CronJobs

security jobs

GRC Program Manager, Product Lifecycle Assurance

OpenAI · San Francisco

hybridunknown$216,000–$240,000Posted Sep 1, 2026GoKubernetesCI/CD

Apply on the employer site

About this role

## About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. They are technical in what they build and operational in how they work—partnering closely with Product, Security, Legal, Privacy, GTM, and Field Security to help OpenAI move quickly while maintaining trust with customers, auditors, regulators, and the public. ## About the Role We’re looking for an experienced **Product Lifecycle Assurance IC** to help scale OpenAI’s GRC function across the product stack. You’ll ensure products address customer and regulatory compliance requirements at launch, and that regressions are detected promptly and corrected. This is a highly cross-functional, deeply technical operations role—not support for SOC or ISO audits. You’ll own product assurance end-to-end from inception through post-launch (continuous) monitoring, leveraging and enhancing existing workflows, reviews, and data, and building the components needed for an end-to-end product assurance program. You’ll partner with Product, Security, Legal, and Privacy to maintain OpenAI’s security, privacy, and compliance claims, and to provide assurance to customers, auditors, and regulators about how OpenAI handles user data. ## What You’ll Do - Operate an end-to-end product assurance program from product development through continuous post-launch monitoring - Own the GRC product assurance program, providing governance over Safety, Deployment, and Security/Legal reviews to surface product risk and enable scalable mitigations - Drive cross-functional collaboration and accountability across the product assurance program - Build controls and low-friction, scalable processes across the infrastructure stack, developer workflows, and launch tooling - Ensure teams have the guidance needed to design and launch safety and meet them where they are - Ensure compliance, security, and privacy claims and maps to verifiable controls - Apply sound judgment in launch reviews and technical assurance trade-offs to guide product and engineering teams on the highest priorities - Help ensure product launch governance operates effectively across key safety, privacy, legal, and security stakeholders, using lessons learned from incidents and regressions to improve the program ## Technical Focus - Build key controls in infrastructure stack, developer workflows, and launch tooling (including CI/CD conformance checks) - Surface launches that need GRC guidance - Work comfortably with complex system architectures (e.g., Kubernetes) and dataflows to understand what could go wrong and where controls should be applied - Partner with Privacy engineering and Data Science to understand data maps and database schemas, leveraging existing processes and controls to further product assurance goals ## What We’re Looking For - Strong technical product lifecycle assurance and security/privacy compliance experience in high-velocity, low-friction development environments - Experience building technical controls, metrics, monitoring tools, CI/CD tooling, and high-fidelity risk signals/dashboards - Ability to run an end-to-end, cross-functional product assurance program with judgment on the right processes/controls for a high assurance bar - Ability to shift assurance “to the left” with just-in-time controls, guidance, guardrails, and responsible friction for develo

Listing freshness

CronJobs last confirmed this listing 17h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord