Senior GRC Lead - AI Security & Compliance

Replit

California (MO)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401(k) match
Health insurance
Dental insurance
Vision insurance
Life insurance
Disability coverage
Parental leave
Flexible PTO
Commuter benefits
Wellness stipend
In-office reimbursement
Team gatherings

Job summary

Replit is building a security GRC function to scale with an AI-native product. As Risk & Compliance lead, you will own certification programs (SOC 2, ISO 27001) end-to-end, manage risk registers, and oversee continuous compliance.

You’ll partner with Engineering and Legal to ensure controls are practical and auditable. You will drive audit readiness, control documentation like ISMS/SSPs, and collaborate with the GRC Engineer to automate evidence where possible, while aligning with GDPR

Qualifications

  • 8+ years in security compliance, IT audit, or GRC roles with direct ownership of at least one SOC 2 and/or ISO 27001
  • Familiarity with SOC 2, ISO 27001, NIST CSF and mapping controls
  • Experience authoring or maintaining ISMS/SSP documents
  • Experience with risk registers and remediation reporting
  • Experience with GRC automation platforms and continuous control monitoring
  • Experience working with external auditors end-to-end
  • Ability to read technical control evidence and discuss systems with engineers
  • Familiarity with GDPR/privacy fundamentals to assist legal teams

Responsibilities

  • Own end-to-end certification roadmap (SOC 2 Type II, ISO 27001) including scoping, gaps, remediation, audits
  • Manage relationships with external auditors and audit calendars
  • Own master security risk register with risk scoring and treatments
  • Build continuous compliance monitoring reflecting real-time control status
  • Maintain audit artifacts (ISMS, SSPs, control evidence)
  • Run audits, readiness assessments, and track remediation to closure
  • Support GDPR/privacy compliance with Legal/Privacy teams
  • Collaborate with GRC Engineer on evidence collection and automation
  • Report compliance posture and audit findings to security leadership

Skills

8+ years in security compliance
SOC 2 / ISO 27001 ownership
GRC automation
ISMS / SSP documentation
Auditing with external auditors
Privacy familiarity (GDPR)

Tools

Anecdotes
Vanta
Drata

Job description

Replit is building a security GRC function to scale with an AI-native product. As Risk & Compliance lead, you will own certification programs (SOC 2, ISO 27001) end-to-end, manage risk registers, and oversee continuous compliance.

You’ll partner with Engineering and Legal to ensure controls are practical and auditable. You will drive audit readiness, control documentation like ISMS/SSPs, and collaborate with the GRC Engineer to automate evidence where possible, while aligning with GDPR

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote GRC Lead — AI Security & Compliance
Remote GRC Lead — AI Security & Compliance

Applied Methods Ltd • Foster City (CA)

On-site
USD 210,000 - 270,000
Competitive Salary
401(k) with 4% match
Health, Dental, Vision, Life
+5
GRC Lead for AI Security: SOC 2 & ISO 27001
GRC Lead for AI Security: SOC 2 & ISO 27001

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
Senior GRC Lead - AI-Driven Security & Compliance
Senior GRC Lead - AI-Driven Security & Compliance

Gusto • San Francisco (CA)

Hybrid
USD 183,000 - 205,000
Equity (RSUs)
Competitive pay & benefits
Hybrid work schedule (2–3 days in-odd)
Senior GRC Lead - AI Governance & Certifications
Senior GRC Lead - AI Governance & Certifications

Legora • New York (NY)

On-site
Confidential
In-person office: Union Square (NYC)
Daily lunch provided
Comprehensive medical, dental & vision
Senior GRC Lead for AI – End-to-End Certifications & Audits
Senior GRC Lead for AI – End-to-End Certifications & Audits

Thinking Machines Lab • San Francisco (CA)

On-site
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Parental leave
+1
Senior GRC Program Lead - SOC 2, GDPR & Security
Senior GRC Program Lead - SOC 2, GDPR & Security

Tandem Inc. • Draper (UT)

Hybrid
USD 110,000 - 170,000
On-site gym
Flexible PTO
Redo perks: monthly ecommerce credit
+2
Risk and Compliance Lead
Risk and Compliance Lead

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
Senior GRC & AI Compliance Engineer — On-site NYC
Senior GRC & AI Compliance Engineer — On-site NYC

Legora • New York (NY)

On-site
USD 170,000 - 250,000
Office lunch daily
Union Square office
Medical plans
+3
GRC Automation Engineer: Continuous Compliance
GRC Automation Engineer: Continuous Compliance

Plaid • Seattle (WA)

On-site
USD 156,000 - 214,000
Equity
401(k)
GRC Engineer - AI-Driven Compliance & Assurance
GRC Engineer - AI-Driven Compliance & Assurance

Legora • New York (NY)

On-site
Confidential
Medical plans
Dental plans
Vision plans
+7