GRC Manager overseeing security governance and compliance at AI infrastructure company Baseten. Lead initiatives for SOC 2, ISO 27001, and GDPR compliance while fostering collaboration across teams.
Responsibilities
Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.
Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.
Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001, GDPR, and other applicable standards and regulations.
Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.
Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.
Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.
Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.
Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.
Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.
Requirements
5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.
Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.
Proven track record managing compliance audits and certification programs end-to-end.
Familiarity with risk management methodologies, control design, and governance frameworks.
Experience working cross-functionally with technical and non-technical stakeholders to implement compliance controls.
Excellent organizational, documentation, and communication skills with attention to detail.
Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.
Benefits
Competitive compensation, including meaningful equity.
100% coverage of medical, dental, and vision insurance for employee and dependents
Generous PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!)
Paid parental leave
Company-facilitated 401(k)
Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.
Director of Deposit Compliance responsible for leading compliance efforts for deposit products at Northwest Bank. Ensuring adherence to regulations and managing risk assessment processes for effective compliance operations.
Chargé de la Qualité et Conformité en alternance pour Economie d’Energie. Soutenir la conformité et le contrôle interne tout en participant à la transition énergétique en France.
Senior Specialist responsible for corrective actions in Global Trade Compliance at L3Harris. Track compliance incidents and facilitate corrective action processes across US and non - US jurisdictions.
Regulatory Affair Specialist at Capgemini Engineering ensuring regulatory compliance with medical device documentation. Supporting regulatory activities and monitoring the regulatory context impact on site processes.
Compliance Analyst role at Leve Saúde ensuring adherence to regulations in the health sector. Responsibilities include audits, policy management, and due diligence processes.
Governance, Risk & Compliance Specialist at Quilter providing oversight on governance, risk, and compliance activities, strengthening Quilter Invest’s risk management culture across the organization.
Regulatory Specialist responsible for contributions in public consultations and regulatory studies. Engaging with institutional relations and ensuring adherence to energy regulations in Brazil.
Working Student supporting regulatory and compliance efforts at Paymenttools' e - money institution. Collaborating on risk management and compliance projects in a hybrid role based in Cologne.
Senior Consultant Regulatory Affairs participating in pharmaceutical projects focused on market access and regulatory compliance. Joining Deloitte's sector regulation team based in Madrid.
Trade Compliance Officer managing stakeholder compliance with UK and US export laws. Contributing to trade policies and documentation for international imports and exports in a hybrid role.