Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer - Governance Risk Compliance

$100k - $228k

Xai

Security Engineer - Governance Risk Compliance

New York, NY; Palo Alto, CA; Washington, D.C.

About xAI

xAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

About The Role:

We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) team member as we expand into government and public sector applications of AI. This critical role will ensure that xAI operates within regulatory, ethical, operational, and federal boundaries while fostering a culture of integrity and resilience. You will collaborate with cross-functional teams to safeguard our mission-driven work in AI development and deployment, including support for sensitive and classified environments.

Responsibilities:
  • Execute security compliance implementation and audits (e.g., ISO 27001/42001, SOC2, FedRAMP HIGH, DoD Cloud Computing SRG IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
  • Work with 3PAOs (Third-Party Assessment Organizations) and federal government Authorizing Officials (AOs) to achieve compliance certifications, reports, and Authorized to Operate (ATO) status.
  • Identify, assess, and prioritize risks related to AI operations, cybersecurity, regulatory compliance, intellectual property, and cloud deployments.
  • Design and implement risk mitigation strategies, including monitoring systems, contingency plans, vulnerability scans, Plan of Action and Milestones (POAMs), and STIGs.
  • Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures throughout the project lifecycle.
  • Serve as a liaison between system owners, security personnel, and cross-functional teams to facilitate effective communication, collaboration, and control implementation.
  • Lead Risk Management Assessment and Authorization (A&A) processes, cloud system risk assessments, compliance reviews for new products/changes/features, and process enhancements.
  • Conduct regular risk assessments, scenario analyses, and proactive evaluations of emerging threats, certifications, requirements, and technologies in the AI landscape.
  • Oversee audits, certifications, third-party assessments, and vulnerability management to maintain compliance and operational credibility.
  • Act as a subject matter expert, providing guidance on risk, compliance, and cybersecurity matters; translate business and technical risks for leadership.
  • Create and present regular reports on GRC performance, risks, and compliance status to senior leadership and stakeholders.
Basic Qualifications:
  • Previous systems engineering experience strongly preferred
  • Must have the ability to evaluate control objectives with IT configurations
  • Bachelor's degree in Computer Science Information Security, Cybersecurity, or a related field
  • Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.
  • 3+ years of experience in governance, risk management, compliance, or technology audit roles.
  • Proven expertise in regulatory frameworks, data privacy, cybersecurity, and federal compliance standards, preferably in a technology, cloud, or AI-driven environment.
  • Strong understanding of AI ethics, emerging technologies, Risk Management Framework (RMF), and their associated risks.
  • Experience with vulnerability management, POAMs, STIG implementation, and cloud security controls.
  • Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to balance innovation, oversight, and taking projects from conception to launch.
  • Excellent communication, stakeholder management, and translation skills, with experience influencing cross-functional teams and communicating risks to leadership.
  • Ability to thrive in a fast-paced, dynamic environment and adapt to evolving priorities.
Preferred Skills And Experience:
  • Experience in the tech or AI industry, particularly with startups, innovative organizations, or government/public sector engagements.
  • Deep expertise maintaining frameworks such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, and STIG/RMF policies (including validation via ACAS and similar tools).
  • Familiarity with ISO 27001, ISO 42001, NIST, SOC 2, or similar compliance frameworks.
  • Background in managing third-party risk, vendor compliance programs, or federal assessments.
  • Understanding of cybersecurity controls for cloud service providers.
  • Knowledge of government cloud services and evolving certification programs.
  • 5+ years of security compliance or technology audit-related.
Compensation And Benefits:

$100,000 - $228,000 USD

Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

xAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Engineer - Governance Risk Compliance in Encino, CA vacancy
  • $280k - $300k

     ...Sr. Director , Security Software EngineeringSr. Director , Security...  ...a team of 3-4 security engineers, focusing on recruitment, mentoring...  ...state and local laws governing nondiscrimination in...  ...Security Analyst I (Governance, Risk & Compliance)ERP Business Systems Analyst... 
    Suggested
    Local area
    Remote work
    Flexible hours
    Shift work
    Night shift
    Weekend work

    INSPYR Solutions

    Beverly Hills, CA
    18 hours ago
  • $100k - $172.5k

     ...: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture...  ...for a Principal Product Security Engineer to be located in Danvers, MA or...  ...you are eager to leverage your security risk and compliance skills to make a difference and directly... 
    Suggested
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Northridge, CA
    4 days ago
  •  ...Senior Network Security Engineer-W2-GC-USC Job Location: Hybrid. Located in one of our hub cities, with preference for CST – 10% onsite...  ...plus. Experience with managing projects to include task delegations, documentation, risk management, and technical ownership.... 
    Suggested
    Remote work

    Kaav Inc.

    Encino, CA
    4 days ago
  • Job Title For positions that will be based in CA, the annual salary range for this position is below. Actual salaries may vary based on numerous factors including, among other things, an individual applicant's experience and qualifications for the position. This range...
    Suggested

    Ripple

    Encino, CA
    1 day ago
  • $112k - $150.1k

     ...The Global Information Security (GIS) organization strives...  ...cyber threats that present risk to The Walt Disney Company....  ...Security Architecture and Engineering team is Disney’s trusted authority...  ...objectives. Support governance and compliance efforts by aligning solutions... 
    Suggested
    Work experience placement

    The Walt Disney Company

    Burbank, CA
    1 day ago
  •  ...Job Description Title: Sr. Product Security Engineer Location: Remote Ekman Associates is a management consulting firm that specializes in...  ...Security policies and standards in collaboration with technology risk; AI/Agent SME: Provide AI/Agent subject matter expertise for... 
    Remote work

    Ekman Associates

    Woodland Hills, CA
    3 days ago
  • $162.35k - $199.85k

     ...Sr. AI Security Engineer The Digital Threat Management (DTM) team is looking for a Sr. AI Security...  ...strategy, regulatory exam readiness, risk reduction, and overall data trust. In...  ...transformation initiatives, ensuring governance is built into system modernization, cloud... 

    Universal Music Group

    Woodland Hills, CA
    1 day ago
  • $160k - $200k

     ...THE ROLE The Principal Data Security Architect / Governance will be a pivotal leader in establishing...  ...adoption of best practices, and driving compliance within our AWS and Databricks-centric...  ...management. Compliance and Risk Management: Serve as the primary subject... 
    Local area
    Worldwide
    Flexible hours

    Live Nation Entertainment

    Beverly Hills, CA
    18 hours ago
  •  ...integration Cloud platforms (AWS, Azure, or GCP) Compliance frameworks (SOX, PCI-DSS) Responsibilities: Design...  ...Enforce privileged access policies and security standards Support audits, access reviews, and risk assessments Troubleshoot platform issues and drive... 
    H1b
    Remote work

    aKube, Inc.

    Burbank, CA
    3 days ago
  •  ...Title: Sr. Security Engineer Location: 4 days onsite Monday - Thursday. 1 Day remote Friday....  ...5.) Demonstrated experience supporting compliance and audit processes (SOX, PCI-DSS, or similar...  ...best practices. - Lead PAM-related risk assessments, access reviews, and audit... 
    Permanent employment
    Work experience placement
    Remote work

    RIT Solutions, Inc.

    Burbank, CA
    3 days ago
  • $90 - $97 per hour

     ...Senior Security Engineer - PAM Software Resources has an immediate, contract job opportunity...  ...industry best practices. - Lead PAM-related risk assessments, access reviews, and audit...  .... - Demonstrated experience supporting compliance and audit processes (SOX, PCI-DSS, or... 
    Permanent employment
    Contract work
    Temporary work
    Work experience placement
    Immediate start

    Software Resources

    Burbank, CA
    2 days ago
  •  ...solve the nation's most complex security challenges. We strive for an...  ...document system audits and risk analysis. Manage and execute...  ...(ConMon) tasks to ensure compliance throughout the system lifecycle...  ...applicants will be subject to a government security investigation and... 
    Full time
    Work experience placement
    Local area
    Immediate start
    Remote work
    Flexible hours

    Arete Associates

    Northridge, CA
    4 days ago
  •  ...Senior Principal Cyber Engineer Forcepoint simplifies security for global businesses and governments. Forcepoint's all-in-one, truly cloud-native platform makes it easy to adopt Zero Trust and prevent the theft or loss of sensitive data and intellectual property no... 
    Full time
    Remote work

    Forcepoint

    Encino, CA
    1 day ago
  •  ...Cyber Defense Specialist, Consultant The Information Security team is looking for a certified security professional to join our fast...  ...into actionable continuous improvement opportunities to reduce risk and improve effectiveness Qualifications Your Knowledge... 
    Work at office
    2 days per week

    Blue Shield Of California

    Woodland Hills, CA
    3 days ago
  •  ...Information Systems Security Manager (ISSM) Join Northrop Grumman on our continued mission...  ...processes to ensure mitigation of risks and supports obtaining certification and...  ...Assist in the implementation of the required government policy, make recommendations on process... 
    For contractors
    Local area

    Phenom People

    Northridge, CA
    3 days ago
  • $146.28k - $219.42k

     ...Cybersecurity Senior Advisor – Offensive Security & Exposure Management...  ..., and delivering measurable risk reduction across the...  ...partnering across security, engineering, and business teams to identify...  ...Management Legal Regulations, Compliance and Investigations Operations... 
    Work at office
    2 days per week
    1 day per week

    Elevance Health

    Woodland Hills, CA
    18 hours ago
  • $168k - $195k

     ...Senior Cyber Security Engineer - Siem And Automation At Corebridge Financial...  ...ensures the necessary IT risk management and security...  ...subject to applicable law, governing Plan document(s) and Company...  ...Company is also committed to compliance with all fair employment practices... 
    Work at office
    Local area
    Immediate start
    Remote work

    Corebridge Financial

    Woodland Hills, CA
    1 day ago
  • $89k - $143.75k

     ...Development Job Sub Function: R&D Software/Systems Engineering Job Category: Scientific/Technology All Job Posting...  ...design reviews with a cyber-lens. Performing periodic risk assessment of security vulnerabilities in software for the product by... 
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    Night shift

    Johnson & Johnson

    Northridge, CA
    3 days ago
  • $141.6k - $212.4k

     ...Senior Principal Cloud Security Architect is the single...  ...regulatory and enterprise risk requirements. This...  ...through Platform Engineering and enforced through automation and governance mechanisms. The role partners...  .... Risk, Audit & Compliance Support audits, regulatory... 
    Work at office
    Local area
    Flexible hours

    Mini Med

    Northridge, CA
    1 day ago
  • $150k - $175k

     ...? Join WWT today! What will you be doing? World Wide Technology, Inc. (WWT) is seeking a highly driven and experienced Cyber Security Specialist to join our dynamic Security Sales team. In this role, you will collaborate closely with cross-functional teams to develop... 
    Full time
    Remote work
    Shift work

    World Wide Technology

    Northridge, CA
    4 days ago
  •  ...Cyber Security Architect (Azure Cloud Security) California, California, United States...  ...environments. Threat Modeling and Risk Management: Conduct threat modeling...  ...Bill of Materials (CBOM) and ensure compliance with security standards. Threat Modeling... 
    Contract work

    Pipe Recruit

    Encino, CA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer - Governance Risk Compliance. Be the first to apply!