GRC Manager
Baseten · San Francisco
About this role
## GRC Manager ### About Baseten Baseten powers mission-critical inference for the world’s most dynamic AI companies (like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma, and Writer). By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we help frontier AI companies bring cutting-edge models into production. We’re growing quickly and recently raised our **$1.5B Series F**. Join us and help build the platform engineers turn to ship AI products. ### The Role Baseten is seeking an experienced, detail-oriented **GRC (Governance, Risk, and Compliance) Manager** to build, support, and continuously enhance our security governance, compliance, and privacy programs. As an early member of our security organization, you’ll work closely with **Engineering, Product, Security, and Legal** to define compliance requirements, assess platform capabilities, and drive implementation from scoping through validation. You’ll also lead **customer assurance** efforts—helping customers understand our security architecture and compliance posture, while bringing their requirements back into product planning. You’ll contribute to Baseten’s broader GRC program, including **governance, risk management, audits, vendor assessments, and security awareness**. ### Responsibilities - **Product Compliance:** Translate regulatory, framework, and customer requirements into product requirements and technical controls. - **Governance & Policy Development:** Design, implement, and maintain security governance frameworks, policies, and procedures. - **Risk Management:** Build and manage the company-wide risk assessment program; identify, track, and mitigate key risks. - **Compliance Operations:** Support compliance efforts for **SOC 2, ISO 27001/27701, HIPAA, FedRAMP**, and other applicable standards. - **Audit & Certification Management:** Coordinate external audits and certifications; ensure evidence collection, control validation, and remediation. - **Third-Party Risk Management:** Oversee vendor security assessments and ensure third parties meet Baseten standards. - **Cross-Functional Collaboration:** Embed compliance and risk management into day-to-day operations and technical processes. - **Customer Trust & Assurance:** Support security questionnaires, due diligence, and documentation requests. - **Training & Awareness:** Develop and deliver security and compliance training. - **Continuous Improvement:** Stay current on evolving regulatory requirements and mature compliance/risk programs. ### Requirements - **BS degree** in CS, CE, MIS, or equivalent - **5+ years** in GRC, Security Compliance, or Information Security (ideally SaaS/cloud-native) - Strong understanding of **SOC 2, ISO 27001, NIST, GDPR** - Proven track record managing compliance audits and certification programs end-to-end - Experience working with leaders/executives in enterprise organizations - Cross-functional experience with technical and non-technical stakeholders - Proven ability to drive **product compliance** by translating requirements into actionable controls - Experience defining project requirements and driving implementation through completion - Experience responding to customer security questionnaires and leading security interviews - Ability to thrive in a fast-paced, high-growth startup while maintaining process discipline ### Nice to Have - Cloud security compliance experience in **AWS or GCP** - Hands-on experience with GRC tools (e.g., **Vanta
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.