Role at a glance
- Salary
- $152K – $258K/yr
- Location
- New York, New York, United States Palo Alto, California, United States
- Work arrangement
- On-site
- Employment
- Full-time
- Experience
- 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.
- Education
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
- Visa support
- To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident...
Spotted an issue?
We’ll check it against the original posting.
Role Summary
The GRC Engineer will own and scale SpaceXAI’s security and AI governance compliance posture across enterprise, commercial, and public-sector environments. The role focuses on designing controls, automating continuous compliance, supporting audit readiness, and partnering with engineering, legal, product, and leadership teams to manage risks in AI systems and cloud deployments.
What You'll Do
- Execute security compliance implementation and audits across SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act.
- Build and maintain Compliance-as-Code, policy-as-code, automated control validation, continuous evidence pipelines, and compliance...
- Operate and extend GRC platforms such as Vanta and integrate them with cloud, identity, and engineering tooling.
- Partner with engineering and architecture to embed compliance requirements into design reviews and translate framework obligations into...
- Develop and improve corporate policies, standards, procedures, and the company’s governance and AI management system posture.
- Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual...
Generated from the employer's posting. Verify important details before applying.
View full postingQualifications
Bachelor's degree in computer science, Information Security, Cybersecurity, or an engineering/STEM field; 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities; experience implementing and maintaining security compliance frameworks in AWS, GCP, or Azure cloud environments; expert-level working knowledge of several listed security frameworks; experience with Compliance-as-Code practices and GRC automation tooling; ability to evaluate control objectives against IT and cloud configurations and work with engineers on remediation.
Required
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field
- 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities
- Experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure)
- Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001
- Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar)
- Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation
Preferred
- 10+ years of security compliance, GRC engineering, or technology audit-related experience
- Hands-on experience implementing technical controls such as IAM, logging and monitoring, encryption, and infrastructure hardening
- Experience integrating compliance checks into CI/CD pipelines
- Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations
- Working knowledge of HIPAA privacy and security rules
- Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination
- Strong understanding of AI ethics and AI governance frameworks such as NIST AI RMF, ISO 42001, and EU AI Act
- Working knowledge in data privacy frameworks such as GDPR and CCPA
Original job description
Content provided by the employer
Original job description
Content provided by the employer
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
ABOUT THE ROLE:
RESPONSIBILITIES:
- Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking.
- Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners.
- Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil.
- Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery.
- Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture.
- Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater.
- Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces).
- Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
- Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them.
BASIC QUALIFICATIONS:
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
- 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.
- Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure).
- Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks.
- Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring.
- Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation.
PREFERRED SKILLS AND EXPERIENCE:
- 10+ years of security compliance, GRC engineering, or technology audit-related experience.
- Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
- Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations.
- Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment.
- Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company.
- Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks.
- Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment.
- Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch.
- Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language.
- Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred.
- Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus.
COMPENSATION AND BENEFITS:
$152,000 - $258,000 USD
Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.
ITAR REQUIREMENTS:
- To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.
SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
About the company
xAI
Large Enterprise
xAI is a cutting-edge technology company focused on developing advanced artificial intelligence solutions to enhance human capabilities and optimize decision-making processes. Founded by a team of leading experts in AI and machine learning, xAI aims to address complex challenges across various industries, including healthcare, finance, and transportation. By prioritizing ethical AI development, the company is committed to creating innovative tools that empower organizations to harness the full potential of artificial intelligence while ensuring transparency and accountability.
xAI is a cutting-edge technology company focused on developing advanced artificial intelligence solutions to enhance human capabilities and optimize decision-making processes. Founded by a team of leading experts in AI and machine learning, xAI aims to address complex challenges across various industries, including healthcare, finance, and transportation. By prioritizing ethical AI development, the company is committed to creating innovative tools that empower organizations to harness the full potential of artificial intelligence while ensuring transparency and accountability.