Strategic GRC Leader - Remote + Equity

OpenRouter, Inc

United States

Remote

USD 175,000 - 205,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

OpenRouter, Inc. is seeking a GRC Manager to own the compliance program day to day in a fully remote US role. You’ll shepherd SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and the EU AI Act, collaborating with IT, Security, Legal, and Finance to embed controls across the company.

Reporting to the Head of IT & Security, you’ll drive audits, evidence collection, training, and policy updates, while shaping a pragmatic approach that scales with a fast-growing, remote-first environment.

Qualifications

  • Hands-on GRC/compliance program experience.
  • At least one SOC 2 audit cycle owned end to end.
  • Fluent in compliance automation (Drata preferred).
  • Able to discuss architecture and data flows with engineers.
  • Strong cross-functional influence and adaptability.

Responsibilities

  • Own Drata end-to-end — administration, integrations, monitoring test health, and the manual evidence collection automation doesn't reach.
  • Curate the SafeBase knowledge base so sales can self-serve most customer security questionnaires — and be the escalation point for the ones they can't.
  • Drive personnel compliance: policy acknowledgments, device compliance, and recurring security and compliance training. This means chasing people down and building the habit, not just running the report.
  • Lead recurring ceremonies: user access reviews, penetration tests, BCDR and incident response tabletop exercises, annual policy review and updates, risk assessments.
  • Work directly with Engineering on product-related compliance questions, from data handling to customer commitments.
  • Maintain audit readiness across SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and the EU AI Act.
  • Translate emerging AI regulation into controls we can actually operate, rather than waiting for someone else's checklist.
  • Partner with HR, Legal, Customer Support, and Finance so compliance fits into work that's already happening.

Skills

GRC
Compliance
SOC 2
Drata
Cross-functional influence
Engineering collaboration
Audit management
Regulatory knowledge

Education

Bachelor's degree

Tools

Drata
SafeBase

Job description

OpenRouter, Inc. is seeking a GRC Manager to own the compliance program day to day in a fully remote US role. You’ll shepherd SOC 2, HIPAA, PCI DSS, GDPR, CCPA, BIPA, and the EU AI Act, collaborating with IT, Security, Legal, and Finance to embed controls across the company.

Reporting to the Head of IT & Security, you’ll drive audits, evidence collection, training, and policy updates, while shaping a pragmatic approach that scales with a fast-growing, remote-first environment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Strategic GRC Lead for AI Compliance & Security
Strategic GRC Lead for AI Compliance & Security

OpenRouter, Inc • New York (NY)

On-site
USD 130,000 - 190,000
Senior GRC Manager: AI Compliance & Security
Senior GRC Manager: AI Compliance & Security

OpenRouter, Inc • United States

Remote
USD 100,000 - 150,000
Senior GRC & Compliance Lead for AI Regulation
Senior GRC & Compliance Lead for AI Regulation

OpenRouter, Inc • Northern (KY)

Hybrid
USD 120,000 - 180,000
Remote Security Compliance Leader GRC & Audit
Remote Security Compliance Leader GRC & Audit

Sardine • Northern (KY)

Hybrid
USD 140,000 - 210,000
Generous compensation
Remote-first culture
Health insurance
+5
GRC Manager
GRC Manager

OpenRouter, Inc • United States

Remote
USD 100,000 - 150,000
GRC Manager
GRC Manager

OpenRouter, Inc • New York (NY)

On-site
USD 130,000 - 190,000
Director of Governance, Risk & Compliance (Fully Remote)
Director of Governance, Risk & Compliance (Fully Remote)

Unknown • United States

Remote
USD 110,000 - 180,000
Competitive salary
401(k) match
Employer-paid health vision dental
+1
Remote GRC Analyst - Security & Compliance Lead
Remote GRC Analyst - Security & Compliance Lead

Bazeta • San Francisco (CA)

Remote
USD 134,000 - 202,000
Equity
Healthcare package
Mentorship and events budget
+2
Remote GRC Analyst: Build Practical Compliance Programs
Remote GRC Analyst: Build Practical Compliance Programs

Insight Security • Northern (KY)

Hybrid
USD 68,000 - 95,000
Health, dental, and vision insurance
Fully remote work
Unlimited PTO
+2
GRC Manager
GRC Manager

OpenRouter, Inc • Northern (KY)

Hybrid
USD 120,000 - 180,000