Sr. Security Engineer - GRC Frameworks & AI Governance

Xai

New York (NY)

On-site

USD 100,000 - 228,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Equity
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
Disability insurance
Life insurance

Job summary

Xai is seeking an experienced Governance, Risk, and Compliance team member in New York to ensure operations within regulatory boundaries while safeguarding AI applications. This role demands a Bachelor’s degree in Computer Science or related and 3+ years of relevant experience.

The candidate will handle compliance audits, risk assessments, and collaborate with cross-functional teams. The compensation range is between $100,000 and $228,000, with additional benefits including equity and comprehensive healthcare.

Qualifications

  • 3+ years of experience in governance, risk management, compliance, or technology audit roles.
  • Experience with vulnerability management and cloud security controls.
  • Ability to thrive in a fast-paced, dynamic environment.

Responsibilities

  • Execute security compliance implementation and audits.
  • Identify, assess, and prioritize risks related to AI operations.
  • Lead Risk Management Assessment and Authorization processes.

Skills

Governance, Risk Management
Compliance
Cybersecurity
Analytical skills

Education

Bachelor’s degree in Computer Science or related field

Tools

NIST
ISO 27001
SOC 2

Job description

ABOUT xAI

xAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands‑on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE

We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) team member as we expand into government and public sector applications of AI. This critical role will ensure that xAI operates within regulatory, ethical, operational, and federal boundaries while fostering a culture of integrity and resilience. You will collaborate with cross‑functional teams to safeguard our mission‑driven work in AI development and deployment, including support for sensitive and classified environments.

RESPONSIBILITIES
  • Execute security compliance implementation and audits (e.g., ISO 27001/42001, SOC2, FedRAMP HIGH, DoD Cloud Computing SRG IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
  • Work with 3PAOs (Third‑Party Assessment Organizations) and federal government Authorizing Officials (AOs) to achieve compliance certifications, reports, and Authorized to Operate (ATO) status.
  • Identify, assess, and prioritize risks related to AI operations, cybersecurity, regulatory compliance, intellectual property, and cloud deployments.
  • Design and implement risk mitigation strategies, including monitoring systems, contingency plans, vulnerability scans, Plan of Action and Milestones (POAMs), and STIGs.
  • Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures throughout the project lifecycle.
  • Serve as a liaison between system owners, security personnel, and cross‑functional teams to facilitate effective communication, collaboration, and control implementation.
  • Lead Risk Management Assessment and Authorization (A&A) processes, cloud system risk assessments, compliance reviews for new products/changes/features, and process enhancements.
  • Conduct regular risk assessments, scenario analyses, and proactive evaluations of emerging threats, certifications, requirements, and technologies in the AI landscape.
  • Oversee audits, certifications, third‑party assessments, and vulnerability management to maintain compliance and operational credibility.
  • Act as a subject matter expert, providing guidance on risk, compliance, and cybersecurity matters; translate business and technical risks for leadership.
  • Create and present regular reports on GRC performance, risks, and compliance status to senior leadership and stakeholders.
BASIC QUALIFICATIONS
  • Bachelor’s degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field
  • 3+ years of experience in governance, risk management, compliance, or technology audit roles.
  • Experience with vulnerability management, POAMs, STIG implementation, and cloud security controls.
PREFERRED SKILLS AND EXPERIENCE
  • 5+ years of security compliance or technology audit-related.
  • Previous systems engineering experience strongly preferred
  • Ability to evaluate control objectives with IT configurations
  • Experience in the tech or AI industry, particularly with startups, innovative organizations, or government/public sector engagements.
  • Proven expertise in regulatory frameworks, data privacy, cybersecurity, and federal compliance standards, preferably in a technology, cloud, or AI‑driven environment.
  • Strong understanding of AI ethics, emerging technologies, Risk Management Framework (RMF), and their associated risks.
  • Exceptional analytical, problem‑solving, organizational, and project management skills, with the ability to balance innovation, oversight, and taking projects from conception to launch.
  • Excellent communication, stakeholder management, and translation skills, with experience influencing cross‑functional teams and communicating risks to leadership.
  • Ability to thrive in a fast‑paced, dynamic environment and adapt to evolving priorities.
  • Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.
  • Deep expertise maintaining frameworks such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, and STIG/RMF policies (including validation via ACAS and similar tools).
  • Familiarity with ISO 27001, ISO 42001, NIST, SOC 2, or similar compliance frameworks.
  • Background in managing third‑party risk, vendor compliance programs, or federal assessments.
  • Understanding of cybersecurity controls for cloud service providers.
  • Knowledge of government cloud services and evolving certification programs.
COMPENSATION AND BENEFITS

$100,000 - $228,000 USD

Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long‑term disability insurance, life insurance, and various other discounts and perks.

ITAR REQUIREMENTS
  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.

xAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Member Of Technical Staff - Cloud Infrastructure
Member Of Technical Staff - Cloud Infrastructure

Pantera Capital • Palo Alto (CA)

On-site
USD 180,000 - 440,000
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
Short & long-term disability insurance
+1
Application Security Engineer
Application Security Engineer

Pantera Capital • Palo Alto (CA)

On-site
USD 100,000 - 258,000
Equity
Medical coverage
401(k)
Program Manager, Prohibited & Regulated Content
Program Manager, Prohibited & Regulated Content

SpaceXAI • Palo Alto (CA)

On-site
USD 110,000 - 145,000
Senior IT Systems Engineer
Senior IT Systems Engineer

Pantera Capital • Palo Alto (CA)

Hybrid
USD 184,000 - 276,000
Equity
Medical, vision and dental coverage
401(k) retirement plan
+2
Senior HR Business Partner
Senior HR Business Partner

xAI • New York (NY)

On-site
USD 160,000 - 198,000
Equity
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
+3
Program Manager, Harmful Activity
Program Manager, Harmful Activity

SpaceXAI • Palo Alto (CA)

On-site
USD 110,000 - 145,000
Equity
Medical coverage
401(k)
Application Security Engineer
Application Security Engineer

xAI • Palo Alto (CA)

On-site
USD 200,000 - 340,000
Equity
Comprehensive medical coverage
401(k) retirement plan
Sr. Security Engineer - GRC Fintech & Financial Services
Sr. Security Engineer - GRC Fintech & Financial Services

SpaceXAI • Palo Alto (CA)

On-site
USD 152,000 - 228,000
Equity
Comprehensive medical, vision, dental
401(k) retirement plan
Program Manager, Harmful Activity New Bastrop, Texas; New York, New York; Palo Alto, California
Program Manager, Harmful Activity New Bastrop, Texas; New York, New York; Palo Alto, California

Maxxd • Town of Texas (WI), Northern (KY)

Hybrid
USD 110,000 - 145,000
Equity
Medical coverage
Vision coverage
+4
Infrastructure Security Engineer
Infrastructure Security Engineer

Pantera Capital • Palo Alto (CA)

On-site
USD 200,000 - 340,000
Equity
Comprehensive medical coverage
401(k) retirement plan
+2