Security Engineer - Governance Risk Compliance
$100k - $228kXai
Security Engineer - Governance Risk Compliance
New York, NY; Palo Alto, CA; Washington, D.C.
About xAI
xAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
About The Role:
We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) team member as we expand into government and public sector applications of AI. This critical role will ensure that xAI operates within regulatory, ethical, operational, and federal boundaries while fostering a culture of integrity and resilience. You will collaborate with cross-functional teams to safeguard our mission-driven work in AI development and deployment, including support for sensitive and classified environments.
Responsibilities:
- Execute security compliance implementation and audits (e.g., ISO 27001/42001, SOC2, FedRAMP HIGH, DoD Cloud Computing SRG IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
- Work with 3PAOs (Third-Party Assessment Organizations) and federal government Authorizing Officials (AOs) to achieve compliance certifications, reports, and Authorized to Operate (ATO) status.
- Identify, assess, and prioritize risks related to AI operations, cybersecurity, regulatory compliance, intellectual property, and cloud deployments.
- Design and implement risk mitigation strategies, including monitoring systems, contingency plans, vulnerability scans, Plan of Action and Milestones (POAMs), and STIGs.
- Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures throughout the project lifecycle.
- Serve as a liaison between system owners, security personnel, and cross-functional teams to facilitate effective communication, collaboration, and control implementation.
- Lead Risk Management Assessment and Authorization (A&A) processes, cloud system risk assessments, compliance reviews for new products/changes/features, and process enhancements.
- Conduct regular risk assessments, scenario analyses, and proactive evaluations of emerging threats, certifications, requirements, and technologies in the AI landscape.
- Oversee audits, certifications, third-party assessments, and vulnerability management to maintain compliance and operational credibility.
- Act as a subject matter expert, providing guidance on risk, compliance, and cybersecurity matters; translate business and technical risks for leadership.
- Create and present regular reports on GRC performance, risks, and compliance status to senior leadership and stakeholders.
Basic Qualifications:
- Previous systems engineering experience strongly preferred
- Must have the ability to evaluate control objectives with IT configurations
- Bachelor's degree in Computer Science Information Security, Cybersecurity, or a related field
- Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.
- 3+ years of experience in governance, risk management, compliance, or technology audit roles.
- Proven expertise in regulatory frameworks, data privacy, cybersecurity, and federal compliance standards, preferably in a technology, cloud, or AI-driven environment.
- Strong understanding of AI ethics, emerging technologies, Risk Management Framework (RMF), and their associated risks.
- Experience with vulnerability management, POAMs, STIG implementation, and cloud security controls.
- Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to balance innovation, oversight, and taking projects from conception to launch.
- Excellent communication, stakeholder management, and translation skills, with experience influencing cross-functional teams and communicating risks to leadership.
- Ability to thrive in a fast-paced, dynamic environment and adapt to evolving priorities.
Preferred Skills And Experience:
- Experience in the tech or AI industry, particularly with startups, innovative organizations, or government/public sector engagements.
- Deep expertise maintaining frameworks such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, and STIG/RMF policies (including validation via ACAS and similar tools).
- Familiarity with ISO 27001, ISO 42001, NIST, SOC 2, or similar compliance frameworks.
- Background in managing third-party risk, vendor compliance programs, or federal assessments.
- Understanding of cybersecurity controls for cloud service providers.
- Knowledge of government cloud services and evolving certification programs.
- 5+ years of security compliance or technology audit-related.
Compensation And Benefits:
$100,000 - $228,000 USD
Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.
xAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
$280k - $300k
...Sr. Director , Security Software EngineeringSr. Director , Security... ...a team of 3-4 security engineers, focusing on recruitment, mentoring... ...state and local laws governing nondiscrimination in... ...Security Analyst I (Governance, Risk & Compliance)ERP Business Systems Analyst...SuggestedLocal areaRemote workFlexible hoursShift workNight shiftWeekend work$100k - $172.5k
...: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture... ...for a Principal Product Security Engineer to be located in Danvers, MA or... ...you are eager to leverage your security risk and compliance skills to make a difference and directly...SuggestedFull timeTemporary workWork at officeLocal areaImmediate startRemote work3 days per week- ...Senior Network Security Engineer-W2-GC-USC Job Location: Hybrid. Located in one of our hub cities, with preference for CST – 10% onsite... ...plus. Experience with managing projects to include task delegations, documentation, risk management, and technical ownership....SuggestedRemote work
- Job Title For positions that will be based in CA, the annual salary range for this position is below. Actual salaries may vary based on numerous factors including, among other things, an individual applicant's experience and qualifications for the position. This range...Suggested
$112k - $150.1k
...The Global Information Security (GIS) organization strives... ...cyber threats that present risk to The Walt Disney Company.... ...Security Architecture and Engineering team is Disney’s trusted authority... ...objectives. Support governance and compliance efforts by aligning solutions...SuggestedWork experience placement- ...Job Description Title: Sr. Product Security Engineer Location: Remote Ekman Associates is a management consulting firm that specializes in... ...Security policies and standards in collaboration with technology risk; AI/Agent SME: Provide AI/Agent subject matter expertise for...Remote work
$162.35k - $199.85k
...Sr. AI Security Engineer The Digital Threat Management (DTM) team is looking for a Sr. AI Security... ...strategy, regulatory exam readiness, risk reduction, and overall data trust. In... ...transformation initiatives, ensuring governance is built into system modernization, cloud...$160k - $200k
...THE ROLE The Principal Data Security Architect / Governance will be a pivotal leader in establishing... ...adoption of best practices, and driving compliance within our AWS and Databricks-centric... ...management. Compliance and Risk Management: Serve as the primary subject...Local areaWorldwideFlexible hours- ...integration Cloud platforms (AWS, Azure, or GCP) Compliance frameworks (SOX, PCI-DSS) Responsibilities: Design... ...Enforce privileged access policies and security standards Support audits, access reviews, and risk assessments Troubleshoot platform issues and drive...H1bRemote work
- ...Title: Sr. Security Engineer Location: 4 days onsite Monday - Thursday. 1 Day remote Friday.... ...5.) Demonstrated experience supporting compliance and audit processes (SOX, PCI-DSS, or similar... ...best practices. - Lead PAM-related risk assessments, access reviews, and audit...Permanent employmentWork experience placementRemote work
$90 - $97 per hour
...Senior Security Engineer - PAM Software Resources has an immediate, contract job opportunity... ...industry best practices. - Lead PAM-related risk assessments, access reviews, and audit... .... - Demonstrated experience supporting compliance and audit processes (SOX, PCI-DSS, or...Permanent employmentContract workTemporary workWork experience placementImmediate start- ...solve the nation's most complex security challenges. We strive for an... ...document system audits and risk analysis. Manage and execute... ...(ConMon) tasks to ensure compliance throughout the system lifecycle... ...applicants will be subject to a government security investigation and...Full timeWork experience placementLocal areaImmediate startRemote workFlexible hours
- ...Senior Principal Cyber Engineer Forcepoint simplifies security for global businesses and governments. Forcepoint's all-in-one, truly cloud-native platform makes it easy to adopt Zero Trust and prevent the theft or loss of sensitive data and intellectual property no...Full timeRemote work
- ...Cyber Defense Specialist, Consultant The Information Security team is looking for a certified security professional to join our fast... ...into actionable continuous improvement opportunities to reduce risk and improve effectiveness Qualifications Your Knowledge...Work at office2 days per week
- ...Information Systems Security Manager (ISSM) Join Northrop Grumman on our continued mission... ...processes to ensure mitigation of risks and supports obtaining certification and... ...Assist in the implementation of the required government policy, make recommendations on process...For contractorsLocal area
$146.28k - $219.42k
...Cybersecurity Senior Advisor – Offensive Security & Exposure Management... ..., and delivering measurable risk reduction across the... ...partnering across security, engineering, and business teams to identify... ...Management Legal Regulations, Compliance and Investigations Operations...Work at office2 days per week1 day per week$168k - $195k
...Senior Cyber Security Engineer - Siem And Automation At Corebridge Financial... ...ensures the necessary IT risk management and security... ...subject to applicable law, governing Plan document(s) and Company... ...Company is also committed to compliance with all fair employment practices...Work at officeLocal areaImmediate startRemote work$89k - $143.75k
...Development Job Sub Function: R&D Software/Systems Engineering Job Category: Scientific/Technology All Job Posting... ...design reviews with a cyber-lens. Performing periodic risk assessment of security vulnerabilities in software for the product by...Full timeTemporary workWork at officeLocal areaRemote workNight shift$141.6k - $212.4k
...Senior Principal Cloud Security Architect is the single... ...regulatory and enterprise risk requirements. This... ...through Platform Engineering and enforced through automation and governance mechanisms. The role partners... .... Risk, Audit & Compliance Support audits, regulatory...Work at officeLocal areaFlexible hours$150k - $175k
...? Join WWT today! What will you be doing? World Wide Technology, Inc. (WWT) is seeking a highly driven and experienced Cyber Security Specialist to join our dynamic Security Sales team. In this role, you will collaborate closely with cross-functional teams to develop...Full timeRemote workShift work- ...Cyber Security Architect (Azure Cloud Security) California, California, United States... ...environments. Threat Modeling and Risk Management: Conduct threat modeling... ...Bill of Materials (CBOM) and ensure compliance with security standards. Threat Modeling...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer - Governance Risk Compliance. Be the first to apply!
- senior application security engineer Encino, CA
- technology risk Encino, CA
- risk assurance Encino, CA
- information system security engineer
- staff security engineer
- senior application security engineer
- sr information security engineer
- security engineering manager
- electronic security engineer
- application security engineer


