About the Role
We are seeking a GRC Lead to manage our certifications (SOC 2, ISO 27001, FedRAMP, etc.) from start to finish and oversee daily compliance processes. You will gather evidence, document controls, and directly interact with auditors, leveraging your technical understanding of our systems to address compliance and risk inquiries.
Responsibilities
- Own the end-to-end certification roadmap, including scoping, control definition, evidence collection, and auditor representation.
- Manage recurring compliance processes such as control testing, audit preparation and response, risk register maintenance, and policy attestations.
- Address compliance and risk questions from engineering, security, and product teams by developing technical fluency in our infrastructure, model deployment, and data handling.
- Track and translate regulatory and framework requirements relevant to AI (e.g., GDPR, EU AI Act) into actionable controls.
- Identify compliance gaps for new products, infrastructure, or jurisdictions and propose necessary changes.
- Develop and maintain tooling and documentation to streamline future audit cycles.
- Create a multi-quarter roadmap for the GRC function while managing ongoing certifications and audits.
Requirements
- 7+ years of related experience in technology and cybersecurity Governance, Risk, and Compliance (GRC), with expertise across all three disciplines.
- Experience leading SOC 2, ISO 27001, FedRAMP, or comparable certifications from scoping through audit close.
- Hands-on experience collecting audit evidence and writing control documentation.
- Experience managing recurring compliance processes like control testing, risk register maintenance, or policy attestations.
- Proven ability to quickly learn new technical domains and communicate them to non-technical stakeholders.
- Experience translating complex compliance requirements into scalable automation using AI agents and custom tooling (preferred).
- Experience growing a GRC function's capabilities (new certifications, tooling, or processes) during company scaling (preferred).
- Willingness to personally manage certifications and audits end-to-end.
- Ability to act as the primary point of contact with auditors.
- Capacity to balance immediate deadlines with long-term strategic planning.
Skills
- Governance
- Risk Management
- Compliance
- Cybersecurity
- SOC 2
- ISO 27001
- FedRAMP
- Audit Evidence Collection
- Control Documentation
- Risk Assessment
- Regulatory Tracking
- AI Compliance
- Technical Communication
- Automation
- AI Agents
- Tooling Development
Location
- San Francisco, California
Work Type
- Full-time
Experience Level
- 7+ years related experience
Salary/Compensations
- $225,000 - $350,000
Benefits
- Generous health, dental, and vision benefits
- Unlimited PTO
- Paid parental leave
- Relocation support
- Visa sponsorship
About the Company
- Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence.
- We are building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals.
- We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything.
Equal Opportunity
- As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.
- Thinking Machines Lab will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the California Fair Chance Act, the San Francisco Fair Chance Ordinance, and any other applicable state or local fair chance ordinance or law.
