Sr. Security Engineer - GRC Frameworks & AI Governance
$152k - $258kX
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.ABOUT THE ROLE:We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments.This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities.RESPONSIBILITIES:Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking.Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners.Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil.Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery.Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture.Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater.Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces).Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them.BASIC QUALIFICATIONS:Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure).Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks.Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring.Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation.PREFERRED SKILLS AND EXPERIENCE:10+ years of security compliance, GRC engineering, or technology audit-related experience.Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations.Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment.Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company.Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks.Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment.Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch.Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language.Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred.Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus.COMPENSATION AND BENEFITS:$152,000 - $258,000 USDBase salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.ITAR REQUIREMENTS:To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
$152k - $258k
...mission is to create AI systems that can... ...motivated, and focused on engineering excellence. This... ...an experienced Governance, Risk, and Compliance (GRC) Engineer focused on... ...fluency in data privacy frameworks (GDPR, CCPA), and... ...represent real security or business risk over...SeniorPermanent employmentFull timeTemporary work- ...resisted innovation. Join us!We are hiring a Senior AI Security Engineer II to lead the security, governance, and risk management of AI at BlinkRx, from... ...Responsibilities:Design and implement a multi-layer AI security framework spanning data classification, detection and...Senior
$130k
...roleWe are looking for a versatile Security Software Engineer to join our team and operate across... ...improving how we scale security through AI, automation, integrations, and... ...bounty experienceFamiliarity with GRC tools and frameworks#LI-Hybrid #LI-JL1A little about usAt Chime...SeniorFull timeWork at officeLocal areaRemote work$175k - $220k
...looking for a highly technical Senior Security Engineer who thrives on building security capabilities... ...through engineering, automation, and AI rather than relying solely on... ...engineering, Incident response, access governance, and security operations. Use software...SeniorFull timeWork at officeFlexible hours$175k - $220k
...looking for a highly technical Senior Security Engineer who is passionate about protecting data... ...challenges through engineering, automation, and AI rather than relying solely on... ...solutions for data discovery, classification, governance, access controls, monitoring, and...SeniorFull timeWork at officeFlexible hours$245.92k - $286.9k
Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.... ...GRC Engineer, you will be a cloud-aware governance, risk, and compliance expert... ...reimbursements.Artificial Intelligence (AI): Our AI Guidelines outline the acceptable...Full timeWork experience placementWork at officeFlexible hours$102.5k - $187.9k
...opportunityWith rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who... ...and regulatory or compliance frameworks (e.g., SOX, GDPR)Familiarity... ...technologies such as BTP, SAC, AI, or RPAWhat we offer youAt EY,...SeniorSummer holidayFlexible hoursShift work$102.5k - $187.9k
...With rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who... ...in alignment with defined risk frameworks Supporting SAP audit activities... ...technologies such as BTP, SAC, AI, or RPA What we offer you...SeniorSummer holidayFlexible hoursShift work- Legora is seeking a senior GRC/Security professional to own our assurance program end to end, including certifications, AI governance, and risk leadership. You’ll interface with auditors, regulators, and customer security teams, shaping controls that scale across products...Senior
$174k - $252k
Identify security issues and implement and design security... ...with security engineering, computer and network... ...security posture management frameworks that provide... ...visibility and automated governance over infrastructure risks... ...Data Protection (UDP), AI Model Oversight, Access...Senior- Basis AI, located in New York, is seeking a compliance expert to build and automate Governance, Risk, and Compliance (GRC) systems. The role demands ownership of compliance programs like SOC and ISO standards, utilizing AI to enhance efficiency. An ideal candidate has experience...SeniorWork at office
$195k - $240k
...Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary simulations... ..., and we expect our offensive engineers to build the tooling that... ...offensive tooling, automation frameworks, and engagement infrastructure...SeniorWork at office$167.5k - $226.3k
...for an experienced, hands-on Senior Security Engineer specializing in AI who will drive and execute the... ...critical role in AI system management and governance Evaluate existing AI security... ...vulnerabilities.Knowledge of AI/ML technologies, frameworks and platforms.Knowledge of...SeniorCasual workWork at officeLocal area$165k - $242k
...The Essential Cloud for AI™. Built for pioneers... ...The Enterprise Security team at CoreWeave is... ...As a Senior Security Engineer, Enterprise Security... ...detection, response, and governance Work with Security... ...security standards and frameworks (e.g., SOC 2, ISO 270...SeniorPermanent employmentFull timeTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$200k - $225k
...shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded,... ...risk assessments and enterprise AI governance decisions where Falcon's architecture... ...Claude Agent SDK or a comparable agent framework. Deep working knowledge of identity...SeniorFull timeLocal areaImmediate startRemote work$163.94k - $215.18k
Hi, we're Oscar. We're hiring a Senior Security AI Engineer 1 to join our Security Engineering team.Oscar is the first health insurance company... ...and implementation of a comprehensive AI security framework encompassing secure model adoption, training data pipelines...SeniorFull timeWork at officeFlexible hours$139k - $204k
...CoreWeave is The Essential Cloud for AI™. Built for pioneers by... ...of boom Work alongside security partners who hold a high bar... ...situations into risk and decision frameworks that drive action... ...information. To conform to U.S. Government export regulations applicable...SeniorPermanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$100k - $165k
...part of MetLife’s Global Security team, you’ll work... ...MetLife.The OpportunityThe Sr. AI & Agentic Security... ...responsible for defining, governing, and securing MetLife’... ...with AI platform engineering, MLOps, DevOps, IAM, and... ...AI security and risk frameworks such as NIST AI RMF, MITRE...SeniorFull timeTemporary workWork at officeLocal areaRelocation package3 days per week- ...re Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is... ...traditional application security and modern AI-driven engineering, ensuring that our "... ...Risk Assessment: Build risk assessment frameworks and deliver action plans to manage...SeniorFull timeWork experience placementWork at officeFlexible hours
$224k - $300k
...financial institutions, businesses, governments and developers, we are improving... ...value. THE WORK: As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest... ...posture, contributing to industry frameworks, engaging regulators, and publishing...SeniorFull timeWork at office- ...building the world’s most advanced AI-powered platform for... ...started. The Role As our first security hire, you’ll build our... ...blocker—earning trust across engineering and product by being a partner... ...you’ve started to think about governance, organizational resilience, and...Senior
$180k - $240k
...Role The Senior Corporate Security Engineer role is responsible for designing... ...Health is also building an AI-native operating model. This... ...-layer security, access governance, logging and usage monitoring... ...27001 and other applicable frameworks Support audit evidence collection...SeniorFull timeWork at officeLocal areaRemote work$192k - $240k
...control spend effortlessly. Brex’s AI-native automation and world-... ...you need to grow your career.Engineering at BrexEngineering at Brex is... ...teams span Software, Data, Security, and IT, and operate with high... ...Security, Corporate Engineering, GRC and IT and to improve security...SeniorWork at officeRemote workWork from home$147k - $210k
Build cross-functional AI and Large Language Model (LLM) tooling... ...research, defensive engineering, and mitigation strategies across... ...efficiency.Conduct deep-dive security research into Android vulnerabilities... ...LLM-based agentic workflows, frameworks, or automation tools...$200k - $220k
...AreNotion is the collaborative AI workspace where teams and... ...looking for a hands-on Corporate Security Engineer to own and improve the... ...closely with IT, Infrastructure, GRC, and Detection & Response to... ...usage at the endpoint, including governance of large language models, AI...Work at officeLocal area- ...Responsibilities Drive Ripple’s AI Security technical strategy and roadmap across AI systems... ...agency. Contribute to industry frameworks, regulatory engagement, and published research... ...Requirements ~10+ years of Security Engineering experience with depth in at least two...SeniorFull timeWork at office
$166k - $208k
...normalized" problem and the AI-native curiosity to... ...a highly skilled AI Security Research & Red team engineer to join our Red Team... ...Establish a rigorous framework for testing "Security... ...customers more secure. Governance, Risk, and Compliance (GRC): You will bridge the...Full timeLocal areaImmediate start- The ServiceNow Identity Security Engineer supports the implementation, configuration, and ongoing... ..., including Veza and related identity governance and authorization visibility capabilities... ...frontier projects at thecutting edgeof AI + Risk Management A collaborative...Remote work
$121k - $203k
...Description: The Senior Information Security Engineer oversees the security of the Firm's... ...Experience with or strong aptitude for AI-assisted development tools, LLMs, and agentic... ...of information systems security risk frameworks and server architecture - Knowledge...SeniorFull timeWork experience placementWork at office$320k - $405k
...interpretable, and steerable AI systems. We want AI to be safe... ...of committed researchers, engineers, policy experts, and business... ...systems. About The Team The Security Engineering team protects Anthropic... ...security, and secure frameworks. You will support one of these...SeniorWork at officeVisa sponsorshipFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Security Engineer - GRC Frameworks & AI Governance. Be the first to apply!
- security engineering manager New York, NY
- application security engineer New York, NY
- sr information security engineer New York, NY
- sr security engineer New York, NY
- entry level security engineer New York, NY
- senior application security engineer New York, NY
- staff security engineer New York, NY
- principal security engineer New York, NY
- physical security engineer New York, NY
- lead security engineer New York, NY


