About the role

  • Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.
  • Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.
  • Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001, GDPR, and other applicable standards and regulations.
  • Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.
  • Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.
  • Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.
  • Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.
  • Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.
  • Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.

Requirements

  • 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.
  • Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.
  • Proven track record managing compliance audits and certification programs end-to-end.
  • Familiarity with risk management methodologies, control design, and governance frameworks.
  • Experience working cross-functionally with technical and non-technical stakeholders to implement compliance controls.
  • Excellent organizational, documentation, and communication skills with attention to detail.
  • Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.

Benefits

  • Competitive compensation, including meaningful equity.
  • 100% coverage of medical, dental, and vision insurance for employee and dependents
  • Generous PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!)
  • Paid parental leave
  • Company-facilitated 401(k)
  • Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.

Job title

GRC Manager

Job type

Experience level

Mid levelSenior

Salary

$150,000 - $250,000 per year

Degree requirement

Bachelor's Degree

Tech skills

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job