GRC Program Manager

OpenAI Inc.
Washington, DC, United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Audit Trail User Authentication Microsoft Azure Cyber Security Data Security Network Security Software Vulnerability Management Kubernetes Terraform

Job description

Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture., Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government (USG) ATOs and compliance frameworks, including but not limited to FedRAMP and Department of War (DoW),for OpenAI products and support agency-specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders., * Drive the ATO process for FedRAMP and across multiple government clients in restricted environments with minimal oversight.

  • Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.
  • Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.
  • Act as a subject matter expert during audits and assessments, representing the organization with credibility and expertise.
  • Continuously refine processes to improve the efficiency and quality of compliance efforts.

Requirements

  • Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors.
  • A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP).
  • Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders.
  • Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure., * An active US security clearance.
  • 5+ years of compliance experience in positions involving information security, data security, or infrastructure or network security.
  • Familiarity with deployment models, including to cloud platforms (Azure, AWS) and the underlying infrastructure primitives (Kubernetes, Terraform).
  • Strong familiarity with core security concepts and technologies, such as authentication, encryption, vulnerability management, and audit logging.
  • The ability to work collaboratively and effectively in a cross-functional team environment.
  • Thrive in dynamic environments and can navigate ambiguity with ease.

About the company

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

3:10 min

Balancing rapid artificial intelligence development with strict compliance regulations

Videos

See all

Related articles

See all