Head of Risk and Compliance

Applied Intuition

Sunnyvale (CA)

On-site

USD 180,000 - 260,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Applied Intuition seeks a multifaceted Risk and Compliance Leader to guide our security GRC program across the organization. You will own policy lifecycle, risk register maintenance, and control framework alignment while coordinating with legal, engineering, operations and customers to communicate compliance status.

You will lead enterprise and product risk assessments, drive audit readiness for SOC 2, ISO 27001, and TISAX, and implement a robust third-party risk program with ongoing monitoring

Qualifications

  • 6+ years of experience in security GRC, risk management, or compliance program ownership.
  • Hands-on experience with enterprise risk assessments and risk register ownership.
  • Deep experience managing SOC 2, ISO 27001, and TISAX audits.
  • Experience running Third Party Risk Management programs including vendor assessments and monitoring.
  • Ability to translate compliance frameworks into practical terms and drive cross-functional remediation.

Responsibilities

  • Own and mature the security GRC program, including policy lifecycle management and risk register maintenance.
  • Conduct enterprise and product-level risk assessments to identify, prioritize, and track risks.
  • Lead and support compliance efforts such as SOC 2, ISO 27001, ISO 9001, and TISAX; manage audits from scoping to remediation.
  • Drive Third Party Risk Management (TPRM) including vendor assessments and contract security reviews.
  • Build and maintain the GRC infrastructure: risk tracking, tooling, reporting, and executive risk reporting.
  • Partner with Legal, Engineering, IT, and Operations to embed compliance in processes and product development.
  • Develop and maintain security policies, standards, and procedures aligned to regulatory obligations.
  • Support customer-facing security assurance activities including questionnaires and audits.

Skills

GRC
Risk management
Compliance program ownership
Audit readiness
Vendor risk management
Policy development

Tools

Vanta
Drata
OneTrust

Job description

Applied Intuition, Inc. is powering the future of physical AI. Founded in 2017 and now valued at $15 billion, the Silicon Valley company is creating the digital infrastructure needed to bring intelligence to every moving machine on the planet. Applied Intuition services the automotive, defense, trucking, construction, mining and agriculture industries in three core areas: tools and infrastructure, operating systems, and autonomy. Eighteen of the top 20 global automakers, as well as the United States military and its allies, trust the company’s solutions to deliver physical intelligence. Applied Intuition is headquartered in Sunnyvale, California, with offices in Washington, D.C.; San Diego; Ft. Walton Beach, Florida; Ann Arbor, Michigan; London; Stuttgart; Munich; Stockholm; Bangalore; Seoul; and Tokyo. Learn more at applied.co.

We are an in-office company, and our expectation is that full-time employees primarily work from their Applied Intuition office 5 days a week. However, we also recognize the importance of flexibility and trust our employees to manage their schedules responsibly. This may include occasional remote work, starting the day with morning meetings from home before heading to the office, or leaving earlier when needed to accommodate family commitments. This in-office expectation does not apply to contractor positions

About the role

We are looking for a multifaceted Risk and Compliance Leader to lead our security compliance initiatives across the organization. You will be responsible for ensuring adequate security controls to identify and mitigate risk across the organization. Additionally, you will collaborate with legal, engineering, operations and customers, as necessary, to ensure the state of compliance is well communicated.

At Applied Intuition, you will:
  • Own and mature the security GRC program, including policy lifecycle management, risk register maintenance, and control framework alignment across the organization

  • Conduct comprehensive enterprise and product-level risk assessments to identify, prioritize, and track risks against the company's risk appetite - translating findings into actionable remediation plans for stakeholders

  • Lead, manage and support compliance efforts such as, but not limited to, SOC2, ISO 27001, ISO 9001, TISAX, and federal/defense requirements - owning audit readiness, evidence collection, and remediation tracking end to end

  • Drive Third Party Risk Management (TPRM) program, including vendor assessments, contract security reviews, and ongoing monitoring of critical third parties

  • Build and maintain the GRC program infrastructure - including risk tracking, compliance tooling, reporting cadences, and executive-level risk reporting

  • Partner with Legal, Engineering, IT, and Operations to embed compliance and risk requirements into business processes, product development, and infrastructure decisions

  • Develop and maintain security policies, standards, and procedures that are practical, enforceable, and aligned to regulatory and contractual obligations

  • Support customer-facing security assurance activities including questionnaires, audits, and contractual security reviews

We're looking for someone who has:
  • 6+ years of experience in security GRC, risk management, or compliance program ownership - with a track record of building or maturing programs, not just executing within them

  • Hands on experience in running Enterprise Risk Assessments aligned with industry standard frameworks, risk register ownership, and translating technical risk into business-level impact

  • Past experience of running Security Maturity Assessments against NIST 800-53, CCF, and more

  • Deep hands-on experience managing SOC 2, ISO 27001, and TISAX audits - including scoping, control mapping, evidence coordination, and auditor management

  • Experience running Third Party Risk Management programs including vendor tiering, security assessments, and ongoing monitoring

  • Ability to interpret compliance frameworks in practical terms and drive cross-functional remediation without direct authority

  • Strong communication skills - comfortable presenting risk posture and program status to executive leadership and board-level stakeholders

  • Experience with GRC tooling such as Vanta, Drata, OneTrust, or similar platforms

Nice to have:
  • Experience with Automotive security and safety compliance frameworks such as ISO 21434, ISO 26262

  • Certifications such as CISSP

Compensation at Applied Intuition for eligible roles includes base salary, equity, and benefits. Base salary is a single component of the total compensation package, which may also include equity in the form of options and/or restricted stock units, comprehensive health, dental, vision, life and disability insurance coverage, 401k retirement benefits with employer match, learning and wellness stipends, and paid time off. Note that benefits are subject to change and may vary based on jurisdiction of employment.

Applied Intuition pay ranges reflect the minimum and maximum intended target base salary for new hire salaries for the position. The actual base salary offered to a successful candidate will additionally be influenced by a variety of factors including experience, credentials & certifications, educational attainment, skill level requirements, interview performance, and the level and scope of the position.

Don’t meet every single requirement? If you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.

Applied Intuition is an equal opportunity employer and federal contractor or subcontractor. Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a) and 41 CFR 60-741.5(a) and that these laws are incorporated herein by reference. These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity or national origin. These regulations require that covered prime contractors and subcontractors take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disability. The parties also agree that, as applicable, they will abide by the requirements of Executive Order 13496 (29 CFR Part 471, Appendix A to Subpart A), relating to the notice of employee rights under federal labor laws.

FOR US-BASED ROLES: Applied Intuition is committed to providing an accessible and inclusive application and interview experience to applicants who are disabled veterans and other applicants with disabilities or medical conditions. Reasonable accommodations are available, requesting an accommodation will not affect your candidacy in any way, and you are not required to disclose the nature of your disability or medical condition in order to make a request.
If you require an accommodation please contact careers@applied.co. We will work with you!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Risk and Compliance
Head of Risk and Compliance

Decisive Point • Sunnyvale (CA)

Hybrid
USD 170,000 - 230,000
Head of Risk and Compliance
Head of Risk and Compliance

Applied Training Solutions, LLC • Sunnyvale (CA)

On-site
USD 180,000 - 260,000
Equity
Health insurance
Dental
+7
DevSecOps Engineer - Government
DevSecOps Engineer - Government

Decisive Point • Washington

On-site
USD 190,000 - 240,000
Health insurance
401(k) retirement
Paid time off
DevSecOps Engineer - Government
DevSecOps Engineer - Government

Applied Intuition • Washington, Northern (KY)

Hybrid
USD 140,000 - 190,000
DevSecOps Engineer - Government
DevSecOps Engineer - Government

Socket.dev • Washington

On-site
USD 140,000 - 210,000
DevSecOps Engineer - Government
DevSecOps Engineer - Government

applied • Washington

On-site
USD 150,000 - 210,000
Product Counsel
Product Counsel

InvestedintheMission • Washington

Hybrid
USD 180,000 - 240,000
Health insurance
401k plan
Paid time off
+1
Technical Program Manager - Defense Autonomy
Technical Program Manager - Defense Autonomy

Applied Intuition, Inc. • Poway (CA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+3
Software Engineer - Control Center
Software Engineer - Control Center

Socket.dev • Sunnyvale (CA)

On-site
USD 180,000 - 240,000
Engineering Manager - Forward Deployment (Defense)
Engineering Manager - Forward Deployment (Defense)

Decisive Point • Washington

On-site
USD 250,000 - 300,000