> Markdown version of [/jobs/ext/3021178-security-engineer-grc-frameworks-ai-governance](https://www.wearedevelopers.com/jobs/ext/3021178-security-engineer-grc-frameworks-ai-governance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - GRC Frameworks & AI Governance - **Company:** SPACEXAI LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $152,000.0 - $258,000.0 - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Continuous Integration, Identity and Access Management, Information Technology Audit, Cloud Services, Policy as Code, Data Logging, Data Processing, Cloud Platform System, IT General Controls (ITGC), Information Technology, RSA Archer Platform, Machine Learning Operations - **Published:** September 21, 2026 - **Apply:** https://www.juju.com/job/15_39a42ec33 ## About the Role * Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. * 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. * Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). * Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 - including building and running controls, not only reading the frameworks. * Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. * Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: * 10+ years of security compliance, GRC engineering, or technology audit-related experience. * Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. * Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. * Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. * Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. * Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. * Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. * Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. * Excellent communication and stakeholder management skills - able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. * Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. * Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. ## Description ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities.RESPONSIBILITIES: * Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. * Build and maintain Compliance-as-Code and continuous compliance capabilities - policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows - so the company can move fast without cutting corners. * Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. * Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. * Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. * Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. * Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). * Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. * Champion a culture of security and compliance across the company - educating teams on why controls exist, not only enforcing them. ## Related Videos - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Policy as [versioned] code - you're doing it wrong](https://www.wearedevelopers.com/videos/532-policy-as-versioned-code-you-re-doing-it-wrong) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)