Sr. Security Engineer - GRC Frameworks & AI Governance

$53k - $800k Palo Alto, CA; New York, NY; Washington, DC

Posted 5d ago

Job Location

Palo Alto, CA; New York, NY; Washington, DC

Tech Stack

Remote Work Policy

On-site

Categories

Applied AI Engineer

About the job

SpaceXAI is seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to scale our security and AI governance compliance posture. You will set organizational standards, design and implement controls, and automate compliance processes to ensure safe and rapid development. The ideal candidate will possess deep knowledge of modern security and AI frameworks, translate control requirements into technical implementations, and integrate compliance into architecture and CI/CD pipelines. You will collaborate with engineering, legal, product, and leadership teams to maintain audit readiness for AI systems across various environments.

Responsibilities

  • Own and execute security compliance implementation and audits across frameworks like SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act.
  • Build and maintain Compliance-as-Code and continuous compliance capabilities, including automated control validation and evidence pipelines.
  • Operate and extend GRC platforms (e.g., Vanta) and integrate them with cloud, identity, and engineering tooling.
  • Partner with engineering and architecture to embed compliance requirements early in design reviews and translate framework obligations into technical control narratives.
  • Develop, maintain, and improve corporate policies, standards, and procedures for governance and AI management.
  • Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, and cloud deployments.
  • Lead risk assessments and compliance reviews for new products, model deployments, and architectural changes, focusing on AI system risks.
  • Cultivate relationships with external auditors, assessors, and regulators, serving as the liaison between auditors and internal teams.
  • Champion a culture of security and compliance across the company by educating teams on control objectives.

Requirements

  • Bachelor's degree in computer science, Information Security, Cybersecurity, or an engineering/STEM field.
  • 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.
  • Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure).
  • Expert-level working knowledge of SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001.
  • Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata).
  • Ability to evaluate control objectives against real IT and cloud configurations and work with engineers on remediation.

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.