GRC Manager

Baseten

San Francisco (CA)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity
Medical/Dental/Vision
Flexible PTO
Parental leave
Fertility stipend
401(k)
Learning opportunities

Job summary

Baseten in San Francisco seeks an experienced GRC Manager to build and enhance Baseten’s security governance, compliance, and privacy programs across our platform.

You will collaborate with Engineering, Operations, Legal and leadership to design policies, manage audits, and implement controls aligned with SOC 2, ISO 27001/27701, HIPAA, and FedRAMP. You’ll drive risk assessment, third‑party risk, and training, maturing our compliance program as we scale.

Qualifications

  • 5+ years in GRC, security compliance, or information security in SaaS/cloud-native environments.
  • Strong understanding of security frameworks and standards (SOC 2, ISO 27001, NIST, GDPR).
  • Proven track record managing compliance audits and certifications end-to-end.
  • Experience with access management concepts and third-party risk.
  • Experience collaborating with technical and non-technical stakeholders to implement controls.
  • Excellent organization, documentation, and communication skills.

Responsibilities

  • Design, implement, and maintain security governance frameworks, policies, and procedures.
  • Build and manage company-wide risk assessment programs.
  • Lead audits and certifications for SOC 2, ISO 27001/27701, HIPAA, FedRAMP.
  • Coordinate external audits and evidence collection.
  • Oversee third‑party security assessments and vendor risk.
  • Partner with Engineering, Product, and Operations to embed compliance in processes.
  • Support customer security questionnaires and due diligence efforts.
  • Deliver security and compliance training to the organization.
  • Drive continuous improvement of risk management programs.

Skills

GRC
Security frameworks
Audit management
Cross-functional
Documentation

Tools

Vanta
Drata
Secureframe

Job description

ABOUT BASETEN

Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F, led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products.

THE ROLE

We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance.

In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow.

RESPONSIBILITIES
  • Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.

  • Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.

  • Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations.

  • Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.

  • Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.

  • Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.

  • Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.

  • Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.

  • Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.

REQUIREMENTS
  • 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.

  • Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.

  • Proven track record managing compliance audits and certification programs end-to-end.

  • Experience with access management concepts, third-party risk

  • Experience working cross-functionally with technical and non-technical stakeholders to implement compliance and security controls.

  • Excellent organizational, documentation, and communication skills with attention to detail.

  • Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.

NICE TO HAVE
  • Experience with cloud security compliance in AWS or GCP environments.

  • Hands-on experience using GRC tools (e.g., Vanta, Drata, Secureframe, Anecdotes).

  • Understanding of AI/ML security considerations, data privacy, and model governance.

  • Previous experience building and scaling compliance programs in an early-stage or rapidly growing startup.

  • Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer).

BENEFITS
  • Competitive compensation, including meaningful equity.

  • 100% coverage of medical, dental, and vision insurance for employee and dependents

  • Flexible PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!)

  • Paid parental leave

  • Fertility and family-building stipend through Carrot

  • Company-facilitated 401(k)

  • Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.

At Baseten, we are committed to fostering a diverse and inclusive workplace. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status.

We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example, the requirements of the San Francisco Fair Chance Ordinance, where applicable).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Manager
GRC Manager

Neura Market • San Francisco (CA)

On-site
USD 140,000 - 190,000
Equity
Medical, dental, and vision coverage
Flexible PTO
+4
GRC Manager
GRC Manager

The Consensus • New York (NY)

On-site
USD 130,000 - 180,000
Competitive compensation
Equity
Medical/Dental/Vision insurance
+1
GRC Manager
GRC Manager

Baseten • New York (NY)

On-site
USD 150,000 - 250,000
Competitive compensation
Medical, dental, vision insurance
Flexible PTO
+4
GRC Manager
GRC Manager

baseten • United States

On-site
USD 140,000 - 210,000
Remote-first environment
Annual team summits
Unlimited PTO
+2
Security Engineer
Security Engineer

The Consensus • San Francisco (CA)

On-site
USD 120,000 - 150,000
100% medical, dental, and vision insurance
Flexible PTO policy
Paid parental leave
+2
Head of IT
Head of IT

AI Chopping Block • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 280,000
Competitive compensation & equity
Full health insurance for employee & +
Flexible PTO including Winter Break
+4
Head of IT
Head of IT

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 280,000
Equity
Medical dental vision coverage for 1
Flexible PTO including Winter Break
+3
Head of IT
Head of IT

Baseten • San Francisco (CA), Northern (KY)

On-site
USD 180,000 - 280,000
Competitive equity
Medical, dental, vision coverage for员工
Software Engineer - Enterprise Platform
Software Engineer - Enterprise Platform

BaseTen • New York (NY), San Francisco (CA)

On-site
USD 150,000 - 230,000
Medical, dental, vision insurance for
Dependent coverage
Flexible PTO incl. Winter Break
+4
Head of IT
Head of IT

Triwill Group • San Francisco (CA)

On-site
USD 180,000 - 280,000
Equity
Medical, dental, vision coverage for员工
Flexible PTO
+4