Strategic GRC Lead for AI Compliance & Security

OpenRouter, Inc

New York (NY)

On-site

USD 130,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

OpenRouter seeks a hands-on compliance leader to own the program day to day, driving SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA and the EU AI Act. You’ll partner with Engineering, HR, Legal, and Finance to embed controls into product development and everyday operations.

You’ll manage audits, evidence collection, and ongoing training, turning evolving regulations into practical security rhythm across the company. This is a strategic builder role that rolls up sleeves.

Qualifications

  • Several years in GRC or compliance, hands-on — you’ve built and run programs.
  • At least one SOC 2 audit cycle owned end to end, evidence through fieldwork.
  • Admin-level fluency in a compliance automation platform (Drata strongly preferred).
  • Technical enough to discuss architecture and data flows with engineers.
  • Proven cross-functional influence without avoiding others.
  • Comfortable when requirements shift and precedent doesn’t exist.

Responsibilities

  • Own Drata end to end — administration, integrations, monitoring test health, and evidence collection automation.
  • Curate the SafeBase knowledge base so sales can self-serve security questionnaires.
  • Drive personnel compliance: policy acknowledgments, device compliance, and recurring training.
  • Lead recurring ceremonies: user access reviews, penetration tests, tabletop exercises, policy reviews.
  • Work with Engineering on product-related compliance questions from data handling to customer commitments.
  • Maintain audit readiness across SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and EU AI Act.
  • Translate emerging AI regulation into actionable controls we can operate.
  • Partner with HR, Legal, Customer Support, and Finance to fit compliance into ongoing work.

Skills

GRC
SOC 2
HIPAA
PCI DSS
GDPR/CCPA
Drata
SafeBase
Cross-functional

Tools

Drata
SafeBase

Job description

OpenRouter seeks a hands-on compliance leader to own the program day to day, driving SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA and the EU AI Act. You’ll partner with Engineering, HR, Legal, and Finance to embed controls into product development and everyday operations.

You’ll manage audits, evidence collection, and ongoing training, turning evolving regulations into practical security rhythm across the company. This is a strategic builder role that rolls up sleeves.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC & Compliance Lead for AI Regulation
Senior GRC & Compliance Lead for AI Regulation

OpenRouter, Inc • Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior GRC Manager: AI Compliance & Security
Senior GRC Manager: AI Compliance & Security

OpenRouter, Inc • United States

Remote
USD 100,000 - 150,000
Strategic GRC Leader - Remote + Equity
Strategic GRC Leader - Remote + Equity

OpenRouter, Inc • United States

Remote
USD 175,000 - 205,000
GRC Manager
GRC Manager

OpenRouter, Inc • United States

Remote
USD 100,000 - 150,000
GRC Manager
GRC Manager

OpenRouter, Inc • New York (NY)

On-site
USD 130,000 - 190,000
GRC Manager
GRC Manager

OpenRouter, Inc • Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior GRC Engineer: AI-Driven Compliance Architecture
Senior GRC Engineer: AI-Driven Compliance Architecture

Playlist • United States

On-site
USD 150,000 - 170,000
Senior GRC Analyst - AI Governance & SOC 2 Lead
Senior GRC Analyst - AI Governance & SOC 2 Lead

Apply • San Francisco (CA)

Hybrid
USD 150,000 - 210,000
Medical, Dental, Vision coverage
401(k) with company match
Remote-friendly culture with SF HQ
+3
Senior GRC Lead - AI Governance & Certifications
Senior GRC Lead - AI Governance & Certifications

Legora • New York (NY)

On-site
Confidential
In-person office: Union Square (NYC)
Daily lunch provided
Comprehensive medical, dental & vision
GRC Lead: AI Privacy & Security Compliance Architect
GRC Lead: AI Privacy & Security Compliance Architect

Perplexity • San Francisco (CA)

On-site
USD 150,000 - 210,000