Jobedly Post a Job

Governance, Risk and Compliance Lead

Thinking Machines Lab · San Francisco
Full-timeTechnicalConstruction$179,000–$241,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Governance Risk Compliance Lead role

Governance Risk Compliance Lead positions focus on delivering results in their domain. This page aggregates open Governance Risk Compliance Lead roles and what employers typically expect.

Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence. We're building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals. We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything. About the Role We're looking for a GRC Lead who personally drives our certifications (SOC 2, ISO 27001, FedRAMP and others as we grow) from scoping through audit close, and runs our compliance processes day to day. You'll collect the evidence, write the control documentation, and sit across from the auditor yourself. You'll work closely with security, legal, safety, and engineering to answer compliance and risk questions directly, using your own technical understanding of how our systems work. Day to day, you'll be managing audits, controls, and risk assessments. Alongside that, you'll be building the roadmap for what this function needs to look like in a year. What You'll Do Own our certification roadmap end to end: scope each certification, build the control set, collect and organize evidence, and represent TML directly to auditors through to close. Manage recurring compliance processes on a set cadence: control testing, audit prep and response, risk register maintenance, and policy attestations. Answer compliance and risk questions from engineering, security, and product teams directly, by building enough technical fluency across our infrastructure, model deployment, and data handling to do so without escalating every question. Track regulatory and framework requirements relevant to an AI company (GDPR, EU AI Act, and similar) and translate them into specific, actionable controls. Identify gaps in current compliance coverage as the company adds new products, infrastructure, or jurisdictions, and propose what needs to change before it becomes a blocker. Build and maintain the tooling and documentation that make the next audit cycle faster than the last one. Plan a multi-quarter roadmap for the GRC function itself, while continuing to personally run the certifications and audits already on the books. Skills and Qualifications Minimum qualifications: 7+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines. Experience leading a SOC 2, ISO 27001, FedRAMP or comparable certification from scoping through audit close. Hands-on experience collecting audit evidence and writing control documentation. Experience managing a recurring compliance process, such as control testing, risk register maintenance, or policy attestations. Experience learning new technical domains quickly and translating them for non-technical stakeholders. Preferred qualifications: We encourage you to apply even if you don't meet all preferred qualifications. Background as a software engineer or in a technical engineering role, now applied to GRC, evidenced by scripts, tools, or automations you've personally built for evidence collection, control testing, or audit workflows. Experience translating complex compliance requirements into scalable automation using AI agents and custom built tooling. Experience growing a GRC function's capability (new certifications, tooling, or processes) as a company scaled. You'll Thrive in This Role if You want to run the certification yourself, end to end. You're the one in the room with the auditor, walking through evidence. You can hold this week's deadlines and next year's roadmap at the same time. Logistics Location: This role is based in San Francisco, California. Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $225,000 - $350,000. Visa sponsorship: We sponsor visa…

Salary estimate

$179,000 – $241,000/yr
Provided by the employer.

Skills for this role

PytorchSecurityAutomation

Resume tips for Governance Risk Compliance Lead applicants

Interview preparation

Prepare concrete STAR-format stories that show Governance Risk Compliance Lead outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Governance Risk Compliance Lead problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Thinking Machines Lab

Thinking Machines Lab is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles