GRC Lead for AI Security: SOC 2 & ISO 27001

Replit

Foster City (CA)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401(k) program
Health insurance
Dental insurance
Vision insurance
Life insurance
Paid leave
Flexible time off
Commuter benefits
Wellness stipend
Autonomous work environment
In-office setup reimbursement
Quarterly team gatherings
In-office amenities

Job summary

Replit is seeking a Risk & Compliance lead to own the certification and audit program end to end, including SOC 2, ISO 27001, and future frameworks. You will manage the master security risk register, monitor compliance in real-time, and partner with Engineering to ensure controls work in practice.

You will also support GDPR/privacy initiatives with Legal/Privacy teams. The role reports to Head of Security GRC and lives in a high-impact security environment at the Foster City, CA office, with

Qualifications

  • 8+ years in security compliance, IT audit, or GRC roles.
  • Own at least one SOC 2 and/or ISO 27001 certification cycle.
  • Working knowledge of SOC 2, ISO 27001, and NIST CSF.
  • Hands-on experience authoring or maintaining ISMS/SSP documentation.
  • Experience owning a formal risk register and reporting to leadership.
  • Experience with GRC automation platforms and external auditors.
  • Familiarity with GDPR/privacy fundamentals.

Responsibilities

  • Own end-to-end certification roadmap (SOC 2 Type II, ISO 27001, future ISO 42001).
  • Manage relationships with external auditors and schedule annual audits.
  • Maintain master security risk register including scoring and remediation.
  • Build and maintain continuous compliance monitoring reflecting real-time state.
  • Own audit artifacts (ISMS docs, SoA, risk assessments, SSPs).
  • Run audits, readiness assessments, and track remediation to closure.
  • Support GDPR/privacy compliance with Legal/Privacy team.
  • Collaborate with GRC Engineer on automation vs manual review.
  • Track and report compliance posture and audit findings to leadership.

Skills

Security compliance
GRC
Audit management
ISMS/SSP
GDPR/privacy
Auditors coordination
Technical control discussion

Tools

Anecdotes
Vanta
Drata

Job description

Replit is seeking a Risk & Compliance lead to own the certification and audit program end to end, including SOC 2, ISO 27001, and future frameworks. You will manage the master security risk register, monitor compliance in real-time, and partner with Engineering to ensure controls work in practice.

You will also support GDPR/privacy initiatives with Legal/Privacy teams. The role reports to Head of Security GRC and lives in a high-impact security environment at the Foster City, CA office, with

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote GRC Lead — AI Security & Compliance
Remote GRC Lead — AI Security & Compliance

Applied Methods Ltd • Foster City (CA)

On-site
USD 210,000 - 270,000
Competitive Salary
401(k) with 4% match
Health, Dental, Vision, Life
+5
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)
GRC Lead: AI Compliance Certifications (SOC 2, ISO 27001)

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1
Risk and Compliance Lead
Risk and Compliance Lead

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
Senior GRC Program Lead - SOC 2, GDPR & Security
Senior GRC Program Lead - SOC 2, GDPR & Security

Tandem Inc. • Draper (UT)

Hybrid
USD 110,000 - 170,000
On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
+2
Remote GRC & Security Compliance Lead
Remote GRC & Security Compliance Lead

PVH (Tommy Hilfiger/Calvin Klein) • United States

On-site
USD 140,000 - 210,000
Remote-first environment
Annual team summits
Unlimited PTO
+2
Senior GRC Lead for AI – End-to-End Certifications & Audits
Senior GRC Lead for AI – End-to-End Certifications & Audits

Thinking Machines Lab • San Francisco (CA)

On-site
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Parental leave
+1
Senior GRC Director: FedRAMP, ISO 27001 & SOC 2 Lead
Senior GRC Director: FedRAMP, ISO 27001 & SOC 2 Lead

Anomali • Redwood City (CA)

Hybrid
USD 180,000 - 230,000
GRC Lead: AI Privacy & Security Compliance Architect
GRC Lead: AI Privacy & Security Compliance Architect

Perplexity • San Francisco (CA)

On-site
USD 150,000 - 210,000
Senior Security GRC Leader (Risk & Compliance)
Senior Security GRC Leader (Risk & Compliance)

Applied Intuition • Sunnyvale (CA)

On-site
USD 180,000 - 260,000
GRC Analyst | AI Security & Compliance
GRC Analyst | AI Security & Compliance

Zip • San Francisco (CA)

On-site
USD 95,000 - 150,000
Start-up equity
Health, vision & dental coverage
Catered meals
+5