
Senior GRC Lead
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in United States.
• Take ownership of and lead Jasper’s compliance audits, encompassing SOC 2, ISO 27001, and similar frameworks, from preparation to certification, with a trajectory toward ISO 42001.
• Collaborate with the Legal team to support GDPR and broader privacy compliance initiatives.
• Streamline overlapping requirements across various frameworks and establish a unified source of truth for control ownership.
• Act as a subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales processes.
• Address customer security questionnaires and assist sales and legal teams throughout the due diligence process.
• Sustain and enhance the risk register, focusing on risk identification, scoring, and remediation tracking.
• Oversee vendor and third-party risk assessments and manage the vendor security review process.
• Take charge of policy management, which includes drafting, reviewing, and updating security and compliance policies.
• Collaborate with Security, Legal, Product, Engineering, GTM, and People to integrate compliance and governance requirements.
• Automate compliance workflows, including the collection of audit artifacts, internal security compliance reviews, and ongoing monitoring.
• Lead, enhance, and assist in implementing AI governance across the organization and its products.
• Report directly to the Director of Security.
• Proficient understanding of AI concepts, including LLMs, agents, copilots, tokens, credits, context windows, RAG, and data governance.
• Over 8 years of experience in Governance, Risk & Compliance, preferably within a SaaS environment.
• In-depth knowledge of SOC 2 Type II, ISO 27001, NIST CSF, and familiarity with at least one regulatory framework such as GDPR, CCPA, or HIPAA.
• Expertise in modern cloud-native web application development practices and associated security best practices, particularly with GCP and frontier AI platforms.
• Experience with GRC tools like Vanta, Drata, OneTrust, or similar solutions.
• Proven track record of managing a risk register and vendor risk programs.
• Excellent cross-functional communication skills, with the ability to convey technical issues to non-technical teams.
• Experience utilizing AI agents, tools, and platforms to automate workflows and develop tools, demonstrating sound judgment in responsible AI application.
• Previous experience in a startup or rapidly growing SaaS company.
• Relevant certifications such as CISA, CISSP, CRISC, or equivalent.
• Experience in scoping or pursuing ISO 42001 or other AI governance frameworks.
• Practical experience with agentic coding tools such as Cursor, Claude Code, or Copilot.
• Working knowledge of Python; capable of modifying and executing scripts, creating automations, and delivering small tools from start to finish.
• Candidates must reside in the continental United States.
• Legal authorization to work in the United States, along with a minimum of two years of valid U.S. work authorization.
• Comprehensive Health, Dental, and Vision coverage starting from the first day for employees and their families.
• 401(k) plan with up to 2% company matching.
• Participation in equity grant programs.
• Flexible PTO policy.
• Annual FlexExperience budget of $900.
• Annual FlexWellness program budget of $1,800.
• Generous allowance for home office setup.
• Annual learning and development stipend of $1,500.
• 16 weeks of paid parental leave.
Terac
DSV - Global Transport and Logistics
Kin Insurance
Summit Therapeutics, Inc.
Get handpicked remote jobs straight to your inbox weekly.