Security GRC Lead
Mercor · San Francisco
About this role
**Security GRC Lead** **About Mercor** Mercor organizes human intelligence to power the AI economy. We're a leading AI data company building infrastructure between human expertise and frontier models. Mercor is a profitable Series C company valued at $10 billion. **Role Overview** You'll be the first GRC hire at a company processing sensitive training data, evals, and human-feedback pipelines for frontier AI labs. Compliance is a sales gate for every $50M+ contract. This is a hands-on role owning continuous SOC 2 monitoring, ISO 27001 buildout, quarterly customer audits, and sub-48-hour questionnaire SLAs. **Key Responsibilities** • Build the compliance operating cadence: SOC 2 Type 2 (continuous), ISO 27001, and next frameworks (HIPAA, FedRAMP Moderate, EU AI Act) • Create a customer-audit machine responding to Anthropic, Google, Meta, NVIDIA, OpenAI without burnout • Establish third-party risk program with formal intake and recurring review • Own policy lifecycle end-to-end: versioning, attestation, exception handling • Implement controls-as-code: Vanta integrations, Wiz policies, Panther rules • Develop data-handling procedures: customer deletion, DSAR workflows, KMS destruction • Build internal trust narrative: customer trust pages, security briefs, disclosure templates **Requirements** • 7+ years in security GRC, compliance engineering, or audit • 2+ years owning SOC 2 Type 2 end-to-end at enterprise-audited company • Shipped ISO 27001 certification (Stage 1 & 2) with real registrar • Fluent in Vanta/Drata/Secureframe at integration level • Sat on company side of Big 4 enterprise customer audit • Translate cloud-security to auditor language with precision • Write controls-as-code (Python, SQL, shell) • Direct experience with SIG, CAIQ, custom questionnaires, on-site audits **Bonus** • GRC experience in AI labs or ML platforms • NIST AI RMF, EU AI Act, ISO 42001 familiarity • FedRAMP Moderate, HIPAA, PCI DSS, HITRUST experience • LLM-automated questionnaire response • Third-party risk program buildout from zero • Published customer trust pages **Why Join** • Build the function from scratch—set operating cadence and pick tools • Compliance work that directly closes deals • AI-native GRC with daily frontier model use • Direct line to auditors and customers • Established security org (TachTech, Latacora, Mandiant, HackerOne) backing you **Benefits** Bi-annual bonus, generous equity (4-year vest), up to $15k relocation, $10k housing bonus, $1.5k monthly meals stipend, free Equinox, $200 laundry reimbursement, $200 wellness reimbursement, health/dental/vision insurance. **Location** In-person 5 days/week: San Francisco, NYC, or London (first Fridays remote)
Listing freshness
CronJobs last confirmed this listing 3h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.