Security GRC Specialist

Modal Labs
New York, NY, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$150,000.0 - $270,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Cloud Engineering DevOps

Job description

We’re looking for a hands-on Security GRC Specialist to own and scale our security and compliance programs while working closely with engineering and product teams. This role is central to building customer trust, enabling sales, and ensuring we meet evolving regulatory and security expectations without slowing down innovation.

You won’t just maintain compliance, you’ll help shape how we build secure systems.

What You’ll Do:

Compliance & Security Programs

  • Own and operate compliance frameworks (e.g., SOC 2, ISO 27001, GDPR, etc.)
  • Drive audits end-to-end: readiness, evidence collection, auditor coordination
  • Continuously improve controls and reduce compliance overhead through automation

Customer Trust & Sales Enablement

  • Lead responses to customer security questionnaires, RFPs, and due diligence requests
  • Partner with Sales and Customer Success to unblock deals and build trust
  • Develop and maintain security documentation (trust center, whitepapers, FAQs)

Engineering Collaboration

  • Work directly with engineering teams to design and implement practical security controls
  • Translate compliance requirements into technical, scalable solutions
  • Identify gaps and drive remediation projects (not just report them)

Risk & Governance

  • Run risk assessments across systems, vendors, and processes
  • Maintain policies and standards, but keep them lightweight and actionable
  • Track and report on security posture and compliance status

Process & Tooling

  • Improve how we manage compliance (evidence collection, control mapping, automation)
  • Evaluate and implement GRC/security tools where appropriate

Requirements

  • Core Experience
  • 3-7+ years in security GRC, compliance, or security engineering-adjacent roles
  • Hands-on experience with frameworks like SOC 2, ISO 27001, or similar
  • Experience supporting audits and customer-facing security conversations Technical Mindset (Important)

  • Comfortable working with engineers and understanding systems (cloud, infra, APIs, etc.)
  • Ability to translate between compliance language and technical implementation
  • Experience with modern cloud environments (AWS/GCP/Azure) is a strong plus Execution & Ownership

  • Proactive and hands-on-you drive changes, not just track them
  • Able to balance rigor with pragmatism in a fast-moving environment
  • Strong communication skills, especially with customers and cross-functional teams Bonus

  • Experience building or scaling a GRC program from early stages
  • Familiarity with automation in compliance workflows
  • Background in security engineering or DevOps

Benefits & conditions

  • $150K - $270K * Offers Equity

About the company

AI needs a new infrastructure layer. We’re building it at Modal.

Every era of computing brought new workloads that previous infrastructure couldn’t support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now.

Our customers include category-defining companies like Lovable, Ramp, Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it’s simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale.

We recently raised a $355M Series C at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We’ve crossed $300M+ ARR and grown fivefold since September.

Our team includes creators of popular open-source projects (e.g.,Seaborn,Luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all