GRC Manager

baseten

United States

On-site

USD 140,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-first environment
Annual team summits
Unlimited PTO
Full healthcare coverage
Parental leave (16 weeks)

Job summary

Baseten seeks an experienced GRC leader to establish and scale our security governance and compliance program. You will partner with engineering, operations, legal, and leadership to design policies, manage audits, and implement controls aligned with SOC 2, ISO 27001, and GDPR.

As an early member of our security team, you will build scalable risk management processes, oversee vendor assessments, support customer due diligence, and drive continuous improvement across security programs while

Qualifications

  • 5+ years in GRC, security compliance, or information security roles.
  • Experience in SaaS or cloud-native environments.
  • Proven track record managing compliance audits and certification programs end-to-end.
  • Cross-functional collaboration with engineering, product, and operations teams.

Responsibilities

  • Design and maintain security governance frameworks, policies, and procedures.
  • Build and manage company-wide risk assessment program.
  • Lead efforts to achieve and maintain SOC 2, ISO 27001, GDPR, and other standards.
  • Coordinate external audits and certification processes with evidence collection and remediation.
  • Oversee vendor security assessments and third-party risk.
  • Embed compliance into day-to-day operations with cross-functional teams.
  • Support customer security questionnaires and due diligence requests.
  • Deliver security/compliance training and drive continuous program improvement.

Skills

GRC
Policy development
Risk assessment
Audits & certifications
Third-party risk
Cross-functional teamwork
SOC 2
ISO 27001
GDPR
Cloud security (AWS/GCP)
GRC tools
AI/ML security
Regulatory awareness

Education

CISA
CISSP
CISM
ISO 27001 Lead Implementer

Tools

Vanta
Drata
Tugboat Logic
Secureframe

Job description

  • We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) to establish, lead, and continuously enhance Baseten’s security governance and compliance programs
  • As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance
  • In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, and GDPR
  • You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow
  • Governance & Policy Development: You’ll design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices
  • Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks
  • Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001, GDPR, and other applicable standards and regulations
  • Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently
  • Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards
  • Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes
  • Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients
  • Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities
  • Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs
Benefits
  • Remote-first work environment. The Baseten team is welcome to work from wherever they want; fully remote, in our San Francisco office, or a mix of both. Today, our team (including our founding team) is spread across the United States, Canada, and Armenia. We provide a $1,000 stipend for you to make your home-office comfortable and productive
  • Regular in-person team summits. We get together as a team three times a year to plan, workshop, and most importantly, get to know each other better
  • Unlimited PTO. We ask that everyone take at least 4 weeks of vacation. And we have a company-wide break between Christmas and New Year’s Day
  • Full healthcare coverage. Medical, dental and vision insurance for you and your family
  • Paid parental leave. 16-weeks fully paid parental leave (adoptive and non-birth parents included) and flexibility with schedules while returning to work
  • Company-sponsored 401(k) for you to contribute to
  • Learning and development budget. We encourage you to take classes, attend conferences, and invest in your craft and we’ll cover expenses to make it happen
  • 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment
  • Excellent organizational, documentation, and communication skills with attention to detail
  • Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline
  • Familiarity with risk management methodologies, control design, and governance frameworks
  • Proven track record managing compliance audits and certification programs end-to-end
  • Experience working cross-functionally with technical and non-technical stakeholders to implement compliance controls
  • Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR
  • Experience with cloud security compliance in AWS or GCP environments
  • Hands-on experience using GRC tools (e.g., Vanta, Drata, Tugboat Logic, Secureframe)
  • Understanding of AI/ML security considerations, data privacy, and model governance
  • Previous experience scaling compliance programs in an early-stage or rapidly growing startup
  • Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Manager
GRC Manager

Baseten • San Francisco (CA)

On-site
USD 150,000 - 190,000
Equity
Medical/Dental/Vision
Flexible PTO
+4
GRC Manager
GRC Manager

Neura Market • San Francisco (CA)

On-site
USD 140,000 - 190,000
Equity
Medical, dental, and vision coverage
Flexible PTO
+4
GRC Manager
GRC Manager

The Consensus • New York (NY)

On-site
USD 130,000 - 180,000
Competitive compensation
Equity
Medical/Dental/Vision insurance
+1
GRC Manager
GRC Manager

Baseten • New York (NY)

On-site
USD 150,000 - 250,000
Competitive compensation
Medical, dental, vision insurance
Flexible PTO
+4
GRC Manager — Secure AI SaaS, Risk & Compliance
GRC Manager — Secure AI SaaS, Risk & Compliance

The Consensus • New York (NY)

On-site
USD 130,000 - 180,000
Competitive compensation
Equity
Medical/Dental/Vision insurance
+1
GRC Manager - SaaS Security & Compliance
GRC Manager - SaaS Security & Compliance

Baseten • San Francisco (CA)

On-site
USD 150,000 - 190,000
Equity
Medical/Dental/Vision
Flexible PTO
+4
GRC & Security Compliance Lead
GRC & Security Compliance Lead

Neura Market • San Francisco (CA)

On-site
USD 140,000 - 190,000
Equity
Medical, dental, and vision coverage
Flexible PTO
+4
GRC & Compliance Leader for AI Security
GRC & Compliance Leader for AI Security

Baseten • New York (NY)

On-site
USD 150,000 - 250,000
Competitive compensation
Medical, dental, vision insurance
Flexible PTO
+4
Security Engineer, GRC
Security Engineer, GRC

candidhealth • United States

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

The Consensus • San Francisco (CA)

On-site
USD 120,000 - 150,000
100% medical, dental, and vision insurance
Flexible PTO policy
Paid parental leave
+2