GRC Manager

US Health Partners, LLC

San Francisco (CA)

On-site

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Equity eligibility
Flexible PTO

Job summary

Baseten is seeking an experienced GRC Manager to build and strengthen our security governance, risk, and compliance programs. You will work with Engineering, Product, Security, and Legal to define requirements, implement controls, and drive audits and certifications.

This role emphasizes customer assurance, vendor risk, and program maturity in a fast-growing SaaS environment. You will lead governance frameworks, risk assessments, and ongoing policy development while collaborating with executive

Qualifications

  • BS degree in CS/CE/MIS or equivalent.
  • 5+ years in GRC, security or information security roles (SaaS/cloud).
  • Knowledge of SOC 2, ISO 27001, NIST, GDPR.
  • Proven track record managing audits and certifications end-to-end.
  • Experience working with executives in Enterprise orgs.
  • Cross-functional collaboration to implement controls.
  • Ability translating regulatory objectives into product deliverables.
  • Strong communication of security posture to technical and non-technical audiences.

Responsibilities

  • Translate regulatory and customer requirements into product requirements and controls with Engineering and Product.
  • Design and maintain security governance policies and procedures.
  • Build and manage company-wide risk assessment program.
  • Support compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other standards.
  • Coordinate external audits and certification processes; ensure evidence collection and remediation.
  • Oversee third-party security assessments and vendor risk management.
  • Collaborate with cross-functional teams to embed compliance in operations.
  • Support customer security questionnaires and due-diligence requests.
  • Deliver security and compliance training; raise company-wide awareness.
  • Drive continuous improvement of the GRC program.

Skills

GRC experience
Security compliance
Audit management
Cross-functional collaboration
Regulatory frameworks
Product compliance
Security controls
Customer questionnaires

Education

Bachelor's degree in CS/CE/MIS

Tools

Vanta
Drata
Secureframe
Anecdotes

Job description

ABOUT BASETEN

Baseten powers mission-critical inference for the world’s most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma, and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We’re growing quickly and recently raised our $1.5B Series F, led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to ship AI products.

THE ROLE

We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance.

You’ll work closely with Engineering, Product, Security, and Legal to define compliance requirements, assess platform capabilities, and drive implementation from initial scoping through validation. You will also lead customer assurance efforts, helping customers understand our security architecture and compliance posture while bringing their requirements back into product planning.

Alongside this product focus, you’ll contribute to Baseten’s broader GRC program, including governance, risk management, audits, vendor assessments, and security awareness.

RESPONSIBILITIES
  • Product Compliance: Translate regulatory, framework, and customer requirements into clear product requirements and technical controls, partnering with Engineering and Product to build compliance into platform design and development.

  • Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.

  • Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.

  • Compliance Operations: Support efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations.

  • Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.

  • Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.

  • Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.

  • Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.

  • Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.

  • Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.

REQUIREMENTS
  • BS Degree in CS, CE, MIS or equivalent field

  • 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.

  • Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.

  • Proven track record managing compliance audits and certification programs end-to-end.

  • Experience working directly with leaders and executives within Enterprise organizations

  • Experience working cross-functionally with technical and non-technical stakeholders to implement compliance and security controls.

  • Proven experience driving product compliance by translating regulatory and customer requirements into actionable product controls with Engineering and Product

  • Experience defining project requirements and driving implementation by translating compliance objectives into clear deliverables, coordinating cross-functional stakeholders, and managing execution through completion.

  • Experience responding to customer security questionnaires and leading customer security interviews, with the ability to clearly communicate security controls, compliance posture, and risk management practices to technical and nontechnical audiences.

  • Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.

NICE TO HAVE
  • Experience with cloud security compliance in AWS or GCP environments.

  • Hands-on experience using GRC tools (e.g., Vanta, Drata, Secureframe, Anecdotes).

  • Understanding of AI/ML security considerations, data privacy, and model governance.

  • Previous experience building and implementing security controls in an early-stage or rapidly growing startup.

  • Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer).

BENEFITS
  • Competitive compensation, including meaningful equity

  • (U.S. only) 100% coverage of medical, dental, and vision insurance for employee and dependents

  • Flexible PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year’s Day!)

  • Paid parental leave

  • Fertility and family-building stipend through Carrot

  • (U.S. only) Company-facilitated 401(k)

  • Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.

At Baseten, we are committed to fostering a diverse and inclusive workplace. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status.

We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example, the requirements of the San Francisco Fair Chance Ordinance, where applicable).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Manager
GRC Manager

Candidate • San Francisco (CA)

On-site
USD 180,000 - 240,000
Competitive equity
US medical/dental/vision (100%)
Flexible PTO including Winter Break
+4
Security Engineer
Security Engineer

The Consensus • San Francisco (CA)

On-site
USD 120,000 - 150,000
100% medical, dental, and vision insurance
Flexible PTO policy
Paid parental leave
+2
Software Engineer - Identity and Authorization
Software Engineer - Identity and Authorization

AI Chopping Block, Inc. • San Francisco (CA), Northern (KY)

On-site
USD 210,000 - 320,000
Competitive compensation
Equity
Medical, dental, vision insurance
+4
Software Engineer - Identity & Authorization
Software Engineer - Identity & Authorization

Baseten • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 260,000
Competitive pay
Medical coverage
Flexible PTO
+4
Head of Real Estate & Workplace
Head of Real Estate & Workplace

Baseten • San Francisco (CA)

On-site
USD 190,000 - 240,000
Competitive compensation
Meaningful equity
Medical/dental/vision insurance (US)
+4
Engineering Manager, Cloud Platform
Engineering Manager, Cloud Platform

The Consensus • San Francisco (CA)

On-site
USD 150,000 - 200,000
100% coverage of medical, dental, and vision insurance for employee and dependents
Flexible PTO policy
Paid parental leave
Head of Environment
Head of Environment

The Consensus • San Francisco (CA)

On-site
USD 250,000 - 350,000
Equity
Medical/Dental/Vision
Flexible PTO
+4
SRE
SRE

The Consensus • New York (NY)

On-site
USD 110,000 - 140,000
Competitive compensation
100% insurance coverage
Flexible PTO policy
+3
Executive Assistant to CRO & Head of Strategic Sales
Executive Assistant to CRO & Head of Strategic Sales

baseten • San Francisco (CA)

On-site
USD 90,000 - 130,000
Competitive compensation, including a
(U.S. only) 100% coverage of medical,
Flexible PTO policy including company
+4
Software Engineer - Partner Platform
Software Engineer - Partner Platform

Baseten • San Francisco (CA)

On-site
USD 180,000 - 240,000
Competitive compensation with equity
US medical, dental, and vision
Flexible PTO and company winter break
+3