., ISO 27001, or other cybersecurity frameworks Employer-covered health insurance and strong... ...directly into each article, started with the help of AI. #J-18808-LjbffrPermanent employmentFull timeWork at officeRemote work
- ...Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something... ...a Mid-Level Security Engineer to support a customer's... ...Artificial Intelligence (AI) across the agency's... ...and the Risk Management Framework (RMF). Certifications...Contract workFlexible hours
$140k - $200k
...health, and national security environments. We apply... ...capabilities, including AI/ML, cloud,... ...bureaucracy. Lead Security Engineer Location: Suitland,... ...controls, and security governance practices Support Authority... ...with federal security frameworks and standards...Full timeFor contractorsWork experience placementFlexible hours$50 per hour
...Appian's Information Security team operates at the heart... ...modern security frameworks. Our team ensures that... ...infrastructure, automated governance, and enterprise threat... ...Science, Computer Engineering, Information Technology... ...Proven fluency in AI and LLMs, encompassing...Hourly payFull timeSummer workInternshipSummer internshipWork at officeLocal area$100k - $258k
SpaceXAI’s mission is to create AI systems that can accurately... ...motivated, and focused on engineering excellence. This organization... ...seeking a seasoned Senior Network Security Engineer to join our dynamic... ...: To conform to U.S. Government export regulations, applicant...Permanent employmentTemporary work$80k - $90k
Job Title: Cyber Security GRC Analyst - Governance, Risk & Compliance Company: Aaratech Inc. Experience: 4+ years Compensation: $80,000 - $90,0... ...initiatives. In this role, you will help manage security frameworks, support audit readiness, conduct risk assessments, and...- ...We specialize in advanced cybersecurity operations, AI/ML integration, cloud modernization, data governance, and risk management. With a proven track record... ...Department of Defense (DoD), Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency...Full time
$100k - $120k
Cogent Communications, based in Washington D.C., is looking for a skilled Cybersecurity Analyst (Security & AI Governance) to safeguard the organization’s information assets and technology infrastructure. This role involves identifying, assessing, and mitigating cyber...$100k - $120k
C.C.D. Cogent Communications Deutschland GmbH is seeking a Cybersecurity Analyst (Security & AI Governance) to protect information assets and manage cyber threats. The role involves collaboration with IT teams and business stakeholders to align cybersecurity and AI governance...$145k - $192.5k
...America’s Global Information Security (GIS) team is looking for a Cyber Threat Defense AI Security Senior Engineer to lead the integration of... ..., including model governance, bias mitigation, and explainability... ...architectures, and MLOps frameworks. Demonstrated ability to drive...Shift workDay shift$100k - $120k
...waiting period. Job Summary: The Cybersecurity Analyst (Security & AI Governance) is responsible for protecting the organization's information... ..., regulatory requirements, and emerging AI governance frameworks. This position will work closely with the CIO and CISO functions...Temporary workWork at office$120k - $190k
# Lead Security Engineer## Dev TechnologyPublished 16 Jul 2026### Share this jobSuitland, MD120K... ...activities and interfacing with senior government stakeholders. Additionally, the role... ...Zero Trust architecture, and the NIST framework, along with experience managing the ATO...- ...Description Job Description Dexian Government Solutions is recruiting for a Senior Security Risk Management Engineer to support our proposal... ...lead for Risk Management Framework (RMF) implementation, Assessment... ...Requirements: CISM + CAP or GRC Clearance Requirements:...Contract workTemporary workLocal area
- ...supporting Federal, State, and Local government agencies. As an SBA-... ...: Web Developer Security Engineer Location: US Congressional... ...modern web technologies and frameworks including .NET (C# MVC, WCF)... ...SQL. Ability to leverage AI-assisted development tools (...Work at officeLocal areaRemote work
$110k - $135k
...Manager, the Web Developer Embeds security across the SDLC for mission-... ...~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl... ..., REST APIs, SQL; ~ AI-assisted dev tools (Copilot,... ...support. Preferred:Federal framework authorization (NIST 800-53/FISMA...$75k - $95k
Join to apply for the Junior Security Engineer role at Tyto Athene, LLC Join to apply for the Junior... ...Engineer role at Tyto Athene, LLC Get AI-powered advice on this job and more... ...executed while coordinating with various government teams in mission-critical environments....16 hoursFull timeWork experience placementRemote work- ...future of cloud networking and security! Cato Networks is the... ...don't miss it! As a Cato AI Security Professional Services... ...architectures and establish governance frameworks aligned to standards such as... ...management, support and engineering teams by providing feedback...WorldwideFlexible hours
- ...component of our nation’s safety and security. Make an impact by using your... ...as a Cybersecurity Systems Engineer/Information Systems Security... ...support the Risk Management Framework (RMF) and ICD 503 Security... ...we do. ● Growth: AI-powered career tool that identifies...For contractorsInterim roleSummer workRelocation
$170k
...Looking to join a team shaping the legal and policy frameworks that govern technology and digital ecosystems? Join a specialist professional... ...‑term success. Responsibilities: Conduct regular security assessments, vulnerability testing, and risk analysis to identify...Permanent employment- ...health, and national security environments. We apply... ...capabilities, including AI/ML, cloud,... ...Senior Network Security Engineer – Palo Alto Firewall... ...secure, mission-critical government environment. The ideal... ..., and DoD security frameworks. Experience with monitoring...Full timeWork experience placementCasual workFlexible hours
- ...seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and... ...role is at the center of CIG's AI-driven Security Operations... ...response times for our government and commercial clients. Must... ...detection content to MITRE ATT&CK framework, ensuring coverage across...Remote workWork from homeFlexible hours
- ...Washington, DC Our client seeks a Security Engineer to support a federal cybersecurity... ...Experience with Tenable Nessus and federal frameworks is important. Due to federal security... ...utilizes artificial intelligence (AI) tools as part of its initial application...Hourly payPermanent employmentContract workLocal area
- ...Cybersecurity Architecture and Engineering, Critical Infrastructure and... ...faced by our federal government clients. Our focus is on enabling... ...effectively - anytime, anywhere, securely. We combine technical... ...desired. Demonstrated use of AI tools and automation platforms...Contract workWork at officeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer - GRC Frameworks & AI Governance. Be the first to apply!
- cloud security engineer Washington DC
- senior cloud security engineer Washington DC
- IT security engineer Washington DC
- sr information security engineer Washington DC
- aws cloud security engineer Washington DC
- azure security engineer Washington DC
- senior security operations engineer Washington DC
- application security engineer Washington DC
- senior application security engineer Washington DC
- sr security engineer Washington DC



