Security GRC Lead at Mercor | CA, US | Rezi

Security GRC Lead at Mercor

Security GRC Lead

Mercor · CA, US

2 weeks ago

Security GRC Lead

Mercor · CA, US

15 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Security GRC Lead role.

Rezi rewrites your resume against Mercor's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Security GRC Lead posting at Mercor — free, in seconds.

About the Role

Mercor is seeking a GRC professional to establish and own the company's compliance operating cadence. This role involves managing continuous SOC 2 monitoring, ISO 27001 buildout, quarterly customer audits, and a rapid questionnaire response SLA. You will leverage AI tools for GRC tasks and ensure compliance posture supports enterprise sales.

Responsibilities

  • Own the operating cadence of a continuously-audited company.
  • Manage continuous SOC 2 monitoring in Vanta.
  • Oversee the active ISO 27001 buildout.
  • Conduct annual KPMG-style customer audits quarterly.
  • Maintain a sub-48-hour questionnaire SLA.
  • Write controls in code where applicable.
  • Push back on tools that hinder compliance efforts.
  • Own the artifacts that close enterprise deals.
  • Utilize AI and LLMs for drafting, reviewing, and responding to compliance tasks.
  • Establish the Mercor compliance operating cadence, including SOC 2 Type 2 and ISO 27001.
  • Build a customer-audit machine capable of responding to major AI labs.
  • Develop the third-party risk program, including intake, review cadence, and evidence requirements.
  • Own the policy lifecycle end-to-end.
  • Implement controls-as-code where appropriate.
  • Define and manage data-handling procedures, including customer data deletion and DSAR workflows.
  • Develop the internal trust narrative, including customer trust pages and security one-pagers.

Requirements

  • 7+ years in security GRC, compliance engineering, or audit.
  • At least 2 years owning a SOC 2 Type 2 program end-to-end at a company audited by enterprise customers.
  • Shipped at least one ISO 27001 certification from kickoff to issued certificate.
  • Fluent in Vanta (or Drata, Secureframe, Sprinto) at the integration and admin level.
  • Sat on the company side of at least one enterprise customer audit conducted by a Big 4 firm.
  • Translate cloud-security language to auditor language and back without losing precision.
  • Write controls as code or query evidence with SQL (Python, SQL, or shell).
  • Understand the difference between 'we don't have a control for that' and 'we have a compensating control'.
  • Direct experience with the customer-trust surface: SIG, CAIQ, custom enterprise questionnaires, on-site auditor sessions, disclosure letters under legal review.

Skills

  • GRC
  • Compliance Engineering
  • Audit
  • SOC 2 Type 2
  • ISO 27001
  • Vanta
  • Drata
  • Secureframe
  • Sprinto
  • Big 4 audit firms
  • Cloud security
  • Auditor language
  • Wiz findings
  • Panther rules
  • IAM policy
  • Controls as code
  • SQL
  • Python
  • Shell scripting
  • SIG
  • CAIQ
  • LLMs

Location

  • San Francisco
  • NYC
  • London

Work Type

  • In-person five days a week
  • First Fridays remote

Experience Level

  • 7+ years in security GRC, compliance engineering, or audit
  • At least 2 years owning a SOC 2 Type 2 program

Benefits

  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k Relocation bonus
  • $10K housing bonus (if you live within 0.5 miles of our office)
  • $1.5K monthly stipend for meals
  • Free Equinox membership
  • $200 monthly laundry reimbursement
  • $200 monthly personal wellness reimbursement
  • Health, Dental, Vision insurance

About the Company

  • Mercor is a leading AI data company organizing human intelligence to power the AI economy.
  • They build the layer between human expertise and frontier models.
  • Millions of domain experts are paid over $4 million per day to train frontier AI models on the platform.
  • Mercor's APEX benchmark family measures AI's real-world impact on professional work.
  • Mercor Enterprise brings this infrastructure to Fortune 500 companies to capture how their best people work and translate that expertise into agents.
  • Mercor is creating a new category of work where expertise powers AI advancement.
  • The company is profitable, Series C, and valued at $10 billion.
  • They have existing security partnerships with TachTech (cloud), Latacora (MDR), Mandiant (IR), and HackerOne (BB).