From 058842cb94a2be8b8cdc7cbc4f46bc0f34add9d4 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Tue, 7 Apr 2026 04:57:21 +0000 Subject: [PATCH 01/17] docs: auto-update engineer directory --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index 472ce24..359c14f 100644 --- a/README.md +++ b/README.md @@ -16,6 +16,7 @@ A community-driven directory of Governance, Risk, and Compliance (GRC) engineers | **[Jessica Barnwell](engineers/Gorg-jess32.md)** | Audit & Assurance, Cloud Security, Compliance Automation, Identity & Access Management, Incident Response, Risk Management, Security Operations | HIPAA, HITRUST, ISO 27001, NIST 800-53, NIST 800-171 | [GitHub](https://github.com/Gorg-jess32), [LinkedIn](https://www.linkedin.com/in/jessicabarnwell/) | | **[John Bommeraveni Joseph](engineers/Johnbjoseph-cybersec.md)** | Audit & Assurance, Compliance Automation, Identity & Access Management, Privacy, Risk Management, Security Governance, Third-Party Risk, Vulnerability Management, AI Governance, Cloud Governance | GDPR, HIPAA, ISO 27001, ISO 42001, NIST AI RMF, NIST CSF, NIST RMF, PCI-DSS, SOC 2 | [GitHub](https://github.com/Johnbjoseph-cybersec), [LinkedIn](https://www.linkedin.com/in/john-bj/) | | **[Sharaden Cole](engineers/Lokage7.md)** | Audit & Assurance, Cloud Security, Compliance Automation, Identity & Access Management, Privacy, Risk Management, Security Architecture, Security Governance, Third-Party Risk | FedRAMP, HIPAA, HITRUST, ISO 27001, NIST 800-53, NIST 800-171, NIST CSF, NIST RMF, PCI-DSS, SOC 2 | [GitHub](https://github.com/Lokage7), [LinkedIn](https://www.linkedin.com/in/sharadencole) | +| **[Mamta Sakuja](engineers/Mamt74.md)** | Audit & Assurance, Cloud Security, Security Governance, AI Governance, Cloud Governance | FedRAMP, GovRAMP, HIPAA, HITRUST, ISO 27001, ISO 27017, ISO 27018, NIST 800-53, NIST 800-171, NIST CSF, NIST RMF, PCI-DSS, SOC 2, StateRAMP | [GitHub](https://github.com/Mamt74), [LinkedIn](https://www.linkedin.com/in/mamta-s-16ab287) | | **[MaryAnna Moore](engineers/MaryAnnaMoore07.md)** | Identity & Access Management, Incident Response, Security Operations, Vulnerability Management | GDPR, HIPAA, NIST 800-53, NIST 800-171, NIST RMF, PCI-DSS, SOC 2 | [GitHub](https://github.com/MaryAnnaMoore07), [LinkedIn](https://www.linkedin.com/in/maryanna-moore/) | | **[Orlando Pizarro](engineers/Orlando-GRCengineer.md)** | Audit & Assurance, Compliance Automation, Risk Management, Security Governance, AI Governance, Cloud Governance | CMMC, FedRAMP, NIST 800-53, NIST 800-171, NIST AI RMF, NIST CSF, NIST RMF | [GitHub](https://github.com/Orlando-GRCengineer), [LinkedIn](https://www.linkedin.com/in/orlando-pizarro-851b12357/) | | **[Steven Smith](engineers/SmittyStuff.md)** | Privacy, Risk Management, Security Architecture, Security Governance, Data Protection, Encryption & Masking | CMMC, HIPAA, HITRUST, ISO 27001, NIST 800-53, NIST 800-171, NIST CSF, NIST RMF, PCI-DSS, SOC 2 | [GitHub](https://github.com/SmittyStuff), [LinkedIn](https://www.linkedin.com/in/steven-smith-itnet/) | @@ -35,6 +36,7 @@ A community-driven directory of Governance, Risk, and Compliance (GRC) engineers | **[Ethan Troy](engineers/ethanolivertroy.md)** | Compliance Automation, Cloud Security, Security Architecture, Offensive Security | FedRAMP, NIST 800-53, NIST CSF, SOC 2, CMMC | [GitHub](https://github.com/ethanolivertroy), [LinkedIn](https://www.linkedin.com/in/ethantroy/) | | **[Garima Kakkar](engineers/garimakakkar.md)** | Audit & Assurance, Compliance Automation, Privacy, Risk Management, Security Governance, Third-Party Risk, AI Governance, Cloud Governance | CCPA, EU AI Act, GDPR, ISO 27001, ISO 42001, NIST 800-53, NIST AI RMF, SOC 2 | [GitHub](https://github.com/garimakakkar), [LinkedIn](https://www.linkedin.com/in/garima-kakkar-54456b60/) | | **[Gregory Wilson](engineers/gregorywilsonjr.md)** | Audit & Assurance, Cloud Security, Compliance Automation, Identity & Access Management, Security Architecture, Security Operations, Vulnerability Management, DevSecOps, Zero-Touch Compliance | CSA STAR, ISO 27001, NIST 800-53, PCI-DSS | [GitHub](https://github.com/gregorywilsonjr), [LinkedIn](https://www.linkedin.com/in/gregorywilsonjr) | +| **[Pradeep Reddy](engineers/iampradeeprs.md)** | Audit & Assurance, Compliance Automation, Risk Management, Security Governance, Third-Party Risk, AI Governance, Cloud Governance | FedRAMP, GDPR, HIPAA, HITRUST, ISO 27001, ISO 42001, NIST 800-53, NIST 800-171, NIST AI RMF, NIST CSF, NIST RMF, PCI-DSS, SOC 2, StateRAMP | [GitHub](https://github.com/iampradeeprs), [LinkedIn](https://www.linkedin.com/in/infosecpradeep/) | | **[Jonathan Steward](engineers/jonathansteward.md)** | Audit & Assurance, Compliance Automation, Risk Management, Third-Party Risk, AI Governance | ISO 27001, NIST CSF, NIST RMF, SOC 2 | [GitHub](https://github.com/jonathansteward), [LinkedIn](https://www.linkedin.com/in/jonathansteward97) | | **[Kyle Cain](engineers/kfcain.md)** | Cloud Security, Compliance Automation, Identity & Access Management, Risk Management, Security Architecture, Security Governance, Security Operations, Third-Party Risk, Vulnerability Management | CMMC, FedRAMP, GovRAMP, ISO 27001, ISO 42001, NIST 800-53, NIST 800-171 | [GitHub](https://github.com/kfcain), [LinkedIn](https://www.linkedin.com/in/kylecain) | | **[Fola Falusi](engineers/kraneduper.md)** | Audit & Assurance, Cloud Security, Compliance Automation, Offensive Security, Risk Management, Security Architecture, Security Governance, Security Operations, Vulnerability Management | ISO 27001, NIST 800-53, NIST CSF, NIST RMF, PCI-DSS | [GitHub](https://github.com/kraneduper), [LinkedIn](https://www.linkedin.com/in/folajimi-falusi/) | From 8212b02b17eae280c576b33d33c096fcbb741822 Mon Sep 17 00:00:00 2001 From: Ethan Troy <63926014+ethanolivertroy@users.noreply.github.com> Date: Tue, 7 Apr 2026 01:46:55 -0400 Subject: [PATCH 02/17] feat: launch jobs board and harden profile submission flow - add ATS-backed jobs board pages, layouts, filters, and search UI - import curated Greenhouse and Ashby roles plus automation workflows - surface jobs across the site and wire Eleventy collections/filters - harden the GitHub-native profile submission handoff and review workflow - add repository contributor guidelines --- .eleventy.js | 131 ++- .github/workflows/deploy-site.yml | 2 + .github/workflows/import-jobs.yml | 40 + .github/workflows/process-submission.yml | 96 +- .gitignore | 1 + AGENTS.md | 19 + jobs/_template.md | 44 + jobs/imported/.gitkeep | 1 + ...rd-8880085e-5005-4dcd-b186-58f42e6a1766.md | 151 +++ ...an-7120f73f-e653-4316-9d1a-590aa3cb2911.md | 118 +++ ...nt-333a7528-e47d-419f-839f-71f76b5620e1.md | 81 ++ ...nt-e24389db-8ae7-4dc2-9e7d-5cb60ba2f2d1.md | 119 +++ ...oe-8d491b45-092a-40c9-809c-1751f1c7a56f.md | 103 ++ ...bs-f80d0420-b6e6-4110-940c-293f64b9761e.md | 82 ++ ...rs-5526c955-fb96-4277-a93a-f66e322bcfab.md | 118 +++ ...re-3f47391b-d305-43e0-b84c-7877e09fc633.md | 86 ++ ...re-b66e4c7c-ef37-42fc-939e-6ece4e99b57b.md | 118 +++ ...da-0ca9bb78-6d6b-4b71-8f77-762f0b16b959.md | 95 ++ ...ey-45ce8f3e-1278-4a44-8f92-fed595a6ad1a.md | 85 ++ ...on-d1623131-b5bf-4679-bcc5-49e2df569fd7.md | 67 ++ ...mp-9912212c-2edd-4bdb-a18c-1087bcae0522.md | 101 ++ ...it-3475841f-c994-4443-b83d-4b8a5b1dd8f2.md | 128 +++ ...re-b9dc8d7e-9f0e-40e7-876e-82eedcaa6017.md | 113 +++ ...er-2702b1ce-58ce-4884-bc43-b47cc1bc1f23.md | 81 ++ ...er-5d7cf717-bfdc-4695-b49e-894786850d5d.md | 86 ++ ...s-5087188007-senior-compliance-engineer.md | 174 ++++ ...0335008-grc-automation-engineering-lead.md | 84 ++ ...7008-security-risk-and-compliance-hipaa.md | 87 ++ ...ion-4672836005-risk-and-compliance-lead.md | 68 ++ ...ms-7643179003-cybersecurity-grc-manager.md | 89 ++ ...ity-compliance-public-sector-specialist.md | 100 ++ ...eblocks-4618281006-technical-grc-expert.md | 68 ++ ...ks-4620939006-grc-operations-specialist.md | 57 ++ ...greenhouse-idme-7661659003-grc-engineer.md | 71 ++ ...666086003-grc-technical-program-manager.md | 58 ++ ...ood-7676724-senior-security-grc-analyst.md | 78 ++ ...ood-7724385-senior-security-grc-analyst.md | 76 ++ ...ernance-risk-and-compliance-grc-manager.md | 130 +++ ...ernance-risk-and-compliance-grc-manager.md | 130 +++ ...nhouse-spycloud-7677705003-grc-engineer.md | 153 +++ ...use-vercel-5836016004-staff-grc-analyst.md | 79 ++ ...-manager-fedramp-il5-and-il6-compliance.md | 118 +++ ...vernance-risk-and-compliance-specialist.md | 122 +++ ...e-risk-and-compliance-manager-nist-fair.md | 121 +++ jobs/jobs.11tydata.js | 28 + package.json | 3 +- scripts/import-jobs.js | 608 ++++++++++++ scripts/job-board-sources.js | 39 + site/_includes/layouts/base.njk | 3 + site/_includes/layouts/job.njk | 132 +++ site/_includes/partials/job-card.njk | 64 ++ site/_includes/partials/job-filter-bar.njk | 78 ++ site/assets/css/style.css | 400 +++++++- site/assets/js/jobs-search.js | 211 +++++ site/assets/js/submit.js | 889 +++++++++++++----- site/index.njk | 25 + site/jobs.njk | 47 + site/submit.njk | 54 +- 58 files changed, 6193 insertions(+), 317 deletions(-) create mode 100644 .github/workflows/import-jobs.yml create mode 100644 AGENTS.md create mode 100644 jobs/_template.md create mode 100644 jobs/imported/.gitkeep create mode 100644 jobs/imported/ashby/ashby-1password-8880085e-5005-4dcd-b186-58f42e6a1766.md create mode 100644 jobs/imported/ashby/ashby-atlan-7120f73f-e653-4316-9d1a-590aa3cb2911.md create mode 100644 jobs/imported/ashby/ashby-confluent-333a7528-e47d-419f-839f-71f76b5620e1.md create mode 100644 jobs/imported/ashby/ashby-confluent-e24389db-8ae7-4dc2-9e7d-5cb60ba2f2d1.md create mode 100644 jobs/imported/ashby/ashby-crusoe-8d491b45-092a-40c9-809c-1751f1c7a56f.md create mode 100644 jobs/imported/ashby/ashby-elevenlabs-f80d0420-b6e6-4110-940c-293f64b9761e.md create mode 100644 jobs/imported/ashby/ashby-hims-and-hers-5526c955-fb96-4277-a93a-f66e322bcfab.md create mode 100644 jobs/imported/ashby/ashby-junipersquare-3f47391b-d305-43e0-b84c-7877e09fc633.md create mode 100644 jobs/imported/ashby/ashby-junipersquare-b66e4c7c-ef37-42fc-939e-6ece4e99b57b.md create mode 100644 jobs/imported/ashby/ashby-lambda-0ca9bb78-6d6b-4b71-8f77-762f0b16b959.md create mode 100644 jobs/imported/ashby/ashby-monarchmoney-45ce8f3e-1278-4a44-8f92-fed595a6ad1a.md create mode 100644 jobs/imported/ashby/ashby-notion-d1623131-b5bf-4679-bcc5-49e2df569fd7.md create mode 100644 jobs/imported/ashby/ashby-ramp-9912212c-2edd-4bdb-a18c-1087bcae0522.md create mode 100644 jobs/imported/ashby/ashby-replit-3475841f-c994-4443-b83d-4b8a5b1dd8f2.md create mode 100644 jobs/imported/ashby/ashby-socure-b9dc8d7e-9f0e-40e7-876e-82eedcaa6017.md create mode 100644 jobs/imported/ashby/ashby-writer-2702b1ce-58ce-4884-bc43-b47cc1bc1f23.md create mode 100644 jobs/imported/ashby/ashby-writer-5d7cf717-bfdc-4695-b49e-894786850d5d.md create mode 100644 jobs/imported/greenhouse/greenhouse-andurilindustries-5087188007-senior-compliance-engineer.md create mode 100644 jobs/imported/greenhouse/greenhouse-anthropic-4980335008-grc-automation-engineering-lead.md create mode 100644 jobs/imported/greenhouse/greenhouse-anthropic-5160757008-security-risk-and-compliance-hipaa.md create mode 100644 jobs/imported/greenhouse/greenhouse-appliedintuition-4672836005-risk-and-compliance-lead.md create mode 100644 jobs/imported/greenhouse/greenhouse-cerebrassystems-7643179003-cybersecurity-grc-manager.md create mode 100644 jobs/imported/greenhouse/greenhouse-cloudflare-7477769-data-centre-security-compliance-public-sector-specialist.md create mode 100644 jobs/imported/greenhouse/greenhouse-fireblocks-4618281006-technical-grc-expert.md create mode 100644 jobs/imported/greenhouse/greenhouse-fireblocks-4620939006-grc-operations-specialist.md create mode 100644 jobs/imported/greenhouse/greenhouse-idme-7661659003-grc-engineer.md create mode 100644 jobs/imported/greenhouse/greenhouse-idme-7666086003-grc-technical-program-manager.md create mode 100644 jobs/imported/greenhouse/greenhouse-robinhood-7676724-senior-security-grc-analyst.md create mode 100644 jobs/imported/greenhouse/greenhouse-robinhood-7724385-senior-security-grc-analyst.md create mode 100644 jobs/imported/greenhouse/greenhouse-sigmacomputing-7690372003-governance-risk-and-compliance-grc-manager.md create mode 100644 jobs/imported/greenhouse/greenhouse-sigmacomputing-7690373003-governance-risk-and-compliance-grc-manager.md create mode 100644 jobs/imported/greenhouse/greenhouse-spycloud-7677705003-grc-engineer.md create mode 100644 jobs/imported/greenhouse/greenhouse-vercel-5836016004-staff-grc-analyst.md create mode 100644 jobs/imported/greenhouse/greenhouse-zscaler-4940338007-federal-compliance-program-manager-fedramp-il5-and-il6-compliance.md create mode 100644 jobs/imported/greenhouse/greenhouse-zscaler-5020699007-senior-governance-risk-and-compliance-specialist.md create mode 100644 jobs/imported/greenhouse/greenhouse-zscaler-5043550007-senior-governance-risk-and-compliance-manager-nist-fair.md create mode 100644 jobs/jobs.11tydata.js create mode 100644 scripts/import-jobs.js create mode 100644 scripts/job-board-sources.js create mode 100644 site/_includes/layouts/job.njk create mode 100644 site/_includes/partials/job-card.njk create mode 100644 site/_includes/partials/job-filter-bar.njk create mode 100644 site/assets/js/jobs-search.js create mode 100644 site/jobs.njk diff --git a/.eleventy.js b/.eleventy.js index ce53c1e..edb9f92 100644 --- a/.eleventy.js +++ b/.eleventy.js @@ -1,9 +1,60 @@ +function toValidDate(value) { + if (!value) return null; + const date = new Date(value); + return Number.isNaN(date.getTime()) ? null : date; +} + +function sortByRecent(a, b) { + const aDate = toValidDate(a.data.posted_date) || toValidDate(a.date) || new Date(0); + const bDate = toValidDate(b.data.posted_date) || toValidDate(b.date) || new Date(0); + return bDate - aDate; +} + +function isLiveJob(data) { + const status = String(data.status || "published").toLowerCase(); + if (["draft", "expired", "filled", "archived"].includes(status)) return false; + + const expires = toValidDate(data.expires_date); + if (!expires) return true; + + const today = new Date(); + today.setHours(0, 0, 0, 0); + return expires >= today; +} + +function asArray(value) { + if (Array.isArray(value)) return value; + if (value === undefined || value === null || value === "") return []; + return [value]; +} + +function normalizedSet(values) { + return new Set(asArray(values).map((item) => String(item).toLowerCase())); +} + +function overlapScore(sourceSet, values, weight) { + return asArray(values).reduce((score, value) => { + return score + (sourceSet.has(String(value).toLowerCase()) ? weight : 0); + }, 0); +} + module.exports = function (eleventyConfig) { eleventyConfig.ignores.add("README.md"); + eleventyConfig.ignores.add("AGENTS.md"); + eleventyConfig.ignores.add("CLAUDE.md"); eleventyConfig.ignores.add("CONTRIBUTING.md"); eleventyConfig.ignores.add("CODE_OF_CONDUCT.md"); + eleventyConfig.ignores.add("snapshot-nav.md"); + eleventyConfig.ignores.add(".impeccable.md"); eleventyConfig.ignores.add(".github/**"); + eleventyConfig.ignores.add(".agent/**"); + eleventyConfig.ignores.add(".agents/**"); + eleventyConfig.ignores.add(".claude/**"); + eleventyConfig.ignores.add(".crush/**"); + eleventyConfig.ignores.add(".kiro/**"); eleventyConfig.ignores.add("engineers/_template.md"); + eleventyConfig.ignores.add("jobs/_template.md"); + eleventyConfig.ignores.add("jobs/**/_template.md"); eleventyConfig.addCollection("engineers", function (api) { return api @@ -11,21 +62,33 @@ module.exports = function (eleventyConfig) { .filter((item) => item.page.fileSlug !== "_template"); }); + eleventyConfig.addCollection("allJobs", function (api) { + return api + .getFilteredByGlob("jobs/**/*.md") + .filter((item) => !String(item.page.fileSlug || "").startsWith("_")) + .sort(sortByRecent); + }); + + eleventyConfig.addCollection("jobs", function (api) { + return api + .getFilteredByGlob("jobs/**/*.md") + .filter((item) => !String(item.page.fileSlug || "").startsWith("_")) + .filter((item) => isLiveJob(item.data)) + .sort(sortByRecent); + }); + eleventyConfig.addPassthroughCopy("site/assets"); eleventyConfig.addPassthroughCopy({ "site/CNAME": "CNAME" }); eleventyConfig.addFilter("uniqueValues", function (collection, field) { const seen = new Map(); collection.forEach((item) => { - const arr = item.data[field]; - if (Array.isArray(arr)) { - arr.forEach((v) => { - if (v) { - const key = v.toLowerCase(); - if (!seen.has(key)) seen.set(key, v); - } - }); - } + asArray(item.data[field]).forEach((v) => { + if (v) { + const key = String(v).toLowerCase(); + if (!seen.has(key)) seen.set(key, v); + } + }); }); return [...seen.values()].sort((a, b) => a.toLowerCase().localeCompare(b.toLowerCase()) @@ -36,16 +99,13 @@ module.exports = function (eleventyConfig) { const counts = {}; const canonical = {}; collection.forEach((item) => { - const arr = item.data[field]; - if (Array.isArray(arr)) { - arr.forEach((v) => { - if (v) { - const key = v.toLowerCase(); - if (!canonical[key]) canonical[key] = v; - counts[key] = (counts[key] || 0) + 1; - } - }); - } + asArray(item.data[field]).forEach((v) => { + if (v) { + const key = String(v).toLowerCase(); + if (!canonical[key]) canonical[key] = v; + counts[key] = (counts[key] || 0) + 1; + } + }); }); return Object.entries(counts) .sort((a, b) => b[1] - a[1]) @@ -70,6 +130,39 @@ module.exports = function (eleventyConfig) { return social.urlPrefix ? social.urlPrefix + value : value; }); + eleventyConfig.addFilter("readableDate", function (value) { + const date = toValidDate(value); + if (!date) return value; + return new Intl.DateTimeFormat("en-US", { + month: "short", + day: "numeric", + year: "numeric" + }).format(date); + }); + + eleventyConfig.addFilter("relatedEngineers", function (engineers, specializations, frameworks, languages, limit) { + const specSet = normalizedSet(specializations); + const frameworkSet = normalizedSet(frameworks); + const languageSet = normalizedSet(languages); + + return (engineers || []) + .map((engineer) => { + const score = + overlapScore(specSet, engineer.data.specializations, 4) + + overlapScore(frameworkSet, engineer.data.frameworks, 2) + + overlapScore(languageSet, engineer.data.languages, 1); + + return { engineer, score }; + }) + .filter((item) => item.score > 0) + .sort((a, b) => { + if (b.score !== a.score) return b.score - a.score; + return a.engineer.data.name.localeCompare(b.engineer.data.name); + }) + .slice(0, limit || 3) + .map((item) => item.engineer); + }); + return { dir: { input: ".", diff --git a/.github/workflows/deploy-site.yml b/.github/workflows/deploy-site.yml index db77ac8..99d9e43 100644 --- a/.github/workflows/deploy-site.yml +++ b/.github/workflows/deploy-site.yml @@ -4,7 +4,9 @@ on: branches: [main] paths: - 'engineers/*.md' + - 'jobs/**' - 'site/**' + - 'scripts/**' - '.eleventy.js' - 'package.json' - 'package-lock.json' diff --git a/.github/workflows/import-jobs.yml b/.github/workflows/import-jobs.yml new file mode 100644 index 0000000..3f77fbf --- /dev/null +++ b/.github/workflows/import-jobs.yml @@ -0,0 +1,40 @@ +name: Import Jobs + +on: + schedule: + - cron: '17 11 * * *' + workflow_dispatch: + +jobs: + import-jobs: + runs-on: ubuntu-latest + permissions: + contents: write + + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Setup Node + uses: actions/setup-node@v4 + with: + node-version: 20 + cache: npm + + - name: Install dependencies + run: npm ci + + - name: Import jobs + env: + GREENHOUSE_BOARDS: ${{ secrets.GREENHOUSE_BOARDS }} + ASHBY_JOB_BOARDS: ${{ secrets.ASHBY_JOB_BOARDS }} + run: npm run import:jobs + + - name: Commit and push changes + run: | + git config --local user.email "github-actions[bot]@users.noreply.github.com" + git config --local user.name "github-actions[bot]" + git add jobs + git diff --staged --quiet || git commit -m "docs: refresh imported jobs" + git pull --rebase origin main + git push diff --git a/.github/workflows/process-submission.yml b/.github/workflows/process-submission.yml index 3b6a0f8..da8a254 100644 --- a/.github/workflows/process-submission.yml +++ b/.github/workflows/process-submission.yml @@ -21,14 +21,55 @@ jobs: const issue = context.payload.issue; const body = issue.body || ''; - // --- Extract markdown from code fence --- - const match = body.match(/\s*```yaml\n([\s\S]*?)```/); - if (!match) { + function parseSubmissionBody(issueBody) { + const encodedMatch = issueBody.match( + /\s*([A-Za-z0-9+/=\s]+?)\s*/ + ); + + if (encodedMatch) { + const encoded = encodedMatch[1].replace(/\s+/g, ''); + const decoded = Buffer.from(encoded, 'base64').toString('utf8'); + const payload = JSON.parse(decoded); + if (!payload || typeof payload.markdown !== 'string' || !payload.markdown.trim()) { + throw new Error('Submission payload did not contain markdown.'); + } + return payload.markdown; + } + + const legacyMatch = issueBody.match(/\s*```yaml\n([\s\S]*?)```/); + if (legacyMatch) { + return legacyMatch[1]; + } + + return null; + } + + let content; + try { + content = parseSubmissionBody(body); + } catch (error) { + await github.rest.issues.createComment({ + owner: context.repo.owner, + repo: context.repo.repo, + issue_number: issue.number, + body: '❌ We could not decode the submission payload in this issue. Please return to the [submission form](https://directory.grcengclub.com/submit/), copy a fresh payload, and submit a new issue.' + }); + await github.rest.issues.update({ + owner: context.repo.owner, + repo: context.repo.repo, + issue_number: issue.number, + state: 'closed', + state_reason: 'not_planned' + }); + return; + } + + if (!content) { await github.rest.issues.createComment({ owner: context.repo.owner, repo: context.repo.repo, issue_number: issue.number, - body: '❌ Could not parse profile content from this issue. Please use the [submission form](https://directory.grcengclub.com/submit/) to resubmit.' + body: '❌ Could not find a valid submission payload in this issue. Please return to the [submission form](https://directory.grcengclub.com/submit/), paste the copied payload into the issue body, and submit a new issue.' }); await github.rest.issues.update({ owner: context.repo.owner, @@ -39,7 +80,6 @@ jobs: }); return; } - const content = match[1]; // --- Parse required fields from YAML frontmatter --- const ghMatch = content.match(/^github:\s*"([^"]+)"/m); @@ -59,7 +99,8 @@ jobs: }); return; } - const username = ghMatch[1]; + const username = ghMatch[1].trim(); + const normalizedUsername = username.toLowerCase(); const nameMatch = content.match(/^name:\s*"([^"]+)"/m); const profileName = nameMatch ? nameMatch[1] : username; @@ -87,7 +128,7 @@ jobs: return; } - const filename = `engineers/${username}.md`; + const filename = `engineers/${normalizedUsername}.md`; // --- Label the issue for bookkeeping --- try { @@ -101,19 +142,45 @@ jobs: // Label may not exist yet — not critical } - // --- Check if profile already exists --- - try { - await github.rest.repos.getContent({ + async function findExistingProfileByGithub() { + const entries = await github.rest.repos.getContent({ owner: context.repo.owner, repo: context.repo.repo, - path: filename, + path: 'engineers', ref: 'main' }); + + for (const entry of entries.data) { + if (entry.type !== 'file' || !entry.name.endsWith('.md') || entry.name === '_template.md') { + continue; + } + + const file = await github.rest.repos.getContent({ + owner: context.repo.owner, + repo: context.repo.repo, + path: entry.path, + ref: 'main' + }); + + const fileContent = Buffer.from(file.data.content, 'base64').toString('utf8'); + const fileGithubMatch = fileContent.match(/^github:\s*"?(.*?)"?$/m); + if (!fileGithubMatch) continue; + + if (fileGithubMatch[1].trim().toLowerCase() === normalizedUsername) { + return entry.path; + } + } + + return null; + } + + const existingProfilePath = await findExistingProfileByGithub(); + if (existingProfilePath) { await github.rest.issues.createComment({ owner: context.repo.owner, repo: context.repo.repo, issue_number: issue.number, - body: `⚠️ A profile for **@${username}** already exists. If you'd like to update it, please open a pull request editing \`${filename}\` directly.` + body: `⚠️ A profile for **@${username}** already exists at \`${existingProfilePath}\`. If you'd like to update it, please open a pull request editing that file directly.` }); await github.rest.issues.update({ owner: context.repo.owner, @@ -123,9 +190,6 @@ jobs: state_reason: 'completed' }); return; - } catch (e) { - if (e.status !== 404) throw e; - // File doesn't exist — proceed } // --- Create branch --- @@ -135,7 +199,7 @@ jobs: ref: 'heads/main' }); - const branchName = `profile/${username}`; + const branchName = `profile/${normalizedUsername}`; try { await github.rest.git.createRef({ owner: context.repo.owner, diff --git a/.gitignore b/.gitignore index 9650b89..21cafc1 100644 --- a/.gitignore +++ b/.gitignore @@ -2,3 +2,4 @@ _site/ node_modules/ .playwright-mcp/ *.png +.firecrawl/ diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..bdfa60d --- /dev/null +++ b/AGENTS.md @@ -0,0 +1,19 @@ +# Repository Guidelines + +## Project Structure & Module Organization +This repository is an Eleventy-powered static site for the GRC Engineer Directory. Content lives in `engineers/*.md`; each file is one profile page and must follow the schema in `engineers/_template.md`. Site templates and page sources live under `site/`, especially `site/_includes/layouts/`, `site/_includes/partials/`, and `site/_data/`. Frontend assets are in `site/assets/css/` and `site/assets/js/`. Build output is generated into `_site/` and should not be committed by hand. Automation and validation rules live in `.github/workflows/`. + +## Build, Test, and Development Commands +Install dependencies once with `npm install`. Use `npm run serve` to start Eleventy with live reload at `http://localhost:8080`. Use `npm run build` to generate the production site in `_site/`. There is no separate unit test suite; the main local verification step is a clean build plus checking the rendered pages in the dev server. + +## Coding Style & Naming Conventions +Follow the existing style: 2-space indentation in JavaScript, JSON, Nunjucks, and YAML frontmatter; semicolons in JS; and straightforward ES5-style browser code unless a file already uses newer syntax. Keep template and asset filenames kebab-case, such as `engineer-card.njk` and `filter-bar.njk`. Engineer profile filenames must match the `github` frontmatter value exactly: `engineers/.md`. + +## Testing & Validation Guidelines +Before opening a PR, run `npm run build` and confirm the relevant page renders correctly. For profile submissions, verify required frontmatter fields (`name`, `github`, `specializations`) and keep links well-formed. The `validate-submission.yml` workflow rejects mismatched filenames, invalid GitHub usernames, empty specializations, and dangerous HTML in markdown bodies. + +## Commit & Pull Request Guidelines +Recent history uses short imperative prefixes like `fix:`, `docs:`, `improve:`, and `redesign:`. Keep commit subjects brief and descriptive, for example `fix: tighten homepage filter spacing`. For PRs, follow `.github/PULL_REQUEST_TEMPLATE/engineer-submission.md`, keep changes scoped, and explain any content or layout impact. For profile additions, include the profile summary and checklist; for UI changes, add screenshots when the rendered result changes. + +## Content & Automation Notes +Do not hand-edit generated README table entries between `BEGIN_ENGINEER_LIST` markers; the update workflow rewrites that section. Avoid inline scripts or embedded HTML in profile bodies, and prefer standard Markdown plus frontmatter-driven data. diff --git a/jobs/_template.md b/jobs/_template.md new file mode 100644 index 0000000..47f6de3 --- /dev/null +++ b/jobs/_template.md @@ -0,0 +1,44 @@ +--- +title: "Senior GRC Engineer" +company: "Example Security" +slug: "example-security-senior-grc-engineer" +status: "published" +source: "Manual" +sources: + - "Manual" +source_url: "https://example.com/careers" +role_url: "https://example.com/careers/senior-grc-engineer" +apply_url: "https://example.com/careers/senior-grc-engineer" +posted_date: "2026-04-06" +expires_date: "2026-05-06" +location: "Remote — United States" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" +frameworks: + - "FedRAMP" + - "SOC 2" +languages: + - "Python" + - "Terraform" +compensation: "$170k - $210k" +summary: "Lead automation and control engineering across a growing GRC platform." +--- + +## Role overview + +Describe the role, team, and mission in plain language. + +## What you'll work on + +- Major responsibility +- Major responsibility +- Major responsibility + +## Why this role fits the directory + +Explain the frameworks, specializations, and tools the job actually uses so engineer matching works well. diff --git a/jobs/imported/.gitkeep b/jobs/imported/.gitkeep new file mode 100644 index 0000000..8b13789 --- /dev/null +++ b/jobs/imported/.gitkeep @@ -0,0 +1 @@ + diff --git a/jobs/imported/ashby/ashby-1password-8880085e-5005-4dcd-b186-58f42e6a1766.md b/jobs/imported/ashby/ashby-1password-8880085e-5005-4dcd-b186-58f42e6a1766.md new file mode 100644 index 0000000..608a985 --- /dev/null +++ b/jobs/imported/ashby/ashby-1password-8880085e-5005-4dcd-b186-58f42e6a1766.md @@ -0,0 +1,151 @@ +--- +title: "Senior Security Engineer, GRC Automation" +company: "1password" +slug: "ashby-1password-8880085e-5005-4dcd-b186-58f42e6a1766" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/1password?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/1password/8880085e-5005-4dcd-b186-58f42e6a1766" +apply_url: "https://jobs.ashbyhq.com/1password/8880085e-5005-4dcd-b186-58f42e6a1766/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "Remote (United States | Canada)" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST 800-53" +languages: + - "Python" + - "JavaScript" + - "Rust" +compensation: "" +summary: "1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming..." +--- + +1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. + +About 1Password + +At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work. + +If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future. + +Trust is earned — and we’re building the systems to earn it at scale. 1Password is looking for a Senior Security Engineer – GRC to design and implement automation, dashboards, and integrations that power our Governance, Risk, and Compliance (GRC) operations. + +You’ll partner directly with the Senior Manager of GRC to build automation that scales our security and privacy commitments — from audit readiness and policy enforcement to customer trust workflows. A key focus for this role will be operationalizing our newly selected GRC platform , integrating it with our internal systems, and ensuring it supports automated, scalable assurance processes across the organization. + +This is a hands-on technical role for someone who’s passionate about making GRC repeatable, visible, and built into how the company works. It sits at the intersection of security engineering, compliance, and platform operations — ideal for someone with a solutions engineering or DevSecOps background who thrives in high-context, high-impact environments. + +This is a remote opportunity within the US or Canada. + +What we're looking for: + +- 5+ years of experience in security engineering, DevSecOps, solutions engineering, or GRC automation roles. +- Proven experience working with GRC, compliance, or audit teams to build automation that supports evidence collection, control testing, or security monitoring. +- Direct experience implementing and integrating GRC platforms (e.g., Drata, Vanta, Tines, JupiterOne) into production environments. +- Strong scripting and integration skills using Python, JavaScript, APIs, webhooks, or workflow automation tools. +- Ability to work cross-functionally with Security, Compliance, Legal, and Infrastructure teams to translate policies into scalable technical systems. +- Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53, and how they map to real-world infrastructure and operations. +- Experience applying automation or AI tools to improve GRC, audit, or assurance workflows, with an understanding of validation, accuracy, and trust tradeoffs. +- Familiarity with AI governance, privacy, and security considerations for LLMs and agentic systems (e.g., sensitive data exposure, prompt injection, system misuse). +- Ability to evaluate where AI-driven approaches are appropriate in GRC workflows versus where deterministic controls and human review are required. +- Builder mindset with modern tools (including AI), with the ability to experiment, evaluate, and operationalize solutions rather than only consume them. + +Bonus points if you have: + +- Hands-on experience with event-driven automation platforms like Tines and their use in control validation and alerting. +- Expertise in building evidence pipelines, tagging telemetry, or creating GRC dashboards (e.g., Looker, Metabase). +- Strong understanding of cloud-native security architecture and its relationship to compliance controls (e.g., AWS IAM, encryption, logging). +- Experience working in customer trust, privacy engineering, or supporting sales/GTM teams with compliance assurance content. +- Experience supporting AI governance, AI risk assessments, or privacy-by-design reviews for AI-enabled systems. +- Experience applying AI to audit, compliance, or third-party risk workflows in a way that improves scale while preserving trust, traceability, and human oversight. + +What you can expect: + +- Lead the implementation and integration of our GRC platform, ensuring it is fully operationalized across key systems and workflows. +- Build automated workflows for control testing, evidence collection, and audit readiness. +- Develop and maintain integrations between the GRC platform and systems of record (e.g., ticketing systems, IAM, asset inventories, configuration management). +- Design dashboards and reporting to track control health, trust signals, and audit performance. +- Collaborate with teams across Security, GRC, and Engineering to embed compliance into operational processes such as onboarding, change management, and incident response. +- Shape the roadmap for automated, resilient internal assurance infrastructure that grows alongside the business. +- Help define and operationalize scalable assurance approaches for internal AI usage and AI-enabled product capabilities. +- Build automated workflows that support AI governance activities such as control mapping, policy enforcement, and audit readiness. +- Partner with Security, Privacy, Legal, Product, and Engineering to translate AI-related trust and compliance requirements into practical, measurable systems and controls. +- Evaluate and improve how GRC processes account for non-deterministic systems, connected AI agents, and AI-powered third-party vendors. + +USA-based roles only: The annual base salary for this role is between $156,000 USD and $210,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. + +Canada-based roles only: The annual base salary for this role is between $143,000 CAD and $193,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. + +At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. + +This posting is for an existing vacancy. + +Our culture + +At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first. + +You’ll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone (https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/). Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We’re looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results. + +How we work with AI + +We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged—it's an essential part of how we will be successful at 1Password. + +This approach extends to our hiring process—candidates are welcome to use AI tools responsibly and thoughtfully during the application process. + +Our approach to remote work + +We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events. + +What we offer + +We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: + +Health and wellbeing + +👶 Maternity and parental leave top-up programs + +🩺 Competitive health benefits + +🏝 Generous PTO policy + +Growth and future + +📈 RSU program for most employees + +💸 Retirement matching program + +🔑 Free 1Password account + +Community + +🤝 Paid volunteer days + +🏆 Peer-to-peer recognition through Bonusly + +🌎 Remote-first work environment + +*Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting. + +You belong here. + +1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love. + +Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we’ll work to meet your needs. + +Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you. + +Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law. + +1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here (https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf) for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form (https://jobs.ashbyhq.com/1password/automation-notice) . For additional information see our Candidate Privacy Notice (https://1password.com/files/candidate-privacy-notice.pdf) . diff --git a/jobs/imported/ashby/ashby-atlan-7120f73f-e653-4316-9d1a-590aa3cb2911.md b/jobs/imported/ashby/ashby-atlan-7120f73f-e653-4316-9d1a-590aa3cb2911.md new file mode 100644 index 0000000..bb4db16 --- /dev/null +++ b/jobs/imported/ashby/ashby-atlan-7120f73f-e653-4316-9d1a-590aa3cb2911.md @@ -0,0 +1,118 @@ +--- +title: "Sr. GRC Engineer" +company: "Atlan" +slug: "ashby-atlan-7120f73f-e653-4316-9d1a-590aa3cb2911" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/atlan?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/atlan/7120f73f-e653-4316-9d1a-590aa3cb2911" +apply_url: "https://jobs.ashbyhq.com/atlan/7120f73f-e653-4316-9d1a-590aa3cb2911/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "India" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "FedRAMP" + - "SOC 2" + - "ISO 27001" + - "ISO 42001" + - "HIPAA" +languages: + - "Rust" +compensation: "" +summary: "Who We Are Atlan is building the missing context layer for data and AI, helping enterprises close the AI value chasm. Today, 95% of AI pilots fail because AI systems don’t..." +--- + +## Who We Are + +Atlan is building the missing context layer for data and AI, helping enterprises close the AI value chasm. Today, 95% of AI pilots fail because AI systems don’t understand the context behind data: what it means, how it’s governed, and how it should be used. + +Atlan connects to every part of the modern data and AI stack to unify this context into a single, shared layer that both humans and AI agents can rely on. With Atlan, teams can discover, understand, and trust their data; build and collaborate on a shared body of knowledge; and activate that context across analytics, operations, and AI workflows.Trusted by global enterprises like Mastercard, Workday, General Motors, Unilever, Ralph Lauren, FOX, Nasdaq, and Medtronic , we’re backed by world-class investors including GIC, Insight Partners, Meritech, Peak XV, and Salesforce Ventures + +Why this Role Matters? + +At Atlan, compliance isn't overhead — it's a competitive advantage that closes deals. We serve 450+ enterprise customers across healthcare, finance, and other regulated industries where security posture directly influences buying decisions. + +You'll own and mature our compliance program across SOC 2, ISO 27001, ISO 42001, GDPR, and HIPAA — while building toward next-generation certifications like FedRAMP. But this isn't a maintenance role. You're joining as the technical architect of our Continuous GRC Maturity Program: a 12-month, executive-sponsored initiative to transform compliance from manual firefighting into automated, scalable infrastructure. + +This role sits on our GRC & Platform Security team and operates with significant autonomy. If you've ever thought "there has to be a better way to do compliance," this is your chance to build it. + +What you'll own + +- Compliance program maturity — Lead end-to-end audit execution across SOC 2, ISO 27001, ISO 42001, ISO 27701, HIPAA, and GDPR. Own auditor relationships, coordinate cross-functional evidence collection, and maintain year-round audit readiness. +- Next-generation framework adoption — Drive FedRAMP readiness: assess platform gaps, build roadmaps, and turn new certifications into planned projects rather than fire drills. +- Enterprise risk management — Build and mature Atlan's risk management program. Identify, assess, and track risks across security, operational, compliance, and third-party domains. Turn abstract risk conversations into measurable metrics with clear ownership and quarterly leadership reviews. +- Third-party risk management — Own Atlan's vendor security assessment program end-to-end: tiered vendor reviews, security questionnaires, risk scoring, and ongoing monitoring. Balance vendor risk against business need at scale. +- Compliance automation infrastructure — Integrate our GRC platform with cloud infrastructure, CI/CD pipelines, HR systems, and product engineering tooling to automate evidence collection and continuous control testing. Reduce manual audit prep effort significantly. +- Controls that prove themselves — Partner with engineering and product teams to design technical controls that automatically generate auditable evidence. Implement continuous testing that catches gaps before auditors do. +- Continuous controls monitoring — Design and operate real-time visibility into control effectiveness: automated dashboards, live control status, and alerting that surfaces gaps before audit cycles begin — not during them. +- Organizational compliance capability — Build awareness programs, run training for engineering and cross-functional teams, and create self-service dashboards that make compliance easy. Make secure-by-default the path of least resistance. + +What makes you a strong match + +Compliance depth + +- 5+ years owning SOC 2 Type II and/or ISO 27001 audits end-to-end — you've been the point person coordinating auditors, collecting evidence, and managing findings +- Hands-on experience across multiple frameworks: SOC 2, ISO 27001, ISO 42001, and at least two of GDPR, HIPAA, ISO 27701, FedRAMP, or CCPA +- Regulatory intelligence mindset — you track emerging requirements and build readiness roadmaps before compliance becomes urgent + +Technical automation + +- Experience with modern GRC platforms (Vanta, Drata, Secureframe, or similar) extended via API — not just out-of-box configuration +- Comfortable with REST APIs, JSON, OAuth, and CI/CD integrations + +Program and stakeholder maturity + +- Built or maintained risk registers, facilitated leadership risk reviews, and turned risk conversations into concrete action plans +- Customer-facing experience: security questionnaires, trust portals, or supporting enterprise sales cycles with compliance documentation +- Able to influence engineering, product, HR, legal, and IT without formal authority — you're an enabler, not a gatekeeper + +AI-augmented GRC + +- You actively use AI tools to accelerate compliance work: drafting control narratives, triaging risk findings, generating evidence summaries, and building AI-assisted workflows for continuous monitoring. +- You understand enough about AI systems to assess their risk implications — not just use them as productivity tools. + +High agency + +- You drive toward outcomes without waiting for perfect requirements. +- You identify problems and build solutions. +- You thrive in ambiguity. + +Nice to have + +- CISA, CRISC, CISM, or CGRC certification +- FedRAMP or NIST framework hands-on implementation experience +- Prior security engineering background before moving into GRC +- Vanta Trust Center or similar trust portal experience +- Hands-on experience applying AI/LLMs to GRC workflows — automated questionnaire responses, AI-assisted risk triage, policy generation, or compliance gap analysis + +## Why Atlan? + +Joining Atlan means being part of a global movement to help data teams do their life’s best work. Here’s what you can expect: + +- Competitive Compensation: We benchmark at the top of the market and keep compensation simple: strong base salary, performance‑based variable pay, and impact‑driven equity (for most roles), so your total rewards grow in step with the value you create over time. +- AI Native Culture: Atlan is where AI-native builders come to build the systems the future of work will run on. AI isn’t an add-on, it’s woven into how we build, think, and work every day, empowering every Atlanian to move faster and create a bigger impact. +- Health & Wellness : From Day‑1 health, dental, vision, and mental health to flexible health stipends, we design benefits offerings that lead in each country we're in. +- Flexible Time Off & Leave Policies: We trust you to own your energy: flexible time off and modern leave so you can unplug properly, support yourself and your loved ones, and come back ready to drive an impact. +- Accelerated Growth & Learning: Develop at an uncommon velocity through cutting-edge tech, complex implementations, and an experienced team that values mastery. +- Global, Remote-First, High-Trust: Work from anywhere with a diverse team across 15+ countries, in a trust-first, async environment that gives you true flexibility and ownership over how you work. + +## More About Us + +Atlan is building the shared context layer that enterprises need so AI can operate on trusted, governed context. The conversation has moved from data leaders asking: “Can we trust the data in our stack?” to businesses asking: “Can we trust AI inside the business?” + +We are the missing infrastructure for businesses becoming AI-forward - the connective tissue between their data stack, operational systems, and AI agents. Recognized as an industry-leading metadata, catalog, and data governance platform , we’ve been named a Leader by both Gartner and Forrester across enterprise data catalogs, metadata management, and governance. To learn more, visit www.atlan.com (http://www.atlan.com) and follow us on LinkedIn (https://www.linkedin.com/company/atlan-hq/posts/?feedView=all) + +Equal Opportunity Employer + +Atlan is committed to building an inclusive, diverse, and authentic workplace. We do not discriminate based on race, color, religion, national origin, age, disability, sex, gender identity or expression, sexual orientation, marital status, military or veteran status, or any other legally protected characteristic. diff --git a/jobs/imported/ashby/ashby-confluent-333a7528-e47d-419f-839f-71f76b5620e1.md b/jobs/imported/ashby/ashby-confluent-333a7528-e47d-419f-839f-71f76b5620e1.md new file mode 100644 index 0000000..8dcacad --- /dev/null +++ b/jobs/imported/ashby/ashby-confluent-333a7528-e47d-419f-839f-71f76b5620e1.md @@ -0,0 +1,81 @@ +--- +title: "Senior Security Risk & Compliance Program Manager" +company: "Confluent" +slug: "ashby-confluent-333a7528-e47d-419f-839f-71f76b5620e1" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/confluent?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/confluent/333a7528-e47d-419f-839f-71f76b5620e1" +apply_url: "https://jobs.ashbyhq.com/confluent/333a7528-e47d-419f-839f-71f76b5620e1/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "Remote, United States" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Identity & Access Management" +frameworks: [] +languages: + - "Rust" +compensation: "" +summary: "We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in..." +--- + +We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them. + +It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together. + +One Confluent. One Team. One Data Streaming Platform. + +## About the Role: + +As a Security Technical Program Manager in the Trust & Security organization, you will play a critical role in fulfilling the vision to secure Confluent’s platform and cloud offerings through a combination of technical expertise, security experience, and excellent program management skills. You should be comfortable and experienced in driving and delivering highly complex projects on time, running significant security programs that span the entire company, and participating in operational security exercises, such as incident response and vulnerability management. + +## What You Will Do: + +- Mentor other Security Program Managers on execution and delivery, both from a security subject matter expert perspective as well as program management +- Work with stakeholders to drive critical security initiatives for the company +- Manage and scale security programs by defining milestones and success criteria, resource allocation, and successful on-time delivery +- Proactively identify and resolve roadblocks/challenges affecting projects +- Drive automation and process improvements for security programs +- Explain technical architecture, decisions, and tradeoffs to both engineering and other functions +- Work with Engineering, Product, and Security leadership to streamline and drive our projects on a predictable schedule +- Participate in operational security work, including incident response and vulnerability management + +## What You Will Bring: + +- 5+ years of relevant industry experience +- Strong foundational knowledge in security domains with expertise in at least one +- Experience in running long-term security programs that deliver iterative improvements and risk reduction over time +- Experience in operational security work, such as incident response and vulnerability management +- Experience driving complex and large programs across organizations +- Strong communication, interpersonal, and leadership skills to work with both engineering and non-technical stakeholders +- Experience managing end-to-end lifecycle of technical projects +- Bachelor's degree in Computer Science, a related field, or equivalent practical experience + +## What Gives You an Edge: + +- Experience in areas such as release management, cost modeling, and capacity planning is a plus +- Strong technical skills. Experience in actual design and development of software programs is a plus +- Experience in leveraging artificial intelligence to manage programs at scale is a plus + +## Ready to build what's next? Let’s get in motion. + +### + +# Come As You Are + +Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible. + +We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law. + +# Privacy Statement + +Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization. By proceeding with this application, you understand that Confluent will share your personal information with other IBM affiliates involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross-border data transfer, are available here (http://ibm.com/careers/us-en/privacy-policy/). diff --git a/jobs/imported/ashby/ashby-confluent-e24389db-8ae7-4dc2-9e7d-5cb60ba2f2d1.md b/jobs/imported/ashby/ashby-confluent-e24389db-8ae7-4dc2-9e7d-5cb60ba2f2d1.md new file mode 100644 index 0000000..3a043ed --- /dev/null +++ b/jobs/imported/ashby/ashby-confluent-e24389db-8ae7-4dc2-9e7d-5cb60ba2f2d1.md @@ -0,0 +1,119 @@ +--- +title: "Director, Governance, Risk and Compliance (GRC)" +company: "Confluent" +slug: "ashby-confluent-e24389db-8ae7-4dc2-9e7d-5cb60ba2f2d1" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/confluent?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/confluent/e24389db-8ae7-4dc2-9e7d-5cb60ba2f2d1" +apply_url: "https://jobs.ashbyhq.com/confluent/e24389db-8ae7-4dc2-9e7d-5cb60ba2f2d1/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "Remote, California" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "FedRAMP" + - "SOC 2" + - "ISO 27001" + - "NIST 800-53" + - "NIST CSF" +languages: + - "Rust" +compensation: "" +summary: "We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in..." +--- + +We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them. + +It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together. + +One Confluent. One Team. One Data Streaming Platform. + +## About the Role: + +Trust is the currency of the cloud. As Confluent continues to mobilize data for the world's leading organizations, ensuring the security, privacy, and integrity of that data is paramount. + +We are seeking a Director of Governance, Risk, and Compliance (GRC) to continue the evolution of our GRC program from a control-based mandate to a strategic business enabler. In this role, you will not just manage compliance and risk. You will architect the framework that allows Confluent to meet the needs of our customers, underpin trust relationship by providing attestations and evidence of controls, develop frameworks and tools to help management understand and manage risk, and operate our Technical Program Management (TPM) reducing risk by driving the execution of horizontal engineering programs. You will provide the vision and north star to guide Confluent to a proactive risk management culture. + +You will lead the strategy for internal governance, enterprise wide risk management, and external compliance obligations, serving as the bridge between technical engineering realities and executive risk appetite. + +## What You Will Do: + +Strategic Governance & Program Leadership + +- Own the Framework: Design, implement, and maintain a common control framework (CCF) that maps to multiple standards (SOC 2, ISO 27001, FedRAMP, NIST CSF, PCI-DSS) to ensure "test once, comply many" efficiency. +- Risk Quantification: Evolve our risk management program towards quantitative risk analysis (e.g. leveraging FAIR, OCTAVE methodologies), utilizing AI to continuously process & analyze complex data sets, and providing executive leadership with data-driven insights on security posture and residual risk and an updated view of Top Risks impacting Confluent. +- Program Modernization: Develop and maintain security policies that are agile, easily discoverable, and practical for an AI-native engineering culture, enforceable through automation. + +Technical Risk Program Management (TPM) + +- Remediation Strategy & Engineering Partnership: Interface directly with Information Security Engineering (InfoSec Eng) to co-develop technical remediation strategies that are secure by design and operationally feasible. You will ensure that top risk concerns, audit findings and compliance gaps are translated into actionable engineering programs and drive them to closure. +- Risk Reporting: Develop and maintain a visual presentation layer (e.g., dynamic dashboards, executive scorecards, and trend analysis) that simplifies complex risk data. This layer will be the primary tool to assist Confluent's management staff in understanding the landscape, understanding severity, and prioritizing risk items effectively. +- Risk Treatment: Evolve current risk management programs to ensure risks are properly tracked, treated, and communicated. +- Program Execution: Apply technical program management best practices to complex security initiatives. Via your TPM team, lead cross-functional projects, such as identity management improvements, AI governance controls, or secret management overhauls, ensuring they are delivered on time and with minimal friction to developer velocity. +- Communication & Accountability: Regularly report to the Trust and Security staff, eStaff and prepare occasion Board level content via weekly, monthly and quarterly execution reviews. + +Customer Trust & Revenue Enablement + +- OCISO Partnership: Collaborate closely with the Office of the CISO (OCISO) to proactively forecast and prioritize security certifications and product features. You will translate the "voice of the customer" and sales pipeline data gathered by OCISO into a concrete GRC roadmap that removes friction from future deals by providing efficient means to evidence data for our customers and auditors. +- Sales Acceleration: Act as a subject matter expert during high-stakes customer engagements, partnering with Sales and OCISO to build confidence with Fortune 500 CISOs and external auditors. + +Compliance Operations & Automation + +- Continuous Compliance and Scale: Partner with Engineering to drive the automation of evidence collection and control monitoring. You will transition traditional audit operations into an AI-assisted continuous compliance model, significantly reducing manual overhead. +- Audit Management: Orchestrate all external audits and certifications, serving as the primary liaison with external auditors and regulators. + +Third-Party & Supply Chain Risk + +- TPRM: Oversee the Third-Party Risk Management program, ensuring that vendors, partners, and AI sub-processors meet Confluent’s security standards throughout the vendor lifecycle. + +## What You Will Bring: + +Experience & Background + +- 10+ years of progressive experience in Information Security, Risk Management, or IT Audit. +- 5+ years of leadership experience building and managing high-performing GRC teams in a high-growth SaaS or cloud-native environment. Experience managing teams of managers and teams of individual contributors. +- Cloud Native Fluency: Deep understanding of modern cloud infrastructure (AWS, GCP, Azure, Kubernetes) and how traditional controls apply to ephemeral, containerized environments. +- AI Fluency: Hands-on experience or a strong vision for leveraging AI tools to scale internal GRC programs and operations. + +Technical & Framework Knowledge + +- Mastery of Standards: Expert-level knowledge of SOC 2 Type II, ISO 27001/27701, NIST 800-53, and PCI-DSS. +- FedRAMP Expertise: Strong familiarity with FedRAMP High/Moderate authorization processes and continuous monitoring requirements is highly preferred. +- Privacy Intersection: Working knowledge of global privacy laws (GDPR, CPRA) and how they intersect with security controls. + +Soft Skills & Leadership Traits + +- Technical Program Management: Proven ability to manage complex cross-functional programs and utilize tools like Jira/Confluence and risk management tools. You know how to speak the language of engineering to get things done. +- Business Acumen: The ability to translate complex technical risks into business terms (ROI, Brand Risk, Velocity) for the C-Suite and Board of Directors. +- Diplomacy & Empathy: A track record of building consensus with Engineering and Product teams. You approach GRC as a partner who helps teams build securely, help engineering leaders manage risk and drives changes in policies for the entire company to operate pragmatically. +- Executive Presence: Confidence in presenting to customers, auditors, and internal executive leadership. + +Education & Certifications + +- Certifications: CISSP, CISM, CISA, or CRISC is a strong plus. +- Education: BS/MS in Computer Science, Information Systems, Business Administration, or equivalent practical experience. + +## Ready to build what's next? Let’s get in motion. + +### + +# Come As You Are + +Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible. + +We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law. + +# Privacy Statement + +Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization. By proceeding with this application, you understand that Confluent will share your personal information with other IBM affiliates involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross-border data transfer, are available here (http://ibm.com/careers/us-en/privacy-policy/). diff --git a/jobs/imported/ashby/ashby-crusoe-8d491b45-092a-40c9-809c-1751f1c7a56f.md b/jobs/imported/ashby/ashby-crusoe-8d491b45-092a-40c9-809c-1751f1c7a56f.md new file mode 100644 index 0000000..83e24ec --- /dev/null +++ b/jobs/imported/ashby/ashby-crusoe-8d491b45-092a-40c9-809c-1751f1c7a56f.md @@ -0,0 +1,103 @@ +--- +title: "Staff GRC Engineer" +company: "Crusoe" +slug: "ashby-crusoe-8d491b45-092a-40c9-809c-1751f1c7a56f" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/Crusoe?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/Crusoe/8d491b45-092a-40c9-809c-1751f1c7a56f" +apply_url: "https://jobs.ashbyhq.com/Crusoe/8d491b45-092a-40c9-809c-1751f1c7a56f/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "San Francisco, CA - US" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "HIPAA" + - "GDPR" +languages: + - "Python" + - "Terraform" + - "JavaScript" +compensation: "" +summary: "Crusoe is on a mission to accelerate the abundance of energy and intelligence . As the only vertically integrated AI infrastructure company built from the ground up, we own and..." +--- + +Crusoe is on a mission to accelerate the abundance of energy and intelligence . As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads. When you join Crusoe, you join a team that is building the future, faster. + +We're in the midst of the greatest industrial revolution of our time. The demand for AI compute is boundless, and power is a bottleneck. We're solving that — with an energy-first approach that makes AI infrastructure better for the world and faster for the people innovating with AI. + +We're looking for problem-solving, opportunity-finding teammates with a sense of urgency, who believe in the scale of our ambition and thrive on a path not fully paved — people who want to grow their careers alongside a team of experts across energy, manufacturing, data center construction, and cloud services. + +If you want to do the most meaningful work of your career, help our customers and partners advance their AI strategies, and be part of a high-performing team that believes in each other, come build with us at Crusoe. + +About This Role + +We’re seeking a Sr. GRC Engineer to design, build, and operate the automation and tooling that powers our Governance, Risk, and Compliance program. Reporting to the Head of GRC, this is an engineer-first role focused on replacing manual compliance workflows with scalable, code-driven systems. + +You’ll build automation across evidence collection, control monitoring, and risk reporting; embedding compliance directly into engineering and infrastructure pipelines so it becomes continuous, not periodic. Deep regulatory expertise isn’t required, but you should understand how compliance requirements translate into automatable controls and repeatable workflows. + +What You’ll Be Working On + +- Designing and maintaining automation workflows that replace manual compliance processes (evidence collection, control testing, policy monitoring, audit reporting) +- Writing production-grade scripts, services, and integrations (Python, JavaScript, YAML, etc.) that connect GRC platforms to internal systems and CI/CD pipelines +- Implementing and customizing GRC platforms (e.g., Vanta, AuditBoard, Drata) through APIs, configuration, and custom automation +- Building dashboards and reporting systems that provide real-time visibility into control health and risk posture +- Embedding compliance checks into engineering workflows so evidence collection and monitoring happen continuously +- Applying AI and LLM-based tools to streamline GRC workflows such as evidence review, control mapping, and risk analysis +- Partnering with Security, IT, and Engineering teams to ensure GRC tooling integrates cleanly into existing environments +- Supporting audits through automated data collection and evidence generation +- Providing technical guidance and training to teams on GRC automation best practices + +What You’ll Bring to the Team + +- 5+ years in a technical role with strong experience in automation, scripting, and systems integration +- Strong programming skills in Python, JavaScript, or similar languages with experience shipping automation to production +- Experience with infrastructure-as-code and automation tools (e.g., Terraform, Ansible, Jenkins) +- Hands-on API integration experience across cloud platforms, SaaS tools, identity systems, and security tooling +- Familiarity with GRC platforms and the ability to extend them through code and automation +- Working knowledge of cloud environments (GCP preferred; AWS/Azure exposure helpful) +- Practical understanding of compliance and risk frameworks (SOC 2, ISO 27001, NIST, HIPAA, GDPR) and how they translate into controls +- Experience applying AI tools to automate workflows and scale operational processes +- Strong communication skills with the ability to bridge engineering and compliance teams + +Bonus Points + +- Certifications such as CISSP, CISA, or CRISC +- Experience embedding compliance controls directly into CI/CD (DevSecOps practices) +- Background in security or infrastructure engineering +- Familiarity with quantitative risk frameworks (FAIR, COSO, ISO 31000) +- Experience building continuous monitoring or continuous compliance systems + +Benfits + +- Competitive compensation +- Restricted Stock Units +- Paid time off & paid holidays +- Comprehensive health, dental & vision insurance +- Employer contributions to HSA account +- Paid parental leave +- Paid life insurance, short-term and long-term disability +- Professional development & tuition reimbursement +- Mental health & wellness support +- Commuter benefits (parking & transit) +- Cell phone stipend +- 401(k) Retirement plan with company match up to 4% of salary +- Volunteer time off + +Compensation Range + +Compensation will be paid in the range of up to $190,000 - $215,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicants knowledge, education, and abilities, as well as internal equity and alignment with market data. + +Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation. diff --git a/jobs/imported/ashby/ashby-elevenlabs-f80d0420-b6e6-4110-940c-293f64b9761e.md b/jobs/imported/ashby/ashby-elevenlabs-f80d0420-b6e6-4110-940c-293f64b9761e.md new file mode 100644 index 0000000..fe91d48 --- /dev/null +++ b/jobs/imported/ashby/ashby-elevenlabs-f80d0420-b6e6-4110-940c-293f64b9761e.md @@ -0,0 +1,82 @@ +--- +title: "Compliance Engineer - US" +company: "Elevenlabs" +slug: "ashby-elevenlabs-f80d0420-b6e6-4110-940c-293f64b9761e" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/elevenlabs?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/elevenlabs/f80d0420-b6e6-4110-940c-293f64b9761e" +apply_url: "https://jobs.ashbyhq.com/elevenlabs/f80d0420-b6e6-4110-940c-293f64b9761e/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "New York" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Audit & Assurance" + - "Cloud Security" +frameworks: + - "FedRAMP" + - "CMMC" + - "CJIS" +languages: [] +compensation: "" +summary: "About ElevenLabs ElevenLabs is an AI research and product company transforming how we interact with technology. We launched in January 2023 with the first human-like AI voice..." +--- + +## About ElevenLabs + +ElevenLabs is an AI research and product company transforming how we interact with technology. + +We launched in January 2023 with the first human-like AI voice model. Today, we serve millions of users and thousands of businesses - from fast-growing startups to large enterprises like Deutsche Telekom and Meta. Our investors are some of the world's most prominent, including Andreessen Horowitz, ICONIQ Growth and Sequoia. We've raised $781M in funding and our last valuation was $11B - multiples of 11, always. We have expanded from voice into three main platforms: + +- ElevenAgents enables businesses to deliver seamless and intelligent customer experiences, with the integrations, testing, monitoring, and reliability necessary to deploy voice and chat agents at scale. +- ElevenCreative empowers creators and marketers to generate and edit speech, music, image, and video across 70+ languages. +- ElevenAPI gives developers access to our leading AI audio foundational models. + +Everything we do is the result of the creativity and commitment of our team - builders doing the best work of their lives. We are researchers, engineers, and operators. IOI medalists and ex-founders. If you want to work hard and create lasting positive impact, we want to hear from you. + +## How we work + +- High-velocity: Rapid experimentation, lean autonomous teams, and minimal bureaucracy. +- Impact not job titles: We don’t have job titles. Instead, it’s about the impact you have. No task is above or beneath you. +- AI first: We use AI to move faster with higher-quality results. We do this across the whole company—from engineering to growth to operations. +- Excellence everywhere: Everything we do should match the quality of our AI models. +- Global team: We prioritize your talent, not your location. + +## What we offer + +- Innovative culture: You’ll be part of a generational opportunity to define the trajectory of AI, surrounded by a team pushing the boundaries of what’s possible. +- Growth paths: Joining ElevenLabs means joining a dynamic team with countless opportunities to drive impact - beyond your immediate role and responsibilities. +- Learning & development : ElevenLabs proactively supports professional development through an annual discretionary stipend. +- Social travel : We also provide an annual discretionary stipend to meet up with colleagues each year, however you choose. +- Annual company offsite: Each year, we bring the entire team together in a new location - past offsites have included Croatia and Italy. +- Co-working : If you’re not located near one of our main hubs, we offer a monthly co-working stipend. + +## About the Role + +- Collaborating across teams to maintain US Government compliance certifications and frameworks such as GovRAMP, FedRAMP, CJIS and CMMC. +- Helping to shape ElevenLabs’ Enterprise offering towards regulated industries such as Local and State Government, Defense and Finance. +- Building technical documentation to demonstrate our compliance to our customers throughout the stack. +- Assisting the sales team by responding to client security requests and managing compliance-related queries. +- Conduct risk assessments based on CIS or NIST frameworks, document findings, and help teams achieve compliance efficiently. +- Enhance compliance as code tooling to automate monitoring, reporting, and reduce friction for other teams to remain compliant. + +## Requirements + +- Experience in completing vendor security assessments and client security questionnaires in highly regulated industries, such as Government and Defense in the US. +- Strong technical expertise in managing and executing compliance, with hands-on experience using compliance management tools (e.g. Vanta). +- Proven ability to maintain and acquire certifications while managing audit readiness and documentation. +- Experience collaborating with cross-functional teams (sales, engineering, legal) to effectively communicate compliance requirements and ensure smooth operations. +- Experience with public cloud compliance (AWS, GCP, Azure) and automating compliance in cloud environments. +- Familiarity with integrating compliance tools into CI/CD pipelines to automate monitoring and reporting. + +## Location + +This role is remote-first, so it can be executed from anywhere in the United States, with the ability to operate in GMT-5 timezone required. If you prefer, you can work from our offices in New York or San Francisco. diff --git a/jobs/imported/ashby/ashby-hims-and-hers-5526c955-fb96-4277-a93a-f66e322bcfab.md b/jobs/imported/ashby/ashby-hims-and-hers-5526c955-fb96-4277-a93a-f66e322bcfab.md new file mode 100644 index 0000000..98de955 --- /dev/null +++ b/jobs/imported/ashby/ashby-hims-and-hers-5526c955-fb96-4277-a93a-f66e322bcfab.md @@ -0,0 +1,118 @@ +--- +title: "Security Compliance Analyst, GRC" +company: "Hims And Hers" +slug: "ashby-hims-and-hers-5526c955-fb96-4277-a93a-f66e322bcfab" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/hims-and-hers?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/hims-and-hers/5526c955-fb96-4277-a93a-f66e322bcfab" +apply_url: "https://jobs.ashbyhq.com/hims-and-hers/5526c955-fb96-4277-a93a-f66e322bcfab/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "US Remote" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "ISO 42001" + - "NIST CSF" + - "NIST AI RMF" +languages: [] +compensation: "" +summary: "Hims & Hers is the leading health and wellness platform, on a mission to help the world feel great through the power of better health. We are redefining healthcare by putting the..." +--- + +Hims & Hers is the leading health and wellness platform, on a mission to help the world feel great through the power of better health. We are redefining healthcare by putting the customer first and delivering access to care that is affordable, accessible, and personal, from diagnosis to treatment to delivery. No two people are the same, so we provide access to personalized care designed for results. By normalizing health & wellness challenges and innovating on their solutions, we’re making better health outcomes easier to achieve. + +Hims & Hers is a public company, traded on the NYSE under the ticker symbol “HIMS.” To learn more about the brand and offerings, you can visit hims.com/about (http://hims.com/about) and hims.com/how-it-works (http://hims.com/how-it-works) . For information on the company’s outstanding benefits, culture, and its talent-first flexible/remote work approach, see below and visit www.hims.com/careers-professionals (http://www.hims.com/careers-professionals). + +## About the Role: + +We are seeking a Security GRC Analyst to support and mature our governance, risk, and compliance program within a fast-paced healthcare technology environment. This role will partner closely with Security, Engineering, Legal, Privacy, Finance, and AI/ML teams to ensure our systems and processes meet regulatory, privacy, and security standards across domestic and international operations. + +You will help drive risk management initiatives, maintain compliance with globally recognized frameworks, and support audits while enabling the business to scale securely and responsibly, particularly in environments leveraging AI and automated decision-making systems. + +## You Will: + +- Support and maintain security and compliance programs aligned with frameworks such as NIST, ISO, PCI DSS, and HIPAA +- Assist in maintaining alignment with global privacy regulations (GDPR, CCPA, and similar frameworks) +- Assist in the development, implementation, and maintenance of security, privacy, and AI governance policies, standards, and procedures +- Coordinate and support internal and external audits (e.g., SOX, PCI DSS, SOC 2, ISO, HIPAA) +- Track and manage remediation efforts for identified risks, control gaps, and audit findings +- Support third-party risk management processes, including vendor assessments for AI/ML and data processing providers +- Partner with engineering, data, and AI/ML teams to ensure secure and compliant system and model lifecycle practices +- Maintain and improve GRC tooling (e.g., AuditBoard, Vanta, or similar platforms) +- Monitor regulatory and framework changes (U.S. and international), including emerging AI governance requirements +- Develop and maintain risk registers, control matrices, and compliance documentation +- Conduct risk assessments, including technology, security, privacy, and AI/ML model risk evaluations +- Assist with security, privacy, and responsible AI awareness and training initiatives +- Provide reporting and metrics on risk posture, compliance status, and AI governance maturity + +## You Have: + +- Bachelor’s degree in Cybersecurity, Information Security, Information Technology/Systems, or related field +- 3–5 years of experience in GRC, security compliance, risk management, audit, or related field +- Experience supporting audits and compliance assessments +- Experience with third-party/vendor risk management +- Familiarity with data governance principles (classification, retention, lineage) +- Thorough understanding of risk management methodologies and control frameworks +- Strong communication, documentation, organizational, and analytical skills +- Ability to communicate security, privacy, and AI risk concepts to technical and non-technical stakeholders +- Working knowledge of core frameworks: NIST CSF, PCI DSS, HIPAA, ISO 27001/27002, and global privacy regulations (GDPR, CCPA) +- Foundational understanding of AI/ML systems and associated governance, risk, and compliance considerations (NIST AI RMF, ISO 42001) +- Familiarity with cloud environments (AWS primary, Google Workspace/MS Azure preferred) and modern SaaS architectures +- Experience with GRC tools (AuditBoard, Vanta, Drata, Archer, ServiceNow GRC, or similar) and ticketing/workflow/documentation tools (Jira, Freshservice, Confluence, GitHub, etc.) + +## Preferred Qualifications + +- Professional certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor +- Experience with compliance automation and continuous monitoring +- Experience supporting or implementing ISO 27001 and/or ISO 42001 programs +- Experience operationalizing privacy programs aligned to GDPR and global privacy standards +- Understanding of AI governance frameworks and emerging standards (e.g., NIST AI RMF, ISO 42001) +- Experience working with AI/ML systems lifecycle governance +- Exposure to incident response, particularly involving data privacy or AI-related risks +- Experience in healthcare or other highly regulated industries + +## What We’re Looking For + +- Strong understanding of security, privacy, and AI governance principles +- Ability to balance regulatory requirements with business agility +- Collaborative and cross-functional mindset +- Proactive problem-solver +- Strong communicator + +## Additional Information + +- Remote-friendly position +- Operates in a fast-paced, regulated healthcare environment +- Focus on secure, compliant, and responsible AI-driven growth + +## Our Benefits (there are more but here are some highlights): + +- Competitive salary & equity compensation for full-time roles +- Unlimited PTO, company holidays, and quarterly mental health days +- Comprehensive health benefits including medical, dental & vision, and parental leave +- Employee Stock Purchase Program (ESPP) +- 401k benefits with employer matching contribution +- Offsite team retreats + +We are committed to building a workforce that reflects diverse perspectives and prioritizes ethics, wellness, and a strong sense of belonging. If you're excited about this role, we encourage you to apply—even if you're not sure if your background or experience is a perfect match. + +Hims considers all qualified applicants for employment, including applicants with arrest or conviction records, in accordance with the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance, the California Fair Chance Act, and any similar state or local fair chance laws. + +It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. + +Hims & Hers is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please contact us at accommodations@forhims.com (mailto:accommodations@forhims.com) and describe the needed accommodation. Your privacy is important to us, and any information you share will only be used for the legitimate purpose of considering your request for accommodation. Hims & Hers gives consideration to all qualified applicants without regard to any protected status, including disability. Please do not send resumes to this email address. + +To learn more about how we collect, use, retain, and disclose Personal Information, please visit our Global Candidate Privacy Statement (https://www.hims.com/global-candidate-privacy-statement). diff --git a/jobs/imported/ashby/ashby-junipersquare-3f47391b-d305-43e0-b84c-7877e09fc633.md b/jobs/imported/ashby/ashby-junipersquare-3f47391b-d305-43e0-b84c-7877e09fc633.md new file mode 100644 index 0000000..e90528c --- /dev/null +++ b/jobs/imported/ashby/ashby-junipersquare-3f47391b-d305-43e0-b84c-7877e09fc633.md @@ -0,0 +1,86 @@ +--- +title: "Head of Fund Administration GRC - India" +company: "Junipersquare" +slug: "ashby-junipersquare-3f47391b-d305-43e0-b84c-7877e09fc633" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/junipersquare?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/junipersquare/3f47391b-d305-43e0-b84c-7877e09fc633" +apply_url: "https://jobs.ashbyhq.com/junipersquare/3f47391b-d305-43e0-b84c-7877e09fc633/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "India" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST RMF" + - "GDPR" + - "CCPA" +languages: [] +compensation: "" +summary: "About Juniper Square Our mission is to unlock the full potential of private markets. Privately owned assets like commercial real estate, private equity, and venture capital make..." +--- + +## About Juniper Square + +Our mission is to unlock the full potential of private markets. Privately owned assets like commercial real estate, private equity, and venture capital make up half of our financial ecosystem yet remain inaccessible to most people. We are digitizing these markets, and as a result, bringing efficiency, transparency, and access to one of the most productive corners of our financial ecosystem. If you care about making the world a better place by making markets work better through technology – all while contributing as a member of a values-driven organization – we want to hear from you. + +Juniper Square offers employees a variety of ways to work, ranging from a fully remote experience to working full-time in one of our physical offices. We invest heavily in digital-first (https://blog.junipersquare.com/juniper-square-ponders-future-of-office-with-digital-first-hybrid-workplace-strategy/) operations, allowing our teams to collaborate effectively across 27 U.S. states, 2 Canadian Provinces, India, Luxembourg, and England. We also have physical offices in San Francisco, New York City, Mumbai and Bangalore for employees who prefer to work in an office some or all of the time. + +# About your Role + +The Head of Fund Administration GRC will be a key contributor to the company's governance, risk and compliance program. This role is responsible for day to day execution and maintenance of the program, ensuring the organization manages the risk effectively and maintain compliance with all relevant laws, regulations and internal policies. This role will help drive a culture of compliance and risk awareness across Fund Administration. + +# What you’ll do + +1. Governance + +- Assist in the development and execution of the GRC strategy aligned with Fund Administration business objectives. +- Help maintain the governance framework, including managing policies, standards, and procedures for risk management and compliance. +- Coordinate with cross-functional teams (e.g., Legal, Fund Administration, IT, Engineering, People Teams, and Internal Audit) to ensure the GRC program is effective. + +2. Risk Management Execution + +- Support the implementation of the enterprise-wide risk management framework. +- Perform risk assessments, monitor, and report on key Compliance and Security risks. +- Execute risk mitigation strategies and track the remediation of identified risks. +- Coordinate other security reviews and assist with vendor risk management. + +3. Compliance Activities + +- Ensure organizational adherence to applicable laws, regulations, and industry standards (e.g., GDPR, CCPA, SOC2, SOC1, ISO 27001, others). +- Support the management of external audits and assessments related to compliance and security. +- Assist in the design and delivery of mandatory GRC training and awareness programs for employees. + +4. Policy and Control Management + +- Help manage the lifecycle of GRC policies, ensuring they are relevant, effective, current, accessible, and enforced. +- Execute the operational effectiveness testing of internal controls. +- Utilize GRC tools and technologies to automate and streamline processes + +# Qualifications + +- Bachelor’s degree in IT, security, or a related field. +- 10+ years of progressive experience in GRC, Internal Audit, Risk Management, or Compliance. +- Strong knowledge of major regulatory frameworks (e.g., SOC, ISO, etc). + +# Preferred Skills + +- Professional certifications such as CISA or similar. +- Security certification CISSP, CCSP, CISM or similar. +- Relevant experience in the Financial Services or technology industry. +- Strong knowledge of NIST, CSA, OWASP, and MITRE ATT&CK. +- Experience in implementing and optimizing GRC technology solutions (e.g., GRC platforms). + +At Juniper Square, we believe building a diverse workforce and an inclusive culture makes us a better company. If you think this job sounds like a fit, we encourage you to apply even if you don’t meet all the qualifications. diff --git a/jobs/imported/ashby/ashby-junipersquare-b66e4c7c-ef37-42fc-939e-6ece4e99b57b.md b/jobs/imported/ashby/ashby-junipersquare-b66e4c7c-ef37-42fc-939e-6ece4e99b57b.md new file mode 100644 index 0000000..859883e --- /dev/null +++ b/jobs/imported/ashby/ashby-junipersquare-b66e4c7c-ef37-42fc-939e-6ece4e99b57b.md @@ -0,0 +1,118 @@ +--- +title: "Senior GRC Analyst" +company: "Junipersquare" +slug: "ashby-junipersquare-b66e4c7c-ef37-42fc-939e-6ece4e99b57b" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/junipersquare?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/junipersquare/b66e4c7c-ef37-42fc-939e-6ece4e99b57b" +apply_url: "https://jobs.ashbyhq.com/junipersquare/b66e4c7c-ef37-42fc-939e-6ece4e99b57b/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "USA" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" +languages: + - "Rust" +compensation: "" +summary: "About Juniper Square Our mission is to unlock the full potential of private markets. Privately owned assets like commercial real estate, private equity, and venture capital make..." +--- + +## About Juniper Square + +Our mission is to unlock the full potential of private markets. Privately owned assets like commercial real estate, private equity, and venture capital make up half of our financial ecosystem yet remain inaccessible to most people. We are digitizing these markets, and as a result, bringing efficiency, transparency, and access to one of the most productive corners of our financial ecosystem. If you care about making the world a better place by making markets work better through technology – all while contributing as a member of a values-driven organization – we want to hear from you. + +Juniper Square offers employees a variety of ways to work, ranging from a fully remote experience to working full-time in one of our physical offices. We invest heavily in digital-first (https://blog.junipersquare.com/juniper-square-ponders-future-of-office-with-digital-first-hybrid-workplace-strategy/) operations, allowing our teams to collaborate effectively across 27 U.S. states, 2 Canadian Provinces, India, Luxembourg, and England. We also have physical offices in San Francisco, New York City, Mumbai and Bangalore for employees who prefer to work in an office some or all of the time. + +## About your role + +As a Senior GRC Analyst, you are responsible for supporting the organization's governance, risk management, and compliance (GRC) program. The ideal candidate will have a strong understanding and experience building scalable, right-sized risk management and compliance processes for a high-growth company. We are looking for someone with strong analytical and problem-solving skills, as well as excellent communication and interpersonal skills. In this role, you will work closely with a broad set of cross-functional stakeholders within the company and should be able to build a rapport and influence towards appropriate risk management outcomes. + +## What you’ll do + +Customer Trust and Assurance + +- Compliance Maintain and onboard existing/new security compliance certifications and frameworks (e.g. SOC2, ISO and others) +- Work with cross-functional teams to procure controls evidence to provide to external auditors timely and issue reports timely. +- Work cross functionally between teams and auditors to ensure a smooth and efficient audit process +- Improve the audit process through automation and controls rationalization year over year +- Monitor and test effectiveness of compliance control health throughout the year; not just during audits +- Serve as a subject matter expert for all things compliance; +- Identify and assess business changes for relevant impacts on compliance posture (e.g. geographical expansion, internal tool replacement, new products) + +- Customer Trust Maintain our trust center by keeping security documents and knowledge base up-to-date +- Support sales teams with open security and privacy questions +- Review incoming security and privacy addendums to customer contracts +- Support customer security and privacy audits +- Work with Sales and Solutions engineering to coach and educate teams on our security and compliance posture + +Governance + +- Policy Management Develop a comprehensive set of security and privacy policies and procedures working with Legal, HR, IT, Engineering. +- Update policies and procedures annually while incorporating stakeholder feedback and obtain approval +- Define and manage incoming policy exceptions on an ongoing basis to manage associated risk + +- Security and Privacy Training and Awareness Develop and implement role and team specific security and privacy training working closely with key business partners. +- Manage the roll-out, escalation and completion of all security and privacy training modules. + +- Phishing Management Manage phishing campaigns on an ongoing basis with appropriate re-training processes baked into the process +- Refine existing phishing reporting processes and integrate this better with our incident management processes + +- GRC Metrics and Reporting Ensure the GRC function meets key performance metrics + +Risk + +- Risk Management Maintain business unit risk registers with existing teams on a monthly basis to appropriately address key risks areas +- Co-develop and coach business units on right-sized and right-scoped risk remediation plans +- Work with cross-functional teams to onboard new business units onto the risk management process + +- Third-Party Risk Management Triage incoming technical security requests for vendor application/system integrations and route to appropriate teams for input. +- Conduct security risk assessments and audits of vendors to evaluate the maturity of their security programs, controls, and documentation. + +## Qualifications + +- Bachelor's degree in information systems, engineering, business, risk management, or a related field +- 5+ years of experience in GRC, security, audit or a related field with past experience in managing a SOC2/ISO 27001 program +- Knowledge of GRC frameworks and regulations +- Experience developing scalable GRC processes +- Ability to work on multiple GRC projects simultaneously +- Ability to partner with stakeholders collaboratively “guardrails” without having a “gated” approach to risk management +- Excellent communication and interpersonal skills + +## Compensation + +Compensation for this position includes a base salary and a variety of benefits. The U.S. base salary range for this role is $135,000 to $190,000. Actual base salaries will be based on candidate-specific factors, including experience, skillset, and location, and local minimum pay requirements as applicable. + +Benefits include: + +- Health, dental, and vision care for you and your family +- Life insurance +- Mental wellness coverage +- Fertility and growing family support +- Flex Time Off in addition to company-paid holidays +- Paid family leave, medical leave, and bereavement leave policies +- Retirement saving plans +- Allowance to customize your work and technology setup at home +- Annual professional development stipend + +Your recruiter can provide additional details about compensation and benefits. + +#experiencedprofessional + +#LI-AM + +#LI-Remote + +#Juniper-US diff --git a/jobs/imported/ashby/ashby-lambda-0ca9bb78-6d6b-4b71-8f77-762f0b16b959.md b/jobs/imported/ashby/ashby-lambda-0ca9bb78-6d6b-4b71-8f77-762f0b16b959.md new file mode 100644 index 0000000..d5f38bc --- /dev/null +++ b/jobs/imported/ashby/ashby-lambda-0ca9bb78-6d6b-4b71-8f77-762f0b16b959.md @@ -0,0 +1,95 @@ +--- +title: "Senior Security GRC Analyst" +company: "Lambda" +slug: "ashby-lambda-0ca9bb78-6d6b-4b71-8f77-762f0b16b959" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/lambda?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/lambda/0ca9bb78-6d6b-4b71-8f77-762f0b16b959" +apply_url: "https://jobs.ashbyhq.com/lambda/0ca9bb78-6d6b-4b71-8f77-762f0b16b959/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "San Francisco Office" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST CSF" + - "PCI-DSS" + - "CMMC" +languages: + - "Rust" +compensation: "" +summary: "Lambda, The Superintelligence Cloud, is a leader in AI cloud infrastructure serving tens of thousands of customers. Our customers range from AI researchers to enterprises and..." +--- + +Lambda, The Superintelligence Cloud, is a leader in AI cloud infrastructure serving tens of thousands of customers. Our customers range from AI researchers to enterprises and hyperscalers. Lambda's mission is to make compute as ubiquitous as electricity and give everyone the power of superintelligence. One person, one GPU. + +If you'd like to build the world's best AI cloud, join us. + +*Note: This position requires presence in our San Francisco or San Jose office location 4 days per week; Lambda’s designated work from home day is currently Tuesday. + +What You’ll Do + +- Validate and verify the organization's security controls and practices meet the requirements of ISO 27001, 27701, PCI, SOC 2 and other relevant regulatory requirements to ensure alignment to business objectives +- Manage IT Risk Register including risk identification, tracking, and prioritization. +- Assist with and drive remediation of control deficiencies and gaps +- Provide guidance to Control Owners in the planning, design, implementation, operation, maintenance & remediation of control activities and other supporting requirements (e.g. policies, standards, processes, system configurations, etc.) +- Communicate with technical and non-technical stakeholders and leaders on cybersecurity risk and controls management topics and program-specific reporting +- Assist with the Customer Trust program which may include managing customer assessments, and security questionnaires +- Assist control owners with root cause analysis and track risk management action plan progress. +- Create risk metrics for management regarding information security control maturity, compliance status, risks, performance and findings Assist with the third-party risk management assessment process, ensuring consistent enforcement of information security requirements + +You + +- Have a minimum of 8 years of experience supporting cybersecurity risk or controls management programs with in-depth knowledge and experience of cybersecurity frameworks including ISO 27001 and 27701, PCI-DSS, SOC, NIST CSF and other regulatory requirements +- Have experience managing and running audits, certification programs and control assessments. This includes but is not limited to scope planning, defining control procedures based on requirements, policies and standards, control testing, and mapping issues to risks +- Have experience collaborating closely with engineers, business teams, and security partners, including incident response, red teams, and architects to seamlessly incorporate cybersecurity controls and risk management processes into their day-to-day operations +- Possess a strong ability to define, drive and execute a program vision, strategy, approach and milestones in alignment with organization priorities and initiatives + +Nice to Have + +- Experience in the machine learning or computer hardware industry +- Experience with Security by Design and/or Privacy by Design principles +- Experience with standard cyber controls frameworks, including CIS Top18, NIST Cyber Security Framework (CSF), NIST 800.53, NIST 800.171, CMMC, Cybersecurity Maturity Model Certification (CMMC), ISO 27001 and 27701, and SOX ITGC control frameworks. +- Broad knowledge of IT infrastructure and architecture of computer systems as well as exposure to a variety of platforms such as operating systems, networks, databases, and ERP systems +- Familiarity with using third-party tools such as Audit Board, Whistic, RSA Archer, ServiceNow for third-party risk management +- Certified Information Systems Auditor (CISA) +- Certified Information Security Manager (CISM) +- Certified Information Systems Security Professional (CISSP) +- Certified in Risk and Information Systems Control (CRISC) +- Experience in the AI infrastructure, machine learning and/or computer hardware industry + +Salary Range Information + +The annual salary range for this position has been set based on market data and other factors. However, a salary higher or lower than this range may be appropriate for a candidate whose qualifications differ meaningfully from those listed in the job description. + +About Lambda + +- Founded in 2012, with 500+ employees, and growing fast +- Our investors notably include TWG Global, US Innovative Technology Fund (USIT), Andra Capital, SGW, Andrej Karpathy, ARK Invest, Fincadia Advisors, G Squared, In-Q-Tel (IQT), KHK & Partners, NVIDIA, Pegatron, Supermicro, Wistron, Wiwynn, Gradient Ventures, Mercato Partners, SVB, 1517, and Crescent Cove +- We have research papers accepted at top machine learning and graphics conferences, including NeurIPS, ICCV, SIGGRAPH, and TOG +- Our values are publicly available: https://lambda.ai/careers (https://lambda.ai/careers) +- We offer generous cash & equity compensation +- Health, dental, and vision coverage for you and your dependents +- Wellness and commuter stipends for select roles +- 401k Plan with 2% company match (USA employees) +- Flexible paid time off plan that we all actually use + +A Final Note: + +You do not need to match all of the listed expectations to apply for this position. We are committed to building a team with a variety of backgrounds, experiences, and skills. + +Equal Opportunity Employer + +Lambda is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law. diff --git a/jobs/imported/ashby/ashby-monarchmoney-45ce8f3e-1278-4a44-8f92-fed595a6ad1a.md b/jobs/imported/ashby/ashby-monarchmoney-45ce8f3e-1278-4a44-8f92-fed595a6ad1a.md new file mode 100644 index 0000000..9097c86 --- /dev/null +++ b/jobs/imported/ashby/ashby-monarchmoney-45ce8f3e-1278-4a44-8f92-fed595a6ad1a.md @@ -0,0 +1,85 @@ +--- +title: "Security GRC Analyst (Senior/Staff)" +company: "Monarchmoney" +slug: "ashby-monarchmoney-45ce8f3e-1278-4a44-8f92-fed595a6ad1a" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/monarchmoney?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/monarchmoney/45ce8f3e-1278-4a44-8f92-fed595a6ad1a" +apply_url: "https://jobs.ashbyhq.com/monarchmoney/45ce8f3e-1278-4a44-8f92-fed595a6ad1a/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "Remote (US)" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Audit & Assurance" + - "Cloud Security" +frameworks: + - "SOC 2" + - "ISO 27001" + - "GDPR" + - "CCPA" +languages: + - "Rust" +compensation: "" +summary: "About Us: Monarch is a powerful, all-in-one personal finance platform designed to help make the complexity of finances feel simple again. Since launching in 2021, we’ve become the..." +--- + +### About Us: + +Monarch is a powerful, all-in-one personal finance platform designed to help make the complexity of finances feel simple again. Since launching in 2021, we’ve become the top-recommended personal finance app by users and experts. Our goal? To take the stress out of finances so our members can focus on what truly matters. + +We are a team of do-ers led by experienced entrepreneurs who are passionate about helping our members reach their financial goals. We are hyper focused on building a product people love and continuing to evolve based on user feedback. + +As a fully remote company (even before COVID!), we welcome applicants from almost anywhere. Our team collaborates synchronously mostly from 9 AM – 2 PM PT and embraces asynchronous work to stay connected across time zones. + +Join us on our mission to transform lives by simplifying money, together. + +The Role: + +Monarch is seeking a Security GRC Analyst to join our Security team during a period of growth. Reporting directly to the Head of Software Infrastructure, you will take point on scaling our compliance program and customer security assurance function; enabling the company to respond to increasing inbound partnership opportunities, onboard vendors safely, and maintain compliance without consuming engineering time. We have a solid foundation (SOC2 Type 2 certified (https://www.reddit.com/r/MonarchMoney/comments/1qj7r1w/monarch_is_officially_soc2_type_2_certified/)), but no dedicated owner within the team. You'll own the day-to-day while building the tooling and workflows to handle increasing volume as we grow. + +What You’ll Do: + +- Scale, automate, and optimize existing GRC, compliance, and customer assurance programs, including security questionnaires, evidence requests, trust center content, and knowledge base. +- Optimize and automate an existing third-party risk program by improving risk signal quality, automating evidence collection, and reducing assessment cycle time. +- Evaluate, implement and maintain GRC tooling (Vanta, Drata, SafeBase, etc.) with a focus on AI-powered automation to minimize operational overhead. +- Mature existing SOC 2 program by strengthening continuous controls monitoring, reducing audit prep effort, and increasing confidence in automated evidence completeness. +- Research, recommend and implement additional frameworks and attestations (ISO 27001, CSA STAR, etc.) to position Monarch as a security leader in personal finance. + +What You’ll Bring: + +- 3-5 years operating and scaling mature GRC, compliance, or customer assurance programs in high-growth environments. +- Hands-on experience with customer assurance (security questionnaires, evidence requests, RFPs). +- Hands-on experience with SOC2, CCPA/GDPR compliance and understanding of other frameworks (e.g. ISO 27001). +- Hands-on experience with Continuous Controls Monitoring and compliance automation tools (Vanta, Drata, Oneleet, SafeBase, or similar). +- Strong written communication skills to support internal and external engagements such as customer-facing responses. +- Comfort with ambiguity and building process from scratch. +- Ability to identify process anti-patterns (manual evidence requests, one-off questionnaires, duplicate controls) and replace them with durable, automated solutions. + +Nice to Haves: + +- Fintech or financial services background. +- Familiarity with cloud infrastructure (AWS) and modern SaaS stack. +- Experience in a high-growth startup environment within B2B SaaS. +- Experience leveraging AI tools (Claude, ChatGPT) for GRC workflows. +- Relevant certifications (CISA, CRISC, Security+). +- Experience partnering with IT to implement Corporate Security controls over SaaS, identity and access management (IAM), and endpoint security. #LI-DNI + +### Benefits : + +- Work wherever you want! As a fully remote company with no central office, we want you to work wherever you are happiest and most productive. Whether that’s out of your home, a co-working space, or elsewhere. +- Competitive cash and equity compensation in a hyper growth, early stage company 🚀. +- Stipend to set-up your ideal working environment. +- Competitive Benefit Plans for employees based on your location (e.g. in the US we offer: Medical, dental and vision benefits and the ability to contribute to a 401k plan). +- Unlimited PTO. +- 3 day weekend every month! We take off the “First Friday” every month to focus on rest, recuperation, or just having fun! + +We are an equal opportunity employer and value diversity. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. diff --git a/jobs/imported/ashby/ashby-notion-d1623131-b5bf-4679-bcc5-49e2df569fd7.md b/jobs/imported/ashby/ashby-notion-d1623131-b5bf-4679-bcc5-49e2df569fd7.md new file mode 100644 index 0000000..709f2ef --- /dev/null +++ b/jobs/imported/ashby/ashby-notion-d1623131-b5bf-4679-bcc5-49e2df569fd7.md @@ -0,0 +1,67 @@ +--- +title: "GRC Senior Analyst" +company: "Notion" +slug: "ashby-notion-d1623131-b5bf-4679-bcc5-49e2df569fd7" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/Notion?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/Notion/d1623131-b5bf-4679-bcc5-49e2df569fd7" +apply_url: "https://jobs.ashbyhq.com/Notion/d1623131-b5bf-4679-bcc5-49e2df569fd7/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "San Francisco, California" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "HIPAA" +languages: + - "Rust" +compensation: "" +summary: "About Us: Notion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done,..." +--- + +# About Us: + +Notion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email—with AI built in to find answers and automate work. Millions of users, from individuals to large organizations like Toyota, Figma, and OpenAI, love Notion for its flexibility and choose it because it helps them save time and money. In-person collaboration is essential to Notion's culture. We require all team members to work from our offices on Mondays, Tuesdays, and Thursdays, our designated Anchor Days. Certain teams or positions may require additional in-office workdays. + +# About the Role: + +Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure, consistent and trustworthy experience, and we value this more than anything. We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion. This is where you come in — partnering with teams across the organization to envision, plan and build Notion's Information Security posture through governance, risk and compliance. + +# What You'll Achieve: + +- Coordinate evidence collection, manage timelines with internal partners, support external auditors for compliance frameworks such as SOX ITGCs, SOC 2 Type II, ISO, HIPAA, and BSI C5. +- Help improve and maintain information security policies, controls, procedures, and standards, for processes, applications, and infrastructure. +- Use and help build custom AI agents and automation to scale and mature our Security GRC programs. For example, automate evidence collection, control monitoring workflows, and reporting. +- Contribute to the development of dashboards and metrics for compliance and audit reporting. +- Implement and expand our continuous control monitoring efforts using our compliance automation tool. +- Identify gaps in our security controls and work with teams across the organization to strengthen them. + +# Skills You'll Need to Bring: + +- Bachelor’s or master’s degree in Computer Science, Information Technology, Management Information Systems, or Cybersecurity, or equivalent practical experience. +- Strong understanding of the governance, risk, and compliance domain and why it matters for organizational security and privacy. +- Familiarity with compliance automation tools (e.g., Anecdotes, Vanta). +- Familiarity with cloud technologies (e.g., AWS, Wiz) and their relationship to risk and compliance. +- Ability to communicate complex ideas clearly to stakeholders. +- A collaborative mindset—you enjoy working cross-functionally to accomplish shared goals and care about learning, growing, and helping others do the same. +- You don’t need to be an AI expert, but you’re curious and willing to adopt AI tools to work smarter and deliver better results. + +# Nice to Haves: + +- Experience (typically 4-5+ years) in the GRC, risk, compliance, or audit domain. +- Working knowledge of Notion and how AI agents can be used to enhance GRC programs. + +We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers. If you’re excited about a role but your past experience doesn’t align perfectly with every bullet point listed in the job description, we still encourage you to apply. If you’re a builder at heart, share our company values, and enthusiastic about making software toolmaking ubiquitous, we want to hear from you. Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Notion considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, please let your recruiter know. Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role’s scope and complexity, and the candidate’s experience and expertise, and may vary from the range provided below. For roles based in San Francisco or New York City, the estimated base salary range for this role is $180,000 - $210,000 per year. By clicking “Submit Application”, I understand and agree that Notion and its affiliates and subsidiaries will collect and process my information in accordance with Notion’s Global Recruiting Privacy Policy (https://notion.notion.site/Notion-Global-Recruiting-Privacy-Policy-fc3eb4e829354a26a2bb6fd5e289b550?pvs=74) and NYLL 144 (https://notion.notion.site/Ashby-AI-Bias-Audit-2b0efdeead05803bbbfae159ec86c528). + +#LI-Onsite diff --git a/jobs/imported/ashby/ashby-ramp-9912212c-2edd-4bdb-a18c-1087bcae0522.md b/jobs/imported/ashby/ashby-ramp-9912212c-2edd-4bdb-a18c-1087bcae0522.md new file mode 100644 index 0000000..2577c20 --- /dev/null +++ b/jobs/imported/ashby/ashby-ramp-9912212c-2edd-4bdb-a18c-1087bcae0522.md @@ -0,0 +1,101 @@ +--- +title: "Software Engineer, FedRAMP Infrastructure" +company: "Ramp" +slug: "ashby-ramp-9912212c-2edd-4bdb-a18c-1087bcae0522" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/ramp?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/ramp/9912212c-2edd-4bdb-a18c-1087bcae0522" +apply_url: "https://jobs.ashbyhq.com/ramp/9912212c-2edd-4bdb-a18c-1087bcae0522/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "Washington, D.C." +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Audit & Assurance" + - "Cloud Security" +frameworks: + - "FedRAMP" +languages: + - "Terraform" + - "SQL" +compensation: "" +summary: "About Ramp Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $100B in..." +--- + +# About Ramp + +Ramp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business spends. We automate how over $100B in annualized spend flows in and out of 50,000+ companies: authorizing payments, flagging risk, categorizing spend, and closing books. + +The problems are high-stakes, data-dense, and unforgiving. + +We hire people with high agency and high urgency. We look for slope over intercept. We care less about where you trained and more about what you’ve built. At Ramp, everyone is a builder who owns problems end to end and makes consequential decisions that shape the outcome. + +The median Ramp customer saves 5% and grows revenue 16% in their first year – far in excess of businesses operating without Ramp. We believe every ambitious company deserves the same. + +If you want to build systems that directly shape how companies move and manage billions, Ramp is the place to do it. + +About the Role + +Ramp is, at its core, an engineering company, and is on a mission to build the best engineering team in the world. Our Infrastructure supports the foundations of our product and platform, owning areas like compute orchestration, databases, messaging, observability, and developer environments. We build the primitives and abstractions that let product teams move fast while ensuring security, scalability, and reliability. This role is a cross-functional position within the Infrastructure organization, with a specific focus on enabling our government environments (FedRAMP, GovRAMP). You’ll act as both a technical owner and a multiplier: helping shape compliant infrastructure patterns, identifying risks across infra domains, and partnering closely with other infra engineers to ensure our architecture continues to meet strict operational and security requirements. You will be expected to take ownership of our government infrastructure and guide its evolution, while also contributing to high-leverage infra projects across the org. Our ideal candidate combines deep cloud infrastructure experience with a strong sense of ownership, collaborative instincts, understands the nuances of operating in secure and regulated environments, and has a desire to mentor others and raise the bar across the team. + +What You’ll Do + +- Influence the evolution of Ramp’s infrastructure to support our government environments +- Work across infra domains to contribute to the next generation of Ramp's database, real-time queue, or container orchestration infrastructure, and ensure proposed changes are viable within our secure environments +- Collaborate across our engineering organization to introduce and scale best practices with cloud-native technologies like Cloudflare, Amazon ALB, Service Discovery, ECS/EKS, Celery, Kafka, Amazon Aurora PostgreSQL, Elasticache Redis, and S3 +- Build abstractions within Terraform to simplify architecture and increase developer velocity and ownership +- Find solutions to Ramp's toughest scaling, performance, and low-latency problems +- Participate in an on-call rotation to address critical production events +- Mentor other engineers and contribute to a high-performing, inclusive engineering culture + +What You Need + +- Minimum 6 years of experience shipping high-quality architectures for critical systems preferred +- Production experience in AWS, GCP, or Azure +- An ability to think through customer requirements and come up with high-impact ways to quickly solve their problems +- Expertise in a production deployment of Infrastructure-as-Code i.e. Terraform +- Proficiency in an object-oriented programing language + +FedRAMP Requirements + +- Proven experience designing and operating cloud infrastructure (AWS) compliant with FedRAMP security standards. +- Expertise implementing secure Infrastructure-as-Code (Terraform) solutions aligned with FedRAMP controls and audits. +- Deep understanding of secure data handling, encryption, logging, and access controls required under FedRAMP guidelines. +- Strong experience building, scaling, and securing database infrastructure and container orchestration systems to meet FedRAMP compliance. + +## Benefits (for U.S.-based full-time employees) + +- 100% medical, dental & vision insurance coverage for you Partially covered for your dependents +- One Medical annual membership + +- 401k (including employer match on contributions made while employed by Ramp) +- Flexible PTO +- Fertility HRA (up to $10,000 per year) +- Parental Leave +- Unlimited AI token usage +- Pet insurance +- Centralized home-office equipment ordering for all employees +- Health and Wellness stipend +- In-office perks: lunch, snacks, drinks, and more +- Budget for intra-office travel +- Relocation support to NYC or SF (as needed) + +## Referral Instructions + +If you are being referred for the role, please contact that person to apply on your behalf. + +## Other notices + +Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. + +Beware of recruiting scams: Ramp will only contact you through official @ Ramp.com (http://Ramp.com) email addresses and will never ask for payment or sensitive personal information during the hiring process. + +Ramp Applicant Privacy Notice (https://ramp.com/legal/applicant-privacy-notice) diff --git a/jobs/imported/ashby/ashby-replit-3475841f-c994-4443-b83d-4b8a5b1dd8f2.md b/jobs/imported/ashby/ashby-replit-3475841f-c994-4443-b83d-4b8a5b1dd8f2.md new file mode 100644 index 0000000..0bdb345 --- /dev/null +++ b/jobs/imported/ashby/ashby-replit-3475841f-c994-4443-b83d-4b8a5b1dd8f2.md @@ -0,0 +1,128 @@ +--- +title: "GRC Lead (Governance, Risk, and Compliance)" +company: "Replit" +slug: "ashby-replit-3475841f-c994-4443-b83d-4b8a5b1dd8f2" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/replit?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/replit/3475841f-c994-4443-b83d-4b8a5b1dd8f2" +apply_url: "https://jobs.ashbyhq.com/replit/3475841f-c994-4443-b83d-4b8a5b1dd8f2/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "Foster City, CA (Hybrid) In office M,W,F" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "FedRAMP" + - "SOC 2" + - "ISO 27001" + - "PCI-DSS" + - "HIPAA" +languages: + - "Rust" +compensation: "" +summary: "Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing..." +--- + +Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. + +## About the role + +We are looking for a GRC Lead to serve as the Technical Lead for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, guiding a team of GRC specialists while partnering deeply across the organization. We need a pragmatic operator who understands that GRC exists to enable the business—balancing rigorous standards with the velocity of a high-growth startup. + +## What You'll Do + +Technical Leadership & Mentorship + +- Team Leadership: Act as the technical anchor for the GRC team. You will mentor GRC analysts and engineers, setting the standard for quality, technical depth, and operational efficiency. +- Program Architecture: Own the technical vision for Replit’s GRC program, moving the team from manual workflows toward "Compliance-as-Code" and automated evidence collection. +- Thought Leadership: Champion a culture of security and privacy across the company, educating teams on why controls exist rather than just enforcing them. + +Cross-Functional Collaboration + +- Engineering & Architecture: Partner with Architects and Engineering Leads to "bake in" compliance requirements early in the design phase. You will translate complex technical implementations into narratives that satisfy frameworks without slowing down development. +- Legal & Privacy: Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging AI-specific regulations (e.g., EU AI Act). +- Sales & GTM: Enable the Sales team by managing the Customer Trust Center and handling complex security questionnaires. You will serve as a subject matter expert in customer calls to build confidence with enterprise prospects. +- Auditor Relationships: Own and cultivate the primary relationship with external auditors. You will serve as the bridge between auditors and internal teams, ensuring requests are reasonable, clear, and relevant to our tech stack. + +Risk Management & Strategic Compliance + +- Risk Register Owner: You will own the Cybersecurity Risk Register . You will be responsible for identifying, quantifying, and tracking risks, distinguishing between theoretical compliance gaps and meaningful business risks. +- Framework Evolution: Manage and evolve our compliance posture across SOC 2, ISO 27001 , and prepare the organization for future certifications in regulated markets (e.g., FedRAMP, ITAR, PCI, HIPAA ). +- Pragmatic Governance: Apply judgment to operate in "gray areas" when appropriate. You will prioritize issues that represent real security or business risk over "compliance theater." + +Automation & Efficiency + +- Control Automation: Drive the shift from manual evidence collection to continuous monitoring. You will identify opportunities to automate audit work, ensuring GRC scales with the business. +- Third-Party Risk: Architect a scalable framework for assessing third-party vendors and AI model providers, ensuring our supply chain remains secure without creating administrative bottlenecks. + +## Required Skills & Experience + +- 8+ years of experience in GRC or Information Security +- Leadership Experience: Proven experience mentoring other GRC professionals or leading complex cross-functional projects. +- Technical Fluency: Ability to speak the language of engineering, cloud (GCP/AWS), and security architecture. You can anticipate how architectural decisions impact risk and compliance. +- Regulatory Breadth: Deep experience with SOC 2, ISO 27001, PCI, HIPPA, and Privacy laws. +- Collaborative Communication: Strong ability to explain risk and tradeoffs to technical (Engineers), legal, and commercial (Sales/Execs) stakeholders. +- Automation Mindset: Experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil. + +## Bonus Qualifications + +- Familiarity with FedRAMP, ITAR, or AI regulation is a strong plus. + +### What We Value + +- Pragmatism: You distinguish between "checking a box" and reducing risk. You focus on outcomes over optics. +- Business Enablement: You understand that your role is to help Replit sell to the enterprise safely, not to say "no" to innovation. +- Solutions-Oriented Leadership: You are collaborative and low-ego. You prefer fixing root causes and empowering teams over enforcing rigid bureaucracy. +- Clarity: You can take a complex regulation and explain exactly what it means for a specific engineering team in plain English. + +This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday. + +Full-Time Employee Benefits Include: + +💰 Competitive Salary & Equity + +💹 401(k) Program with a 4% match + +⚕️ Health, Dental, Vision and Life Insurance + +🩼 Short Term and Long Term Disability + +🚼 Paid Parental, Medical, Caregiver Leave + +🚗 Commuter Benefits + +📱 Monthly Wellness Stipend + +🧑‍💻 Autonomous Work Environment + +🖥 In Office Set-Up Reimbursement + +🏝 Flexible Time Off (FTO) + Holidays + +🚀 Quarterly Team Gatherings + +☕ In Office Amenities + +Want to learn more about what we are up to? + +- Meet the Replit Agent (https://www.youtube.com/watch?v=IYiVPrxY8-Y) +- Replit: Make an app for that (https://www.youtube.com/watch?v=4zd9hzngFwY) +- Replit Blog (https://blog.replit.com/) +- Amjad TED Talk (https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi) + +Interviewing + Culture at Replit + +- Operating Principles (https://blog.replit.com/operating-principles) +- Reasons not to work at Replit (https://blog.replit.com/reasons-not-to-join-replit) + +To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds. diff --git a/jobs/imported/ashby/ashby-socure-b9dc8d7e-9f0e-40e7-876e-82eedcaa6017.md b/jobs/imported/ashby/ashby-socure-b9dc8d7e-9f0e-40e7-876e-82eedcaa6017.md new file mode 100644 index 0000000..a7cfcfb --- /dev/null +++ b/jobs/imported/ashby/ashby-socure-b9dc8d7e-9f0e-40e7-876e-82eedcaa6017.md @@ -0,0 +1,113 @@ +--- +title: "GRC Analyst – Public Sector" +company: "Socure" +slug: "ashby-socure-b9dc8d7e-9f0e-40e7-876e-82eedcaa6017" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/socure?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/socure/b9dc8d7e-9f0e-40e7-876e-82eedcaa6017" +apply_url: "https://jobs.ashbyhq.com/socure/b9dc8d7e-9f0e-40e7-876e-82eedcaa6017/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "Remote - US" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "FedRAMP" + - "NIST 800-53" + - "NIST 800-171" + - "GDPR" + - "CCPA" +languages: + - "OSCAL" + - "Rust" +compensation: "" +summary: "Why Socure? Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The..." +--- + +## Why Socure? + +Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day. + +We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won’t be your place. If you want to help build the future of identity with a team that holds a high bar for itself — keep reading. + +# About the role + +Socure is seeking an Analyst, GRC – Public Sector to execute and enhance the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role drives measurable improvements in compliance efficiency and audit readiness by managing vulnerability remediation, continuous monitoring, access oversight, and evidence preparation that allow Socure to meet the rigorous standards of FedRAMP, GovRAMP, and related frameworks. The Analyst collaborates across Security, Engineering, IT, DevOps, Product, Legal, and other teams to operationalize regulatory requirements, automate workflows, and offers the opportunity to shape the GRC strategy for Socure’s fast-growing public sector business. + +# What you'll do + +### Compliance & Certification Management + +- Day-to-day coordination and execution of external Third Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation. +- Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks. +- Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices. + +### Continuous Monitoring & Vulnerability Management + +- Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines. +- Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing. + +### Access Management & Training + +- Oversee access controls for FedRAMP environments, including access requests, least privilege reviews and role-based access control validation and quarterly access certifications. +- Design, implement and deliver FedRAMP training programs to promote compliance awareness +- Create and manage automated workflows to improve efficiency. + +### Audit & Assessment Readiness + +- Maintain compliance evidence repositories. audit preparation materials, and reporting artifacts. +- Conduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress. + +### Process Improvement & Collaboration + +- Collaborate with the Director of GRC to design and implement AI-enabled compliance workflows, leveraging automation tools to streamline evidence generation, reporting, and audit readiness +- Support the development, rollout, and maintenance of machine-readable compliance documentation (e.g., OSCAL or comparable structured formats) to facilitate interoperability +- Partner with automation and engineering teams to integrate structured compliance data into Socure’s broader risk management and monitoring ecosystem including vulnerability remediation, access requests, and compliance reporting. +- Monitor regulatory and industry trends for potential impacts to compliance strategy. + +### Public Sector Sales & Customer Engagement + +- Serve as a security subject matter expert for public sector sales activities, including prospect briefings, RFP/RFQ responses, contract negotiations, and integration discussions. +- Support development of external communications such as press releases and customer-facing materials related to security certifications and authorizations. + +### Monitor Evolving Requirements + +- Monitor new and evolving requirements and perform gap analyses including Updates to applicable NIST Special Publications and other government standards +- Contract security requirements from new customers +- Updates to the FedRAMP Program requirements and processes as the program evolves + +- Provide input to standards bodies on evolving standards when applicable + +# What you'll bring + +- 5+ years of cybersecurity or identity management experience, including 1+ year in the public sector. +- Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171). +- Proven ability to manage continuous monitoring, vulnerability remediation, and compliance reporting. +- Experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to automate and streamline compliance processes. +- Strong communication, organization, and collaboration skills with the ability to manage multiple priorities. +- Ability to adapt to changing requirements +- Must be a U.S. Person (U.S. Citizens or U.S. Permanent Residents) residing in the United States and be able to obtain a U.S. OPM NACI clearance. + +### Preferred Qualifications + +- Experience in regulated industries (e.g., financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards. +- Professional certifications preferred (CISSP, CISM, CISA, IAPP). +- Proven success leading certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171) +- Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams. +- Strong understanding of evolving cybersecurity standards and digital identity regulations, with the ability to translate them into practical risk and compliance improvements. + +Socure is an equal opportunity employer that values diversity in all its forms within our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you need an accommodation during any stage of the application or hiring process—including interview or onboarding support—please reach out to your Socure recruiting partner directly. + +Follow Us! + +YouTube (https://www.youtube.com/c/Socure) | LinkedIn (https://www.linkedin.com/company/socure/) | X (Twitter) (https://x.com/socureme) | Facebook (https://www.facebook.com/socure/) diff --git a/jobs/imported/ashby/ashby-writer-2702b1ce-58ce-4884-bc43-b47cc1bc1f23.md b/jobs/imported/ashby/ashby-writer-2702b1ce-58ce-4884-bc43-b47cc1bc1f23.md new file mode 100644 index 0000000..ab46bd4 --- /dev/null +++ b/jobs/imported/ashby/ashby-writer-2702b1ce-58ce-4884-bc43-b47cc1bc1f23.md @@ -0,0 +1,81 @@ +--- +title: "Security specialist, GRC (UK)" +company: "Writer" +slug: "ashby-writer-2702b1ce-58ce-4884-bc43-b47cc1bc1f23" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/writer?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/writer/2702b1ce-58ce-4884-bc43-b47cc1bc1f23" +apply_url: "https://jobs.ashbyhq.com/writer/2702b1ce-58ce-4884-bc43-b47cc1bc1f23/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "London, UK" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "GDPR" + - "CCPA" +languages: + - "Rust" +compensation: "" +summary: "🚀 About WRITER WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving..." +--- + +## 🚀 About WRITER + +WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving it's possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER's end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company's data and fueled by WRITER's enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI. + +Founded in 2020 with office hubs in San Francisco, New York City, Austin, Chicago, and London, our team thinks big and moves fast, and we're looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI. + +## 📐 About the role + +This is your chance to shape AI governance from the ground up at one of the fastest-growing companies in enterprise AI. As a security specialist, GRC at WRITER, you'll be building the frameworks that ensure our AI platform earns and keeps the trust of the world's most demanding enterprises. You're not just checking boxes—you're creating the compliance infrastructure that enables WRITER to scale safely and securely while moving at the speed of innovation. + +The opportunity here is extraordinary: you'll work at the intersection of AI, security, and business enablement, helping define what governance looks like for enterprise AI systems that didn't exist a few years ago. You'll lead audit engagements for SOC 2, ISO 27001, and other critical certifications, respond to customer security assessments that directly impact major deals, and build the policies and controls that protect both our AI models and the sensitive data flowing through them. You'll translate complex regulatory requirements into practical, business-aligned security controls while partnering with Engineering, Legal, Product, and Sales to ensure WRITER can sell into highly regulated industries without compromising our velocity. + +This role is hybrid from our London office, reporting to the head of security. + +## 🦸🏻‍♀️ What you'll do + +- Own and drive WRITER's security compliance program end-to-end including managing SOC 2 Type II audits, ISO Triad (27001/27701/42001) certification, and expanding our compliance coverage to meet emerging customer requirements in regulated industries like financial services and healthcare +- Lead customer assurance efforts by responding to security questionnaires, DDQs, and RFPs from enterprise customers, maintaining our trust portal with up-to-date security documentation, and partnering with Sales to remove security blockers that could delay major deals +- Build and maintain WRITER's security governance framework including creating and updating security policies, access control standards, vendor risk procedures, incident response plans, and AI-specific governance documentation that addresses model training, data handling, and responsible AI deployment +- Conduct continuous control monitoring and evidence collection by implementing automated compliance workflows, tracking remediation activities across teams, performing control testing, and ensuring we maintain audit-ready documentation throughout the year instead of scrambling before audits +- Drive risk assessments and third-party vendor security reviews by evaluating supplier controls, identifying and quantifying security risks across our AI platform and infrastructure, and working cross-functionally to prioritize and track remediation efforts +- Partner with Engineering and Product teams to embed compliance into the development lifecycle by reviewing architecture decisions for security and privacy implications, ensuring secure-by-design principles are followed for new AI features, and translating regulatory requirements into technical controls that developers can actually implement +- Serve as the primary point of contact for external auditors and assessors, coordinating evidence collection, scheduling interviews, addressing findings, and ensuring audit processes run smoothly while minimizing disruption to the broader team + +## ⭐️ What you need + +- 2+ years of hands-on experience in GRC, security compliance, or audit roles within fast-paced tech companies or startups—you understand how to build compliance programs that enable growth rather than slow it down +- Deep working knowledge of security frameworks and certifications including SOC 2 Type II, ISO 27001, GDPR, CCPA, and familiarity with emerging AI governance requirements—you've led audits from planning through certification and can speak confidently about control requirements +- Strong technical literacy that allows you to evaluate cloud security architectures, understand API security, review access control implementations, and have credible conversations with engineers about security controls—you don't need to write code but you need to understand how systems work +- Excellent project management abilities with the skill to juggle multiple audits, customer questionnaires, policy updates, and remediation initiatives simultaneously while keeping stakeholders informed and projects moving forward without constant oversight +- Outstanding communication skills that enable you to explain complex compliance requirements in clear, actionable language to technical and non-technical audiences alike—you can craft policies that engineers will actually follow and present risk scenarios that executives will understand +- Natural curiosity about AI governance and emerging regulatory landscape including AI-specific frameworks, model risk management, data privacy implications of AI training, and responsible AI principles—you're excited to help define best practices in an evolving space +- Alignment with WRITER's values of Connect (building trusted relationships with customers, auditors, and cross-functional teams), Challenge (pushing beyond checkbox compliance to create governance that truly reduces risk), and Own (taking full accountability for WRITER's security posture and customer trust) + +## 🍩 Benefits & perks (UK full-time employees): + +- Generous PTO, plus company holidays +- Comprehensive medical and dental insurance +- Paid parental leave for all parents (12 weeks) +- Fertility and family planning support +- Early-detection cancer testing through Galleri (https://www.galleri.com/partner/writer) +- Competitive pension scheme and company contribution +- Annual work-life stipends for: Wellness stipend for gym, massage/chiropractor, personal training, etc. +- Learning and development stipend + +- Company-wide off-sites and team off-sites +- Competitive compensation and company stock options diff --git a/jobs/imported/ashby/ashby-writer-5d7cf717-bfdc-4695-b49e-894786850d5d.md b/jobs/imported/ashby/ashby-writer-5d7cf717-bfdc-4695-b49e-894786850d5d.md new file mode 100644 index 0000000..973c5f6 --- /dev/null +++ b/jobs/imported/ashby/ashby-writer-5d7cf717-bfdc-4695-b49e-894786850d5d.md @@ -0,0 +1,86 @@ +--- +title: "Security specialist, GRC" +company: "Writer" +slug: "ashby-writer-5d7cf717-bfdc-4695-b49e-894786850d5d" +status: "published" +source: "Ashby" +sources: + - "Ashby" +source_url: "https://api.ashbyhq.com/posting-api/job-board/writer?includeCompensation=true" +role_url: "https://jobs.ashbyhq.com/writer/5d7cf717-bfdc-4695-b49e-894786850d5d" +apply_url: "https://jobs.ashbyhq.com/writer/5d7cf717-bfdc-4695-b49e-894786850d5d/application" +posted_date: "2026-04-07" +expires_date: "2026-05-07" +location: "New York City, NY" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "GDPR" + - "CCPA" +languages: + - "Rust" +compensation: "" +summary: "🚀 About WRITER WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving..." +--- + +## 🚀 About WRITER + +WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving it's possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER's end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company's data and fueled by WRITER's enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI. + +Founded in 2020 with office hubs in San Francisco, New York City, Austin, Chicago, and London, our team thinks big and moves fast, and we're looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI. + +## 📐 About the role + +This is your chance to shape AI governance from the ground up at one of the fastest-growing companies in enterprise AI. As a security specialist, GRC at WRITER, you'll be building the frameworks that ensure our AI platform earns and keeps the trust of the world's most demanding enterprises. You're not just checking boxes—you're creating the compliance infrastructure that enables WRITER to scale safely and securely while moving at the speed of innovation. + +The opportunity here is extraordinary: you'll work at the intersection of AI, security, and business enablement, helping define what governance looks like for enterprise AI systems that didn't exist a few years ago. You'll lead audit engagements for SOC 2, ISO 27001, and other critical certifications, respond to customer security assessments that directly impact major deals, and build the policies and controls that protect both our AI models and the sensitive data flowing through them. You'll translate complex regulatory requirements into practical, business-aligned security controls while partnering with Engineering, Legal, Product, and Sales to ensure WRITER can sell into highly regulated industries without compromising our velocity. + +This role is hybrid from our San Francisco or New York City offices, reporting to the head of security. + +## 🦸🏻‍♀️ What you'll do + +- Own and drive WRITER's security compliance program end-to-end including managing SOC 2 Type II audits, ISO Triad (27001/27701/42001) certification, and expanding our compliance coverage to meet emerging customer requirements in regulated industries like financial services and healthcare +- Lead customer assurance efforts by responding to security questionnaires, DDQs, and RFPs from enterprise customers, maintaining our trust portal with up-to-date security documentation, and partnering with Sales to remove security blockers that could delay major deals +- Build and maintain WRITER's security governance framework including creating and updating security policies, access control standards, vendor risk procedures, incident response plans, and AI-specific governance documentation that addresses model training, data handling, and responsible AI deployment +- Conduct continuous control monitoring and evidence collection by implementing automated compliance workflows, tracking remediation activities across teams, performing control testing, and ensuring we maintain audit-ready documentation throughout the year instead of scrambling before audits +- Drive risk assessments and third-party vendor security reviews by evaluating supplier controls, identifying and quantifying security risks across our AI platform and infrastructure, and working cross-functionally to prioritize and track remediation efforts +- Partner with Engineering and Product teams to embed compliance into the development lifecycle by reviewing architecture decisions for security and privacy implications, ensuring secure-by-design principles are followed for new AI features, and translating regulatory requirements into technical controls that developers can actually implement +- Serve as the primary point of contact for external auditors and assessors, coordinating evidence collection, scheduling interviews, addressing findings, and ensuring audit processes run smoothly while minimizing disruption to the broader team + +## ⭐️ What you need + +- 2+ years of hands-on experience in GRC, security compliance, or audit roles within fast-paced tech companies or startups—you understand how to build compliance programs that enable growth rather than slow it down +- Deep working knowledge of security frameworks and certifications including SOC 2 Type II, ISO 27001, GDPR, CCPA, and familiarity with emerging AI governance requirements—you've led audits from planning through certification and can speak confidently about control requirements +- Strong technical literacy that allows you to evaluate cloud security architectures, understand API security, review access control implementations, and have credible conversations with engineers about security controls—you don't need to write code but you need to understand how systems work +- Excellent project management abilities with the skill to juggle multiple audits, customer questionnaires, policy updates, and remediation initiatives simultaneously while keeping stakeholders informed and projects moving forward without constant oversight +- Outstanding communication skills that enable you to explain complex compliance requirements in clear, actionable language to technical and non-technical audiences alike—you can craft policies that engineers will actually follow and present risk scenarios that executives will understand +- Natural curiosity about AI governance and emerging regulatory landscape including AI-specific frameworks, model risk management, data privacy implications of AI training, and responsible AI principles—you're excited to help define best practices in an evolving space +- Alignment with WRITER's values of Connect (building trusted relationships with customers, auditors, and cross-functional teams), Challenge (pushing beyond checkbox compliance to create governance that truly reduces risk), and Own (taking full accountability for WRITER's security posture and customer trust) + +🍩 Benefits & perks (US Full-time employees) + +- Generous PTO, plus company holidays +- Medical, dental, and vision coverage for you and your family +- Paid parental leave for all parents (12 weeks) +- Fertility and family planning support +- Early-detection cancer testing through Galleri (https://www.galleri.com/partner/writer) +- Flexible spending account and dependent FSA options +- Health savings account for eligible plans with company contribution +- Annual work-life stipends for: Wellness stipend for gym, massage/chiropractor, personal training, etc. +- Learning and development stipend + +- Company-wide off-sites and team off-sites +- Competitive compensation, company stock options and 401k + +WRITER is an equal-opportunity employer and is committed to diversity. We don't make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. + +By submitting your application on the application page, you acknowledge and agree to WRITER's Global Candidate Privacy Notice (https://writer.com/legal/candidate-privacy-notice/). diff --git a/jobs/imported/greenhouse/greenhouse-andurilindustries-5087188007-senior-compliance-engineer.md b/jobs/imported/greenhouse/greenhouse-andurilindustries-5087188007-senior-compliance-engineer.md new file mode 100644 index 0000000..e479db5 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-andurilindustries-5087188007-senior-compliance-engineer.md @@ -0,0 +1,174 @@ +--- +title: "Senior Compliance Engineer" +company: "Andurilindustries" +slug: "greenhouse-andurilindustries-5087188007-senior-compliance-engineer" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/andurilindustries/jobs?content=true" +role_url: "https://boards.greenhouse.io/andurilindustries/jobs/5087188007?gh_jid=5087188007" +apply_url: "https://boards.greenhouse.io/andurilindustries/jobs/5087188007?gh_jid=5087188007" +posted_date: "2026-04-03" +expires_date: "2026-05-03" +location: "Costa Mesa, California, United States" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "FedRAMP" + - "SOC 2" + - "NIST 800-53" + - "NIST 800-171" + - "CMMC" +languages: + - "Python" + - "Terraform" + - "Rust" +compensation: "" +summary: "Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise,..." +--- + +

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

ABOUT THE TEAM

+

The Corporate Assurance Team manages enterprise cybersecurity governance, risk, and compliance (GRC) by implementing and operationalizing global compliance frameworks across Anduril's corporate and product environments. The team serves as the bridge between regulatory requirements and engineering execution, ensuring that Anduril's rapidly evolving technology stack meets the highest standards of security and compliance.

+

ABOUT THE JOB

+

The Compliance Engineer is a technically hands-on role responsible for driving automation, compliance, and security engineering principles into the design, integration, and operation of Anduril's internal systems. This individual will be instrumental in securing Anduril's software development process by translating complex compliance requirements into scalable, automated, and developer-friendly solutions.

+

The ideal candidate brings a strong DevSecOps background with deep expertise in cloud infrastructure security, embedded systems security, and federal compliance frameworks. They are equally comfortable writing Terraform modules as they are interpreting NIST controls, and they thrive at the intersection of security policy and engineering execution.

+

This is not a paperwork-driven compliance role. This is a builder's role. You will architect and automate compliance infrastructure that enables Anduril's engineering teams to deploy secure, compliant applications by default — removing bottlenecks rather than creating them.

+

WHY THIS ROLE MATTERS

+

At Anduril, compliance is not a checkbox — it is an engineering discipline. The Compliance Engineer plays a critical role in ensuring that Anduril can move fast without compromising the security and regulatory posture required to serve national defense missions. By building compliance into the foundation of our infrastructure, you will directly enable engineering teams to focus on what they do best: building transformative technology that protects those who protect us.

+

KEY RESPONSIBILITIES

+

Infrastructure & Automation

+ +

Compliance Engineering & Framework Implementation

+ +

Cross-Functional Collaboration & Enablement

+ +

Strategic & Advisory

+ +

REQUIRED QUALIFICATIONS

+

Education & Experience

+ +

Technical Skills

+ +

Soft Skills & Competencies

+ +

Eligibility

+ +

PREFERRED QUALIFICATIONS

+
US Salary Range
$146,000$194,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including: 

+

Healthcare Benefits 

+
    +
  • US Roles: Comprehensive medical, dental, and vision plans at little to no cost to you. 
  • +
  • UK & AUS Roles: We cover full cost of medical insurance premiums for you and your dependents. 
  • +
  • IE Roles: We offer an annual contribution toward your private health insurance for you and your dependents. 
  • +
+

Additional Benefits 

+
    +
  • Income Protection: Anduril covers life and disability insurance for all employees. 
  • +
  • Generous time off: Highly competitive PTO plans with a holiday hiatus in December. Caregiver & Wellness Leave is available to care for family members, bond with a new baby, or address your own medical needs. 
  • +
  • Family Planning & Parenting Support: Coverage for fertility treatments (e.g., IVF, preservation), adoption, and gestational carriers, along with resources to support you and your partner from planning to parenting. 
  • +
  • Mental Health Resources: Access free mental health resources 24/7, including therapy and life coaching. Additional work-life services, such as legal and financial support, are also available. 
  • +
  • Professional Development: Annual reimbursement for professional development 
  • +
  • Commuter Benefits: Company-funded commuter benefits based on your region. 
  • +
  • Relocation Assistance: Available depending on role eligibility. 
  • +
+

Retirement Savings Plan 

+
    +
  • US Roles: Traditional 401(k), Roth, and after-tax (mega backdoor Roth) options. 
  • +
  • UK & IE Roles: Pension plan with employer match. 
  • +
  • AUS Roles: Superannuation plan. 
  • +
+

The recruiter assigned to this role can share more information about the specific compensation and benefit details associated with this role during the hiring process. 

+

 

+
+

Protecting Yourself from Recruitment Scams

+

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

+
+
+

To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:

+
    +
  • +

    No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

    +
  • +
  • Please always verify communications: +
      +
    • Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.
    • +
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to contact@anduril.com
    • +
    +
  • +
  • +

    Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links.

    +
  • +
  • +

    What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

    +
  • +
+
+

Data Privacy

+

To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/. 

diff --git a/jobs/imported/greenhouse/greenhouse-anthropic-4980335008-grc-automation-engineering-lead.md b/jobs/imported/greenhouse/greenhouse-anthropic-4980335008-grc-automation-engineering-lead.md new file mode 100644 index 0000000..5978587 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-anthropic-4980335008-grc-automation-engineering-lead.md @@ -0,0 +1,84 @@ +--- +title: "GRC Automation Engineering Lead " +company: "Anthropic" +slug: "greenhouse-anthropic-4980335008-grc-automation-engineering-lead" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/anthropic/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/anthropic/jobs/4980335008" +apply_url: "https://job-boards.greenhouse.io/anthropic/jobs/4980335008" +posted_date: "2026-04-01" +expires_date: "2026-05-01" +location: "San Francisco, CA | New York City, NY | Seattle, WA" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "FedRAMP" + - "SOC 2" + - "HIPAA" +languages: + - "Python" + - "Terraform" + - "Rust" +compensation: "" +summary: "About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole...." +--- + +

About Anthropic

+

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the Role

+

We are seeking a GRC Automation Lead to join our GRC organization and build the technical foundation for how we scale our risk and compliance programs. In this role, you will lead the team that designs and implements automated workflows, data pipelines, and integrations that transform manual compliance processes into scalable engineering systems. 

+

This is a greenfield opportunity to establish the team, architecture, and integrations that will define how we approach governance, risk, and compliance at Anthropic. The core challenge is a data problem: compliance information lives across dozens of systems—cloud infrastructure, identity providers, HR platforms, ticketing tools, code repositories—and your job is to design systems that bring it together, normalize it, and make it actionable. Success in this role comes from understanding how systems connect and how data flows between them, not from writing code yourself.

+

At Anthropic, you'll also have a unique advantage: the ability to design AI-powered workflows where Claude acts as an extension of your team, handling tasks that would traditionally require additional headcount or manual effort. You'll need ingenuity to identify where agentic AI can accelerate evidence collection, interpret unstructured data, triage compliance gaps, and augment human judgment in risk assessments. Working closely with Security, IT, and Engineering teams, you'll translate compliance and regulatory requirements into solutions that support audit programs including SOC 2, ISO, HIPAA, and FedRAMP, building systems that combine traditional automation with AI capabilities to achieve scale that wouldn't otherwise be possible.

+

Responsibilities: 

+ +

You may be a good fit if you:

+ +

Strong candidates may have:

+ +

Deadline to apply: None, applications will be received on a rolling basis.

The annual compensation range for this role is listed below. 

+

For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:
$405,000$405,000 USD

Logistics

+

Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience

+

Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience

+

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

+

Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

+

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

+

We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed.  Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.

Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visit anthropic.com/careers directly for confirmed position openings.

+

How we're different

+

We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.

+

The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.

+

Come work with us!

+

Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process

diff --git a/jobs/imported/greenhouse/greenhouse-anthropic-5160757008-security-risk-and-compliance-hipaa.md b/jobs/imported/greenhouse/greenhouse-anthropic-5160757008-security-risk-and-compliance-hipaa.md new file mode 100644 index 0000000..5119a2b --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-anthropic-5160757008-security-risk-and-compliance-hipaa.md @@ -0,0 +1,87 @@ +--- +title: "Security Risk & Compliance, HIPAA" +company: "Anthropic" +slug: "greenhouse-anthropic-5160757008-security-risk-and-compliance-hipaa" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/anthropic/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/anthropic/jobs/5160757008" +apply_url: "https://job-boards.greenhouse.io/anthropic/jobs/5160757008" +posted_date: "2026-04-01" +expires_date: "2026-05-01" +location: "San Francisco, CA | New York City, NY | Seattle, WA; Washington, DC" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST 800-53" + - "HIPAA" + - "HITRUST" +languages: + - "Rust" +compensation: "" +summary: "About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole...." +--- + +

About Anthropic

+

Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About that Role

+

As part of the Anthropic security department, the compliance team owns understanding security and AI safety expectations, as established by regulators, customers, and (nascent) industry norms — which we also seek to influence. The compliance team uses this understanding to provide direction to internal partners on the priorities of security and safety requirements they must meet. The compliance team demonstrates adherence to security expectations through credential attainment, the establishment of assurance and oversight mechanisms, and direct engagement with auditors, customers, and partners.

+

This opportunity is unique. Anthropic is expanding HIPAA coverage across its product portfolio — including Claude Code, the Claude Developer Platform, and Claude Cowork — and we need to build the compliance infrastructure to match that expansion. We are looking for someone to own HIPAA compliance operations end-to-end, not just advise on it.

+

Responsibilities:

+ +

You may be a good fit if you:

+ +

Strong candidates may also:

+ +

Candidates need not have:

+ +

Deadline to Apply: None, applications will be received on a rolling basis.

The annual compensation range for this role is listed below. 

+

For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:
$255,000$270,000 USD

Logistics

+

Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience

+

Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience

+

Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position

+

Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.

+

Visa sponsorship: We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.

+

We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed.  Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.

Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you're ever unsure about a communication, don't click any links—visit anthropic.com/careers directly for confirmed position openings.

+

How we're different

+

We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact — advancing our long-term goals of steerable, trustworthy AI — rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We're an extremely collaborative group, and we host frequent research discussions to ensure that we are pursuing the highest-impact work at any given time. As such, we greatly value communication skills.

+

The easiest way to understand our research directions is to read our recent research. This research continues many of the directions our team worked on prior to Anthropic, including: GPT-3, Circuit-Based Interpretability, Multimodal Neurons, Scaling Laws, AI & Compute, Concrete Problems in AI Safety, and Learning from Human Preferences.

+

Come work with us!

+

Anthropic is a public benefit corporation headquartered in San Francisco. We offer competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and a lovely office space in which to collaborate with colleagues. Guidance on Candidates' AI Usage: Learn about our policy for using AI in our application process

diff --git a/jobs/imported/greenhouse/greenhouse-appliedintuition-4672836005-risk-and-compliance-lead.md b/jobs/imported/greenhouse/greenhouse-appliedintuition-4672836005-risk-and-compliance-lead.md new file mode 100644 index 0000000..2b0da2e --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-appliedintuition-4672836005-risk-and-compliance-lead.md @@ -0,0 +1,68 @@ +--- +title: "Risk and Compliance Lead " +company: "Appliedintuition" +slug: "greenhouse-appliedintuition-4672836005-risk-and-compliance-lead" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/appliedintuition/jobs?content=true" +role_url: "https://boards.greenhouse.io/appliedintuition/jobs/4672836005?gh_jid=4672836005" +apply_url: "https://boards.greenhouse.io/appliedintuition/jobs/4672836005?gh_jid=4672836005" +posted_date: "2026-03-13" +expires_date: "2026-04-12" +location: "Sunnyvale, California, United States" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST 800-53" +languages: + - "Rust" +compensation: "" +summary: "About Applied Intuition Applied Intuition, Inc. is powering the future of physical AI. Founded in 2017 and now valued at $15 billion, the Silicon Valley company is creating the..." +--- + +

About Applied Intuition

+
Applied Intuition, Inc. is powering the future of physical AI. Founded in 2017 and now valued at $15 billion, the Silicon Valley company is creating the digital infrastructure needed to bring intelligence to every moving machine on the planet. Applied Intuition services the automotive, defense, trucking, construction, mining and agriculture industries in three core areas: tools and infrastructure, operating systems, and autonomy. Eighteen of the top 20 global automakers, as well as the United States military and its allies, trust the company’s solutions to deliver physical intelligence. Applied Intuition is headquartered in Sunnyvale, California, with offices in Washington, D.C.; San Diego; Ft. Walton Beach, Florida; Ann Arbor, Michigan; London; Stuttgart; Munich; Stockholm; Bangalore; Seoul; and Tokyo. Learn more at applied.co.
+

We are an in-office company, and our expectation is that employees primarily work from their Applied Intuition office 5 days a week. However, we also recognize the importance of flexibility and trust our employees to manage their schedules responsibly. This may include occasional remote work, starting the day with morning meetings from home before heading to the office, or leaving earlier when needed to accommodate family commitments.

About the role

+

We are looking for a multifaceted Risk and Compliance Lead to lead our security compliance initiatives across the organization. You will be responsible for ensuring adequate security controls to identify and mitigate risk across the organization. Additionally, you will collaborate with legal, engineering, operations and customers, as necessary, to ensure the state of compliance is well communicated.

+

At Applied Intuition, you will:

+ +

We're looking for someone who has:

+ +

Nice to have:

+ +

Compensation at Applied Intuition for eligible roles includes base salary, equity, and benefits. Base salary is a single component of the total compensation package, which may also include equity in the form of options and/or restricted stock units, comprehensive health, dental, vision, life and disability insurance coverage, 401k retirement benefits with employer match, learning and wellness stipends, and paid time off. Note that benefits are subject to change and may vary based on jurisdiction of employment.

+

Applied Intuition pay ranges reflect the minimum and maximum intended target base salary for new hire salaries for the position. The actual base salary offered to a successful candidate will additionally be influenced by a variety of factors including experience, credentials & certifications, educational attainment, skill level requirements, interview performance, and the level and scope of the position.

+

Please reference the job posting’s subtitle for where this position will be located. For pay transparency purposes, the base salary range for this full-time position in the location listed is: $160,000 - $190,000 USD annually. 

Don’t meet every single requirement? If you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.

+

Applied Intuition is an equal opportunity employer and federal contractor or subcontractor. Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a) and 41 CFR 60-741.5(a) and that these laws are incorporated herein by reference. These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity or national origin. These regulations require that covered prime contractors and subcontractors take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disability. The parties also agree that, as applicable, they will abide by the requirements of Executive Order 13496 (29 CFR Part 471, Appendix A to Subpart A), relating to the notice of employee rights under federal labor laws.

diff --git a/jobs/imported/greenhouse/greenhouse-cerebrassystems-7643179003-cybersecurity-grc-manager.md b/jobs/imported/greenhouse/greenhouse-cerebrassystems-7643179003-cybersecurity-grc-manager.md new file mode 100644 index 0000000..c74c436 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-cerebrassystems-7643179003-cybersecurity-grc-manager.md @@ -0,0 +1,89 @@ +--- +title: "Cybersecurity GRC Manager" +company: "Cerebrassystems" +slug: "greenhouse-cerebrassystems-7643179003-cybersecurity-grc-manager" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/cerebrassystems/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/cerebrassystems/jobs/7643179003" +apply_url: "https://job-boards.greenhouse.io/cerebrassystems/jobs/7643179003" +posted_date: "2026-04-02" +expires_date: "2026-05-02" +location: "Sunnyvale CA or Toronto Canada" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST 800-53" + - "HIPAA" + - "GDPR" +languages: [] +compensation: "" +summary: "Cerebras Systems builds the world's largest AI chip, 56 times larger than GPUs. Our novel wafer-scale architecture provides the AI compute power of dozens of GPUs on a single..." +--- + +

Cerebras Systems builds the world's largest AI chip, 56 times larger than GPUs. Our novel wafer-scale architecture provides the AI compute power of dozens of GPUs on a single chip, with the programming simplicity of a single device. This approach allows Cerebras to deliver industry-leading training and inference speeds and empowers machine learning users to effortlessly run large-scale ML applications, without the hassle of managing hundreds of GPUs or TPUs.  

+

Cerebras' current customers include top model labs, global enterprises, and cutting-edge AI-native startups. OpenAI recently announced a multi-year partnership with Cerebras, to deploy 750 megawatts of scale, transforming key workloads with ultra high-speed inference. 

+

Thanks to the groundbreaking wafer-scale architecture, Cerebras Inference offers the fastest Generative AI inference solution in the world, over 10 times faster than GPU-based hyperscale cloud inference services. This order of magnitude increase in speed is transforming the user experience of AI applications, unlocking real-time iteration and increasing intelligence via additional agentic computation.

About The Role

+

The Cybersecurity GRC Manager is accountable for maturing and scaling engineering-driven governance, risk, and compliance programs that support the security, privacy, and regulatory-compliant posture of the organization. The ideal candidate will bring a unique blend of deep technical security acumen and GRC expertise, enabling the creation of GRC workflows that are measurable, automated, and resilient. This is a strategic, cross-functional, and customer-facing role reporting to the Director of Governance, Risk, & Compliance. 

+

A successful candidate will have a comprehensive understanding of cybersecurity and privacy industry frameworks (e.g., NIST, ISO, SOC 2, CCPA, GDPR, HIPAA). They will be responsible for transforming governance, risk, and compliance practices into proactive, testable capabilities using automation, continuous auditing, and AI-driven solutions. 

+

Proficiency with AI tools (LLMs, prompt engineering, generative‑AI workflows) is a core requirement – you’ll use AI to streamline GRC workflow creation and implementation, evidence generation, and security risk mitigation. Experience with designing and implementing autonomous “agentic AI” solutions is preferred. 

+

Responsibilities 

+ +

Skills And Qualifications   

+
Required Experience 
+ +
Technical and Domain Expertise 
+ +
Soft Skills 
+

Why Join Cerebras

+

People who are serious about software make their own hardware. At Cerebras we have built a breakthrough architecture that is unlocking new opportunities for the AI industry. With dozens of model releases and rapid growth, we’ve reached an inflection  point in our business. Members of our team tell us there are five main reasons they joined Cerebras:

+
    +
  1. Build a breakthrough AI platform beyond the constraints of the GPU.
  2. +
  3. Publish and open source their cutting-edge AI research.
  4. +
  5. Work on one of the fastest AI supercomputers in the world.
  6. +
  7. Enjoy job stability with startup vitality.
  8. +
  9. Our simple, non-corporate work culture that respects individual beliefs.
  10. +
+

Read our blog: Five Reasons to Join Cerebras in 2026.

+

Apply today and become part of the forefront of groundbreaking advancements in AI!

+
+

Cerebras Systems is committed to creating an equal and diverse environment and is proud to be an equal opportunity employer. We celebrate different backgrounds, perspectives, and skills. We believe inclusive teams build better products and companies. We try every day to build a work environment that empowers people to do their best work through continuous learning, growth and support of those around them.

+
+

This website or its third-party tools process personal data. For more details, click here to review our CCPA disclosure notice.

diff --git a/jobs/imported/greenhouse/greenhouse-cloudflare-7477769-data-centre-security-compliance-public-sector-specialist.md b/jobs/imported/greenhouse/greenhouse-cloudflare-7477769-data-centre-security-compliance-public-sector-specialist.md new file mode 100644 index 0000000..6dc7d03 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-cloudflare-7477769-data-centre-security-compliance-public-sector-specialist.md @@ -0,0 +1,100 @@ +--- +title: "Data Centre Security Compliance Public Sector Specialist" +company: "Cloudflare" +slug: "greenhouse-cloudflare-7477769-data-centre-security-compliance-public-sector-specialist" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/cloudflare/jobs?content=true" +role_url: "https://boards.greenhouse.io/cloudflare/jobs/7477769?gh_jid=7477769" +apply_url: "https://boards.greenhouse.io/cloudflare/jobs/7477769?gh_jid=7477769" +posted_date: "2026-02-06" +expires_date: "2026-03-08" +location: "Hybrid" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "FedRAMP" + - "SOC 2" + - "NIST 800-53" + - "PCI-DSS" +languages: [] +compensation: "" +summary: "About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other..." +--- + +
About Us
+
+

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. 

+

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

+

Location: Austin, TX

+

About the Role

+

Cloudflare is looking for a Data Center Security Compliance Public Sector Specialist to assist our global Data Center Security Compliance team. This critical role is part of the Infrastructure Operations organization that is responsible for building, scaling, and running Cloudflare’s data center and network infrastructure around the world.  You will play a key role in ensuring the performance, availability, and security of Cloudflare’s network.  In pursuit of the goal to “help build a better Internet,” Cloudflare operates one of the world’s largest and most important cloud networks. Spanning more than 300 cities across the globe, Cloudflare’s network is a key strategic asset and supports all customers and products.

+

The DCSC Public Sector Specialist sits at the intersection of physical infrastructure, strict government regulation (FedRAMP), and operational security.  We are looking for a driven, detailed, and organized professional that can help us improve operational excellence working with our large, strategic partners. In this role, you will have the opportunity to blend strategic vision with tactical implementation to drive outcomes. The ideal candidate will have experience working with the Data Center Security Compliance Programs with a focus on improving operational excellence to drive growth and scalability. This is your opportunity to join a growing, fast-paced, and market-leading cloud security company that is poised to be one of the iconic brands of the decade. If you are interested in building your career with a company that is experiencing explosive growth, while being given the responsibility and challenge to have a real impact on our company’s success, then this is the opportunity for you.

+

Key Responsibilities

+
    +
  1. Public Sector & Compliance Governance
  2. +
+ +

       2. Audit Lifecycle Management

+ +

        3. Identity & Access Management (IAM) Operations

+ +

       4.  Partner Relations & Reporting

+ +

Requirements

+ +



What Makes Cloudflare Special?

+

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

+

Project Galileo: Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.

+

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.

+

1.1.1.1: We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

+

Sound like something you’d like to be a part of? We’d love to hear from you!

+

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

+

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

+

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

diff --git a/jobs/imported/greenhouse/greenhouse-fireblocks-4618281006-technical-grc-expert.md b/jobs/imported/greenhouse/greenhouse-fireblocks-4618281006-technical-grc-expert.md new file mode 100644 index 0000000..1e07515 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-fireblocks-4618281006-technical-grc-expert.md @@ -0,0 +1,68 @@ +--- +title: "Technical GRC Expert" +company: "Fireblocks" +slug: "greenhouse-fireblocks-4618281006-technical-grc-expert" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/fireblocks/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/fireblocks/jobs/4618281006" +apply_url: "https://job-boards.greenhouse.io/fireblocks/jobs/4618281006" +posted_date: "2026-03-31" +expires_date: "2026-04-30" +location: "Tel Aviv-Yafo, Tel Aviv District, Israel" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" +languages: + - "Rust" +compensation: "" +summary: "The world of digital assets is accelerating in speed, magnitude, and complexity, opening the door to new ways for leveraging the blockchain. Fireblocks’ platform and network..." +--- + +

The world of digital assets is accelerating in speed, magnitude, and complexity, opening the door to new ways for leveraging the blockchain. Fireblocks’ platform and network provide the simplest and most secure way for companies to work with digital assets and it trusted by some of the largest financial institutions, banks, globally-recognized brands, and Web3 companies in the world, including BNY Mellon, BNP Paribas, ANZ Bank, Revolut, and thousands more. 

The world of digital assets is accelerating in speed, magnitude, and complexity, opening the door to new ways for leveraging the blockchain. Fireblocks’ platform and network provide the simplest and most secure way for companies to work with digital assets and it trusted by some of the largest financial institutions, banks, globally-recognized brands, and Web3 companies in the world, including BNY Mellon, BNP Paribas, ANZ Bank, Revolut, and thousands more.

+

About the Role

+

We’re looking for a highly skilled Technical GRC Expert with strong technical and hands-on cybersecurity expertise. This role bridges the gap between compliance and technology — ensuring that Fireblocks’ GRC frameworks are not just compliant on paper but effective in practice across infrastructure, SaaS, and cloud environments.

+

As the Cybersecurity GRC Engineer you will oversee the technical execution of GRC initiatives, collaborating with cross-functional teams (Security Engineering, IT, DevOps, Product) to drive resilience, risk reduction, and audit readiness across the organization.

+

Reporting line: GRC Director

+

What you will do

+ +

Qualifications:

+ +

Preferred Qualifications:

+ +

 

Fireblocks' mission is to enable every business to easily and securely access digital assets and cryptocurrencies. In order to do that, we strongly believe our workforce should be as diverse as our clients, and this is why we embrace diversity and inclusion in all its forms. 

+
Please see our candidate privacy policy here.
diff --git a/jobs/imported/greenhouse/greenhouse-fireblocks-4620939006-grc-operations-specialist.md b/jobs/imported/greenhouse/greenhouse-fireblocks-4620939006-grc-operations-specialist.md new file mode 100644 index 0000000..4aa5a63 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-fireblocks-4620939006-grc-operations-specialist.md @@ -0,0 +1,57 @@ +--- +title: "GRC Operations Specialist" +company: "Fireblocks" +slug: "greenhouse-fireblocks-4620939006-grc-operations-specialist" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/fireblocks/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/fireblocks/jobs/4620939006" +apply_url: "https://job-boards.greenhouse.io/fireblocks/jobs/4620939006" +posted_date: "2026-03-31" +expires_date: "2026-04-30" +location: "Tel Aviv-Yafo, Tel Aviv District, Israel" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "GDPR" +languages: + - "Rust" +compensation: "" +summary: "The world of digital assets is accelerating in speed, magnitude, and complexity, opening the door to new ways for leveraging the blockchain. Fireblocks’ platform and network..." +--- + +

The world of digital assets is accelerating in speed, magnitude, and complexity, opening the door to new ways for leveraging the blockchain. Fireblocks’ platform and network provide the simplest and most secure way for companies to work with digital assets and it trusted by some of the largest financial institutions, banks, globally-recognized brands, and Web3 companies in the world, including BNY Mellon, BNP Paribas, ANZ Bank, Revolut, and thousands more. 

We are looking for a passionate and experienced Governance, Risk, and Compliance (GRC) operations specialist to contribute to our company’s efforts in making Fireblocks the most security and trusted provider of digital asset management solutions. This role is critical in driving our day-to-day GRC programs, ensuring they are well maintained, run according to schedule, and align with our business needs.
As the GRC operations specialist, you will oversee the successful implementation and progress of GRC programs, practices, and projects, while collaborating with multiple cross-functional teams within the security department and outside of it. 



What You Will Do
+ +

What You Will Bring:
+ +


Preferred Qualifications:
+

Fireblocks' mission is to enable every business to easily and securely access digital assets and cryptocurrencies. In order to do that, we strongly believe our workforce should be as diverse as our clients, and this is why we embrace diversity and inclusion in all its forms. 

+
Please see our candidate privacy policy here.
diff --git a/jobs/imported/greenhouse/greenhouse-idme-7661659003-grc-engineer.md b/jobs/imported/greenhouse/greenhouse-idme-7661659003-grc-engineer.md new file mode 100644 index 0000000..2ca7508 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-idme-7661659003-grc-engineer.md @@ -0,0 +1,71 @@ +--- +title: "GRC Engineer" +company: "Idme" +slug: "greenhouse-idme-7661659003-grc-engineer" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/idme/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/idme/jobs/7661659003" +apply_url: "https://job-boards.greenhouse.io/idme/jobs/7661659003" +posted_date: "2026-03-16" +expires_date: "2026-04-15" +location: "McLean, Virginia; Mountain View, California, United States" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Security Governance" + - "Audit & Assurance" + - "Cloud Security" +frameworks: + - "FedRAMP" + - "SOC 2" + - "ISO 27001" + - "CCPA" +languages: + - "Python" + - "OSCAL" +compensation: "" +summary: "Company Overview ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity..." +--- + +

Company Overview

+

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.

Role Overview

+

ID.me is seeking a GRC Engineer to design, build, and operate AI agents that automate the compliance lifecycle across FedRAMP, ISO 27001, SOC 2, and Kantara accreditation programs.

+

This role is a technologist that focuses on solving GRC domain problems with automation and AI.. You will write code and build tooling to scale GRC capabilities and reduce the compliance burden.. You will own engineering AI capabilities while also have the skillset to dive into compliance issues as another set up hands..

+

The primary initial challenge is automated evidence collection. You will develop programmatic methods to extract evidence from source systems, feed it into evaluation agents, and enable continuous monitoring to replace traditional annual snapshots with ongoing automated assurance.

+

This role is based out of our Mountain View, CA or McLean, VA offices and requires full-time in-office attendance

+

Core Responsibilities

+ +

Basic Qualifications

+ +

Preferred Qualifications

+ +

#LI-JS1

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

+

ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.

+

Please review our Privacy Policy, including our CCPA policy, at id.me/privacy. If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.

+

ID.me participates in E-Verify.

diff --git a/jobs/imported/greenhouse/greenhouse-idme-7666086003-grc-technical-program-manager.md b/jobs/imported/greenhouse/greenhouse-idme-7666086003-grc-technical-program-manager.md new file mode 100644 index 0000000..fa10f9e --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-idme-7666086003-grc-technical-program-manager.md @@ -0,0 +1,58 @@ +--- +title: "GRC Technical Program Manager" +company: "Idme" +slug: "greenhouse-idme-7666086003-grc-technical-program-manager" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/idme/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/idme/jobs/7666086003" +apply_url: "https://job-boards.greenhouse.io/idme/jobs/7666086003" +posted_date: "2026-03-16" +expires_date: "2026-04-15" +location: "McLean, Virginia; Mountain View, California, United States" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Security Governance" + - "Audit & Assurance" + - "Cloud Security" +frameworks: + - "FedRAMP" + - "SOC 2" + - "ISO 27001" + - "NIST 800-53" + - "CCPA" +languages: [] +compensation: "" +summary: "Company Overview ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity..." +--- + +

Company Overview

+

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.

Role Overview

+

ID.me is seeking a Technical Program Manager – Security Assurance to serve as the operational backbone of our external compliance programs. You will co-own the end-to-end lifecycle of controls, policies, and program-specific documentation for FedRAMP, ISO 27001, and SOC 2, with additional contributions to Kantara accreditation.

+

You will drive cross-functional alignment independently, owning outcomes rather than tasks. A unique requirement of this role is high proficiency with AI tools; our team utilizes purpose-built AI agents for evidence validation, control evaluation, and finding management. Fluency in AI-assisted workflows is essential.

+

This role is based out of our Mountain View, CA or McLean, VA offices and requires full-time in-office attendance.

+

Core Responsibilities

+ +

Preferred Qualifications

+ +

#LI-JS1

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

+

ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.

+

Please review our Privacy Policy, including our CCPA policy, at id.me/privacy. If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.

+

ID.me participates in E-Verify.

diff --git a/jobs/imported/greenhouse/greenhouse-robinhood-7676724-senior-security-grc-analyst.md b/jobs/imported/greenhouse/greenhouse-robinhood-7676724-senior-security-grc-analyst.md new file mode 100644 index 0000000..2b216f4 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-robinhood-7676724-senior-security-grc-analyst.md @@ -0,0 +1,78 @@ +--- +title: "Senior Security GRC Analyst" +company: "Robinhood" +slug: "greenhouse-robinhood-7676724-senior-security-grc-analyst" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/robinhood/jobs?content=true" +role_url: "https://boards.greenhouse.io/robinhood/jobs/7676724?t=gh_src=&gh_jid=7676724" +apply_url: "https://boards.greenhouse.io/robinhood/jobs/7676724?t=gh_src=&gh_jid=7676724" +posted_date: "2026-04-03" +expires_date: "2026-05-03" +location: "Menlo Park, CA" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" +languages: [] +compensation: "" +summary: "Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next..." +--- + +

Join us in building the future of finance.

+

Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading.

About the team + role

+

We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards.

+

The Security GRC (Governance, Risk, and Compliance) team’s mission is to ensure Robinhood meets its “Safety Always” commitments through disciplined risk management, resilient control environments, and effective governance practices. We work closely with Information Security, Technology, Corporate Engineering, Enterprise Risk, and Compliance teams to maintain strong oversight of risk across the organization. Our team supports global regulatory alignment while enabling the business to build compliant, secure products efficiently.

+

As a Senior Security GRC Analyst, you will focus on risk management across Information Security, Technology, and Corporate Engineering. You will conduct risk assessments, evaluate control effectiveness, support regulatory exams and audits, and provide clear reporting on risk posture. You will help strengthen how Robinhood manages risk across multiple regulatory environments through a centralized enterprise approach. This role offers exposure to international expansion efforts and the opportunity to contribute to automation and AI initiatives that improve control testing, reporting, and governance processes. 

+

This role is based in our Menlo Park, CA office, with in-person attendance expected at least 3 days per week.

+

At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams.

+

What you’ll do

+ +

What you bring

+ +

Bonus points:

+ +

What we offer

+

In addition to the base pay range listed below, this role is also eligible for bonus opportunities + equity + benefits.

+

Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business needs, or market demands. The expected base pay range for this role is based on the location where the work will be performed and is aligned to one of 3 compensation zones. For other locations not listed, compensation can be discussed with your recruiter during the interview process.

+

Base Pay Range:

Zone 1 (Menlo Park, CA; New York, NY; Bellevue, WA; Washington, DC)
$166,000$195,000 USD
Zone 2 (Denver, CO; Westlake, TX; Chicago, IL)
$146,000$172,000 USD
Zone 3 (Lake Mary, FL; Clearwater, FL; Gainesville, FL)
$129,000$152,000 USD

Click here to learn more about our Total Rewards, which vary by region and entity.

+

If our mission energizes you and you’re ready to build the future of finance, we look forward to seeing your application.

+

Robinhood provides equal opportunity for all applicants, offers reasonable accommodations upon request, and complies with applicable equal employment and privacy laws. Inclusion is built into how we hire and work—welcoming different backgrounds, perspectives, and experiences so everyone can do their best. Please review the Privacy Policy for your country of application.

diff --git a/jobs/imported/greenhouse/greenhouse-robinhood-7724385-senior-security-grc-analyst.md b/jobs/imported/greenhouse/greenhouse-robinhood-7724385-senior-security-grc-analyst.md new file mode 100644 index 0000000..bb7743f --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-robinhood-7724385-senior-security-grc-analyst.md @@ -0,0 +1,76 @@ +--- +title: "Senior Security GRC Analyst" +company: "Robinhood" +slug: "greenhouse-robinhood-7724385-senior-security-grc-analyst" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/robinhood/jobs?content=true" +role_url: "https://boards.greenhouse.io/robinhood/jobs/7724385?t=gh_src=&gh_jid=7724385" +apply_url: "https://boards.greenhouse.io/robinhood/jobs/7724385?t=gh_src=&gh_jid=7724385" +posted_date: "2026-04-03" +expires_date: "2026-05-03" +location: "Ljubljana, Slovenia" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" +languages: [] +compensation: "" +summary: "Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next..." +--- + +

Join us in building the future of finance.

+

Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading.

About the team + role

+

We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards.

+

The Security GRC (Governance, Risk, and Compliance) team’s mission is to ensure Robinhood meets its “Safety Always” commitments through disciplined risk management, resilient control environments, and effective governance practices. We work closely with Information Security, Technology, Corporate Engineering, Enterprise Risk, and Compliance teams to maintain strong oversight of risk across the organization. Our team supports global regulatory alignment while enabling the business to build compliant, secure products efficiently.

+

As a Senior Security GRC Analyst, you will focus on risk management across Information Security, Technology, and Corporate Engineering. You will conduct risk assessments, evaluate control effectiveness, support regulatory exams and audits, and provide clear reporting on risk posture. You will help strengthen how Robinhood manages risk across multiple regulatory environments through a centralized enterprise approach. This role offers exposure to international expansion efforts and the opportunity to contribute to automation and AI initiatives that improve control testing, reporting, and governance processes. 

+

This role is based in our Ljubljana, Slovenia office, with in-person attendance expected at least 2 days per week. 

At Robinhood, we believe in the power of in-person work to accelerate progress, spark innovation, and strengthen community. Our office experience is intentional, energizing, and designed to fully support high-performing teams.

+

Applications for this role will be accepted through April 20, 2026.

+

What you’ll do

+ +

What you bring

+ +

Bonus points:

+ +

What we offer

+

Click here to learn more about our Total Rewards, which vary by region and entity.

+

If our mission energizes you and you’re ready to build the future of finance, we look forward to seeing your application.

+

Robinhood provides equal opportunity for all applicants, offers reasonable accommodations upon request, and complies with applicable equal employment and privacy laws. Inclusion is built into how we hire and work—welcoming different backgrounds, perspectives, and experiences so everyone can do their best. Please review the Privacy Policy for your country of application.

diff --git a/jobs/imported/greenhouse/greenhouse-sigmacomputing-7690372003-governance-risk-and-compliance-grc-manager.md b/jobs/imported/greenhouse/greenhouse-sigmacomputing-7690372003-governance-risk-and-compliance-grc-manager.md new file mode 100644 index 0000000..c242aa3 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-sigmacomputing-7690372003-governance-risk-and-compliance-grc-manager.md @@ -0,0 +1,130 @@ +--- +title: "Governance, Risk & Compliance (GRC) Manager" +company: "Sigmacomputing" +slug: "greenhouse-sigmacomputing-7690372003-governance-risk-and-compliance-grc-manager" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/sigmacomputing/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/sigmacomputing/jobs/7690372003" +apply_url: "https://job-boards.greenhouse.io/sigmacomputing/jobs/7690372003" +posted_date: "2026-04-06" +expires_date: "2026-05-06" +location: "San francisco, CA" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST CSF" + - "NIST RMF" + - "HIPAA" +languages: + - "Python" + - "SQL" + - "Rust" +compensation: "" +summary: "Governance, Risk & Compliance (GRC) Manager Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our..." +--- + +

 

+

 

Governance, Risk & Compliance (GRC) Manager

+

Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our San Francisco office or upcoming New York office and reports to the General Counsel. You'll have the opportunity to build a strategic, enterprise-wide GRC function that enables business growth while managing organizational risk.

+

As our GRC Manager, you'll partner with Legal, Engineering, Product, Sales, Operations, and leadership to develop a comprehensive GRC framework that protects Sigma's interests, supports our strategic objectives, and builds stakeholder trust. You'll mature our governance structures, implement scalable risk management processes, and ensure compliance with applicable regulatory requirements—all while enabling the business to move quickly and confidently.

+

What You'll Do

+

Governance

+ +

Risk Management

+ +

Compliance

+ +

Business Enablement

+ +

What You Bring

+

Required

+ +

Preferred

+ +

Why Join Sigma

+

This is an opportunity to build a world-class GRC program that doesn't just check boxes but genuinely enables the business to pursue opportunities with confidence. You'll work across the entire organization, have direct access to the General Counsel, and make a tangible impact on how Sigma manages risk and creates value for customers.

+

Additional Job details

+

The base salary range for this position is $190k - $215k annually.

+

Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work at Sigma Computing. This role is eligible for stock options, as well as a comprehensive benefits package.

About us:

+

Sigma is the AI apps and analytics platform connected to the cloud data warehouse. Using Sigma, business and technical teams can build intelligent, production-ready AI apps that accelerate and automate operational workflows. Sigma provides a spreadsheet interface, SQL and Python editors, visual builders, and native AI to help teams turn live data into interactive applications, analysis, reports, and embedded experiences.

+

Sigma announced its $200M in Series D financing in May 2024, to continue transforming BI through its innovations in AI infrastructure, data application development, enterprise-wide collaboration, and business user adoption. Spark Capital and Avenir Growth Capital co-led the Series D funding round, with additional participation from a group of past investors including Snowflake Ventures and Sutter Hill Ventures.The Series D funding, raised at a valuation 60% higher than the company’s Series C round three years ago, promises to further accelerate Sigma’s growth.   

+

Come join us!

+

Benefits For Our Full-Time Employees:

+
    +
  • Equity                                                                                                 
  • +
  • Generous health benefits
  • +
  • Flexible time off policy. Take the time off you need!
  • +
  • Paid bonding time for all new parents
  • +
  • Traditional and Roth 401k
  • +
  • Commuter and FSA benefits
  • +
  • Lunch Program
  • +
  • Dog friendly office
  • +
+

Sigma Computing is an equal opportunity employer. We are committed to building a smart and strong team regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status. We look forward to learning how your experience can enable all of us to grow.

+

Note: We have an in-office work environment in all our offices in SF, NYC, and London.

+

Our Privacy Practices

+

When you submit a job application on this site, Sigma processes your personal data for the purposes of evaluating your candidacy for employment at Sigma and as otherwise needed throughout the recruitment and hiring process. Please review Sigma’s Candidate Privacy Notice for more details. Please note that your personal data may be transferred to a country other than the one in which it was provided (including to USA, the UK, and Canada). 

+

Sigma’s use of AI

+

This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision-making. 

diff --git a/jobs/imported/greenhouse/greenhouse-sigmacomputing-7690373003-governance-risk-and-compliance-grc-manager.md b/jobs/imported/greenhouse/greenhouse-sigmacomputing-7690373003-governance-risk-and-compliance-grc-manager.md new file mode 100644 index 0000000..909aeb8 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-sigmacomputing-7690373003-governance-risk-and-compliance-grc-manager.md @@ -0,0 +1,130 @@ +--- +title: "Governance, Risk & Compliance (GRC) Manager" +company: "Sigmacomputing" +slug: "greenhouse-sigmacomputing-7690373003-governance-risk-and-compliance-grc-manager" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/sigmacomputing/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/sigmacomputing/jobs/7690373003" +apply_url: "https://job-boards.greenhouse.io/sigmacomputing/jobs/7690373003" +posted_date: "2026-04-06" +expires_date: "2026-05-06" +location: "New York City, NY" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST CSF" + - "NIST RMF" + - "HIPAA" +languages: + - "Python" + - "SQL" + - "Rust" +compensation: "" +summary: "Governance, Risk & Compliance (GRC) Manager Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our..." +--- + +

 

+

 

Governance, Risk & Compliance (GRC) Manager

+

Sigma is seeking an experienced GRC Manager to lead and scale our governance, risk, and compliance programs. This role is based in our San Francisco office or upcoming New York office and reports to the General Counsel. You'll have the opportunity to build a strategic, enterprise-wide GRC function that enables business growth while managing organizational risk.

+

As our GRC Manager, you'll partner with Legal, Engineering, Product, Sales, Operations, and leadership to develop a comprehensive GRC framework that protects Sigma's interests, supports our strategic objectives, and builds stakeholder trust. You'll mature our governance structures, implement scalable risk management processes, and ensure compliance with applicable regulatory requirements—all while enabling the business to move quickly and confidently.

+

What You'll Do

+

Governance

+ +

Risk Management

+ +

Compliance

+ +

Business Enablement

+ +

What You Bring

+

Required

+ +

Preferred

+ +

Why Join Sigma

+

This is an opportunity to build a world-class GRC program that doesn't just check boxes but genuinely enables the business to pursue opportunities with confidence. You'll work across the entire organization, have direct access to the General Counsel, and make a tangible impact on how Sigma manages risk and creates value for customers.

+

Additional Job details

+

The base salary range for this position is $190k - $215k annually.

+

Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work at Sigma Computing. This role is eligible for stock options, as well as a comprehensive benefits package.

About us:

+

Sigma is the AI apps and analytics platform connected to the cloud data warehouse. Using Sigma, business and technical teams can build intelligent, production-ready AI apps that accelerate and automate operational workflows. Sigma provides a spreadsheet interface, SQL and Python editors, visual builders, and native AI to help teams turn live data into interactive applications, analysis, reports, and embedded experiences.

+

Sigma announced its $200M in Series D financing in May 2024, to continue transforming BI through its innovations in AI infrastructure, data application development, enterprise-wide collaboration, and business user adoption. Spark Capital and Avenir Growth Capital co-led the Series D funding round, with additional participation from a group of past investors including Snowflake Ventures and Sutter Hill Ventures.The Series D funding, raised at a valuation 60% higher than the company’s Series C round three years ago, promises to further accelerate Sigma’s growth.   

+

Come join us!

+

Benefits For Our Full-Time Employees:

+
    +
  • Equity                                                                                                 
  • +
  • Generous health benefits
  • +
  • Flexible time off policy. Take the time off you need!
  • +
  • Paid bonding time for all new parents
  • +
  • Traditional and Roth 401k
  • +
  • Commuter and FSA benefits
  • +
  • Lunch Program
  • +
  • Dog friendly office
  • +
+

Sigma Computing is an equal opportunity employer. We are committed to building a smart and strong team regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status. We look forward to learning how your experience can enable all of us to grow.

+

Note: We have an in-office work environment in all our offices in SF, NYC, and London.

+

Our Privacy Practices

+

When you submit a job application on this site, Sigma processes your personal data for the purposes of evaluating your candidacy for employment at Sigma and as otherwise needed throughout the recruitment and hiring process. Please review Sigma’s Candidate Privacy Notice for more details. Please note that your personal data may be transferred to a country other than the one in which it was provided (including to USA, the UK, and Canada). 

+

Sigma’s use of AI

+

This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision-making. 

diff --git a/jobs/imported/greenhouse/greenhouse-spycloud-7677705003-grc-engineer.md b/jobs/imported/greenhouse/greenhouse-spycloud-7677705003-grc-engineer.md new file mode 100644 index 0000000..d0fb972 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-spycloud-7677705003-grc-engineer.md @@ -0,0 +1,153 @@ +--- +title: "GRC Engineer" +company: "Spycloud" +slug: "greenhouse-spycloud-7677705003-grc-engineer" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/spycloud/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/spycloud/jobs/7677705003" +apply_url: "https://job-boards.greenhouse.io/spycloud/jobs/7677705003" +posted_date: "2026-04-01" +expires_date: "2026-05-01" +location: "Austin, Texas | Remote" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "SOC 2" + - "ISO 27001" + - "NIST 800-53" + - "CCPA" + - "CMMC" +languages: + - "Python" +compensation: "" +summary: "SpyCloud is on a mission to make the internet a safer place by disrupting the criminal underground. SpyCloud’s solutions thwart cyberattacks and protect more than 4 billion..." +--- + +

SpyCloud is on a mission to make the internet a safer place by disrupting the criminal underground. SpyCloud’s solutions thwart cyberattacks and protect more than 4 billion accounts worldwide. Cybersecurity is an exciting, evolving space, and being at the forefront of the fight to disrupt cybercrime makes SpyCloud a special place to work. If you’re driven to align your career with a fantastic mission, look no further!

The GRC Engineer is a role within SpyCloud’s Governance, Risk, and Compliance (GRC) department, part of the Legal & Compliance organization. This position plays a critical role in strengthening SpyCloud’s compliance posture by driving audit readiness, scaling continuous control testing, and embedding compliance requirements into cloud-native systems and workflows.

+

This role partners closely with Engineering, Security, IT, Product, and Legal teams to ensure compliance requirements are implemented effectively within cloud environments. The GRC Engineer leads complex compliance initiatives while leveraging automation and scripting to improve efficiency, accuracy, and scalability.

+

 

+

What You'll Do:

+ +

 

+

Requirements:

+ +

 

+

Nice to Have:

+ +

SpyCloud is not sponsoring visas at this time.

+

For applicants residing in California, please click here to read SpyCloud's CCPA Notice.

+

For applicants residing in the UK, please click here to read SpyCloud's Employee Privacy Notice.

+

U.S.-Based Benefits + Perks (for Full Time Employees):

+

At SpyCloud, we are committed to working alongside individuals who are equally passionate about preventing cybercrime, regardless of their department or role. Guided by our core values in all business decisions, we prioritize unity in our mission and ensure all SpyCloud employees have the support and benefits they need to stay focused on our goals. In addition to our engaging workspace in South Austin, flexible and remote-friendly work options, and competitive salary package, we offer our employees a comprehensive benefits package that includes:

+
    +
  • 401(k) with Employer Contribution
  • +
  • Health, Vision, and Dental Insurance +
      +
    • Health Savings Account (HSA) available with Employer Contribution
    • +
    +
  • +
  • Employer Paid Life, Short-term, and Long-term Disability Insurance
  • +
  • Generous PTO Plan and 16 paid holidays per year
  • +
+

U.K.-Based Benefits + Perks (for Full Time Employees):

+
    +
  • Retirement Savings Plan with Employer Contribution
  • +
  • Employer Provided Private Health Insurance and Healthcare Cashplan
  • +
  • Employer Paid Life Insurance and Income Replacement
  • +
  • Generous Holiday Plan and 14 paid holidays per year
  • +
+

About SpyCloud:

+

SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions leverage advanced analytics and AI to proactively prevent ransomware and account takeover, detect insider threats, safeguard employee and consumer identities, and accelerate cybercrime investigations. SpyCloud's data from breaches, malware-infected devices, and successful phishes also powers many popular dark web monitoring and identity theft protection offerings. Customers include seven of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 200 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.

To learn more and see insights on your company’s exposed data, visit spycloud.com.

+

Our Mission:

+

Our mission is to make the internet a safer place by disrupting the criminal underground. Together with our customers and partners, we aim to end criminals’ ability to profit from stolen information.

+

Who We Are:

+

SpyCloud is a place for innovative, collaborative, and problem-solvers to thrive. Individually, we’re amazing, but together, we’re unstoppable. We celebrate diversity and various perspectives and aim to create an inclusive and supportive environment for all. We are proud to be an Equal Employment Opportunity and Affirmative Action employer of choice. All aspects of employment decisions will be based on merit, performance, and business needs. We do not discriminate on the basis of any status protected under federal, state, or local law. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. Women, minorities, individuals with disabilities, and protected veterans are encouraged to apply. SpyCloud complies with applicable state and local laws governing nondiscrimination in employment. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

+

SpyCloud expressly prohibits any form of workplace harassment. Improper interference with the ability of SpyCloud's employees to perform their job duties may result in discipline up to and including discharge. SpyCloud shares the right to work and participates in the E-Verify program in all locations.

+

If you need assistance or accommodation due to a disability, you may contact us.

+

Our Culture:

+

Our culture is something really special. We’re all driven to disrupt the cybercriminal economy as we keep customer accounts safe from compromise. We support a truly worthy and serious mission, but we have fun doing it together. If you are driven, inventive, and collaborative, you’ll fit right in.

+

SpyCloud’s Recruitment Policy:

+

We will never ask an applicant for sensitive or personal financial information during the recruitment process. We advise all applicants seeking employment with SpyCloud to review available information on recruitment fraud. Anyone who suspects that they have been contacted by someone falsely representing SpyCloud should email careers@spycloud.com.

+

Compensation Transparency Policy: 

+

At SpyCloud, we believe in transparency and fairness in compensation. We strive to ensure that all employees are fairly compensated for their contributions, and we openly discuss our compensation philosophy and structure. We are committed to providing competitive salaries and benefits packages to attract and retain top talent, and we encourage open dialogue and feedback regarding compensation matters.

+

Learn more and apply: SpyCloud Careers

+
diff --git a/jobs/imported/greenhouse/greenhouse-vercel-5836016004-staff-grc-analyst.md b/jobs/imported/greenhouse/greenhouse-vercel-5836016004-staff-grc-analyst.md new file mode 100644 index 0000000..e8bb7d8 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-vercel-5836016004-staff-grc-analyst.md @@ -0,0 +1,79 @@ +--- +title: "Staff GRC Analyst" +company: "Vercel" +slug: "greenhouse-vercel-5836016004-staff-grc-analyst" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/vercel/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/vercel/jobs/5836016004" +apply_url: "https://job-boards.greenhouse.io/vercel/jobs/5836016004" +posted_date: "2026-04-02" +expires_date: "2026-05-02" +location: "Remote - United States" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "FedRAMP" + - "SOC 2" + - "ISO 27001" + - "NIST 800-53" + - "NIST AI RMF" +languages: + - "Rust" +compensation: "" +summary: "About Vercel: Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK,..." +--- + +

About Vercel:

+

Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web.

+

Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.

About the role:

+

We are looking for a Staff GRC Analyst to join our Governance, Risk, and Compliance (GRC) team. You will have the opportunity to enhance our global compliance posture and further our commitment to managing enterprise risk. Your role will be instrumental in ensuring that our company operates in accordance with security requirements and embodies an environment where it’s everyone’s responsibility. This role will help shape the next iteration of the GRC program and further embed compliance requirements into the business.

+

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

+

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

+

Getting started:

+ +

What you will do:

+ +

About you:

+ +

Bonus if you:

+ +

Benefits:

+ +

The San Francisco, CA base pay range for this role is $180,000.00 - $270,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process. 

+

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.

+

 

+
diff --git a/jobs/imported/greenhouse/greenhouse-zscaler-4940338007-federal-compliance-program-manager-fedramp-il5-and-il6-compliance.md b/jobs/imported/greenhouse/greenhouse-zscaler-4940338007-federal-compliance-program-manager-fedramp-il5-and-il6-compliance.md new file mode 100644 index 0000000..e3b85a6 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-zscaler-4940338007-federal-compliance-program-manager-fedramp-il5-and-il6-compliance.md @@ -0,0 +1,118 @@ +--- +title: "Federal Compliance Program Manager (FedRAMP, IL5 and IL6 Compliance)" +company: "Zscaler" +slug: "greenhouse-zscaler-4940338007-federal-compliance-program-manager-fedramp-il5-and-il6-compliance" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/zscaler/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/zscaler/jobs/4940338007" +apply_url: "https://job-boards.greenhouse.io/zscaler/jobs/4940338007" +posted_date: "2026-03-31" +expires_date: "2026-04-30" +location: "Crystal City, Virginia, USA; Remote - USA" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Audit & Assurance" + - "Cloud Security" +frameworks: + - "FedRAMP" +languages: + - "Rust" +compensation: "" +summary: "About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise , we are..." +--- + +

About Zscaler

+

Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

+

Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.

+

We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.

 

+

We are looking for an experienced Federal Compliance Program Manager to join our Technology Risk & Compliance team. Reporting to the Director of Technology Risk and Compliance, this role allows for remote work provided the individual maintains the readiness to work on-site in a Washington, DC SCIF on a frequent or as-needed basis. You will be responsible for designing, implementing, and maintaining integrated Federal Compliance frameworks for FedRAMP and DoD authorization. Your work will directly influence business strategy by ensuring compliance activities are integrated into broader business processes and initiatives while supporting our mission as a global cloud security leader.

+

What you’ll do (Role Expectations)

+ +

Who You Are (Success Profile)

+ +

What We’re Looking for (Minimum Qualifications)

+ +

What Will Make You Stand Out (Preferred Qualifications)

+ +

#LI-JM1

+

#LI-Remote

+

 

+

 

Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

+

The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.

Base Pay Range
$140,000$200,000 USD

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

+

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

+
+
    +
  • Various health plans
  • +
  • Time off plans for vacation and sick time
  • +
  • Parental leave options
  • +
  • Retirement options
  • +
  • Education reimbursement
  • +
  • In-office perks, and more!
  • +
+

Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.

+
+

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

+

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

+

Pay Transparency

+

Zscaler complies with all applicable federal, state, and local pay transparency rules.

+

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

diff --git a/jobs/imported/greenhouse/greenhouse-zscaler-5020699007-senior-governance-risk-and-compliance-specialist.md b/jobs/imported/greenhouse/greenhouse-zscaler-5020699007-senior-governance-risk-and-compliance-specialist.md new file mode 100644 index 0000000..73d4ad7 --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-zscaler-5020699007-senior-governance-risk-and-compliance-specialist.md @@ -0,0 +1,122 @@ +--- +title: "Senior Governance, Risk & Compliance Specialist" +company: "Zscaler" +slug: "greenhouse-zscaler-5020699007-senior-governance-risk-and-compliance-specialist" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/zscaler/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/zscaler/jobs/5020699007" +apply_url: "https://job-boards.greenhouse.io/zscaler/jobs/5020699007" +posted_date: "2026-04-03" +expires_date: "2026-05-03" +location: "Remote - USA" +work_modes: + - "Remote" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Cloud Security" +frameworks: + - "FedRAMP" +languages: + - "Rust" +compensation: "" +summary: "About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise , we are..." +--- + +

About Zscaler

+

Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

+

Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.

+

We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.

Role

+

We are looking for a Senior Governance, Risk & Compliance Specialist to join our Technology Risk & Compliance team. This is a remote U.S. role with a preference for a hybrid schedule near San Jose, CA, reporting to the Director Technology Risk and Compliance. You will support the implementation, maintenance, and enhancement of integrated GRC frameworks for FedRAMP and DoD authorizations. Your work will directly influence business strategy by ensuring compliance activities are integrated into broader business processes while supporting our mission as a global cloud security leader.

+

What you’ll do (Role Expectations)

+ +

Who You Are (Success Profile)

+ +

What We’re Looking for (Minimum Qualifications)

+ +

What Will Make You Stand Out (Preferred Qualifications)

+ +

#LI-hybrid #LI-BH1

+

 

Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

+

The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.

Base Pay Range
$119,000$170,000 USD

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

+

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

+
+
    +
  • Various health plans
  • +
  • Time off plans for vacation and sick time
  • +
  • Parental leave options
  • +
  • Retirement options
  • +
  • Education reimbursement
  • +
  • In-office perks, and more!
  • +
+

Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.

+
+

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

+

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

+

Pay Transparency

+

Zscaler complies with all applicable federal, state, and local pay transparency rules.

+

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

diff --git a/jobs/imported/greenhouse/greenhouse-zscaler-5043550007-senior-governance-risk-and-compliance-manager-nist-fair.md b/jobs/imported/greenhouse/greenhouse-zscaler-5043550007-senior-governance-risk-and-compliance-manager-nist-fair.md new file mode 100644 index 0000000..404ad6e --- /dev/null +++ b/jobs/imported/greenhouse/greenhouse-zscaler-5043550007-senior-governance-risk-and-compliance-manager-nist-fair.md @@ -0,0 +1,121 @@ +--- +title: "Senior Governance, Risk & Compliance Manager - NIST, FAIR" +company: "Zscaler" +slug: "greenhouse-zscaler-5043550007-senior-governance-risk-and-compliance-manager-nist-fair" +status: "published" +source: "Greenhouse" +sources: + - "Greenhouse" +source_url: "https://boards-api.greenhouse.io/v1/boards/zscaler/jobs?content=true" +role_url: "https://job-boards.greenhouse.io/zscaler/jobs/5043550007" +apply_url: "https://job-boards.greenhouse.io/zscaler/jobs/5043550007" +posted_date: "2026-03-31" +expires_date: "2026-04-30" +location: "San Jose, California, USA" +work_modes: + - "Hybrid / On-site" +job_types: + - "Full-time" +specializations: + - "Compliance Automation" + - "Risk Management" + - "Security Governance" + - "Audit & Assurance" +frameworks: + - "NIST RMF" +languages: + - "Rust" +compensation: "" +summary: "About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise , we are..." +--- + +

About Zscaler

+

Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.

+

Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.

+

We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.

Role

+

We are looking for a Cybersecurity Risk Management Principal to join our team. This is a hybrid role, going in to the San Jose, CA office 3 days a week.  You'll be reporting to the Sr. Director, Enterprise Risk Management within the Security GRC department. You will serve as a technical leader and subject matter expert, conducting sophisticated risk assessments and maintaining the strategic risk register to protect our global infrastructure. You'll bridge the gap between deep technical adversary tactics and high-level business impact to drive remediation across the enterprise.

+

What you’ll do (Role Expectations)

+ +

Who You Are (Success Profile)

+ +

What We’re Looking for (Minimum Qualifications)

+ +

What Will Make You Stand Out (Preferred Qualifications)

+ +

#LI-BH1 #LI-Hybrid

Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

+

The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.

Base Pay Range
$164,500$235,000 USD

At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.

+

Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:

+
+
    +
  • Various health plans
  • +
  • Time off plans for vacation and sick time
  • +
  • Parental leave options
  • +
  • Retirement options
  • +
  • Education reimbursement
  • +
  • In-office perks, and more!
  • +
+

Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.

+
+

By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.

+

Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.

+

Pay Transparency

+

Zscaler complies with all applicable federal, state, and local pay transparency rules.

+

Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.

diff --git a/jobs/jobs.11tydata.js b/jobs/jobs.11tydata.js new file mode 100644 index 0000000..9cf610f --- /dev/null +++ b/jobs/jobs.11tydata.js @@ -0,0 +1,28 @@ +function addDays(dateValue, days) { + const base = dateValue ? new Date(dateValue) : new Date(); + if (Number.isNaN(base.getTime())) return null; + base.setDate(base.getDate() + days); + return base.toISOString().slice(0, 10); +} + +function normalizeList(data, arrayKey, scalarKey) { + if (Array.isArray(data[arrayKey]) && data[arrayKey].length) return data[arrayKey]; + if (data[scalarKey]) return [data[scalarKey]]; + return []; +} + +module.exports = { + layout: "layouts/job.njk", + permalink: (data) => "jobs/" + (data.slug || data.page.fileSlug) + "/index.html", + tags: "jobs-content", + eleventyComputed: { + slug: (data) => data.slug || data.page.fileSlug, + status: (data) => data.status || "published", + sources: (data) => normalizeList(data, "sources", "source"), + work_modes: (data) => normalizeList(data, "work_modes", "work_mode"), + job_types: (data) => normalizeList(data, "job_types", "job_type"), + expires_date: (data) => data.expires_date || addDays(data.posted_date, 30), + description: (data) => data.description || ((data.title && data.company) ? (data.title + " at " + data.company) : "Open governance, risk, and compliance role"), + eleventyExcludeFromCollections: (data) => String(data.page.fileSlug || "").startsWith("_") + } +}; diff --git a/package.json b/package.json index 3862afb..acc89ff 100644 --- a/package.json +++ b/package.json @@ -4,7 +4,8 @@ "private": true, "scripts": { "build": "npx @11ty/eleventy", - "serve": "npx @11ty/eleventy --serve" + "serve": "npx @11ty/eleventy --serve", + "import:jobs": "node scripts/import-jobs.js" }, "devDependencies": { "@11ty/eleventy": "^3.0.0" diff --git a/scripts/import-jobs.js b/scripts/import-jobs.js new file mode 100644 index 0000000..66d5d10 --- /dev/null +++ b/scripts/import-jobs.js @@ -0,0 +1,608 @@ +const fs = require("fs/promises"); +const path = require("path"); +const { greenhouseBoards: catalogGreenhouseBoards, ashbyBoards: catalogAshbyBoards } = require("./job-board-sources"); + +const ROOT = process.cwd(); +const IMPORT_ROOT = path.join(ROOT, "jobs", "imported"); +const USER_AGENT = "GRC Engineer Directory Job Importer/1.0 (+https://directory.grcengclub.com)"; + +const FRAMEWORK_RULES = [ + ["FedRAMP", ["fedramp", "govramp", "state ramp", "state-ramp"]], + ["SOC 2", ["soc 2", "soc2"]], + ["ISO 27001", ["iso 27001", "iso27001"]], + ["ISO 42001", ["iso 42001", "iso42001"]], + ["NIST 800-53", ["nist 800-53", "800-53"]], + ["NIST 800-171", ["nist 800-171", "800-171"]], + ["NIST CSF", ["nist csf", "cybersecurity framework"]], + ["NIST RMF", ["nist rmf", "risk management framework"]], + ["NIST AI RMF", ["ai rmf", "nist ai rmf"]], + ["PCI-DSS", ["pci", "pci-dss", "payment card industry"]], + ["HIPAA", ["hipaa"]], + ["GDPR", ["gdpr"]], + ["CCPA", ["ccpa"]], + ["CMMC", ["cmmc"]], + ["CJIS", ["cjis"]], + ["HITRUST", ["hitrust"]] +]; + +const LANGUAGE_RULES = [ + ["Python", ["python"]], + ["Terraform", ["terraform"]], + ["OPA/Rego", ["rego", "open policy agent", "opa"]], + ["SQL", ["sql"]], + ["Bash", ["bash", "shell scripting"]], + ["JavaScript", ["javascript", "node.js", "nodejs"]], + ["Go", ["golang", " go ", "go/"]], + ["PowerShell", ["powershell"]], + ["OSCAL", ["oscal"]], + ["Rust", ["rust"]] +]; + +const SPECIALIZATION_RULES = [ + ["Compliance Automation", ["grc", "compliance", "controls", "control testing", "continuous controls", "audit readiness", "security compliance"]], + ["Risk Management", ["risk", "risk register", "risk assessment", "third-party risk"]], + ["Security Governance", ["policy", "governance", "governance risk", "governance, risk", "control framework"]], + ["Audit & Assurance", ["audit", "assurance", "sox", "evidence collection"]], + ["Cloud Security", ["aws", "azure", "gcp", "cloud security", "kubernetes", "container security"]], + ["Identity & Access Management", ["iam", "identity", "access management", "okta", "entra", "sso", "privileged access"]], + ["Privacy", ["privacy", "data protection", "gdpr", "ccpa"]], + ["Security Architecture", ["security architecture", "secure design", "threat modeling"]], + ["Security Operations", ["soc", "security operations", "siem", "detection", "monitoring"]], + ["Incident Response", ["incident response", "forensics", "breach"]], + ["Third-Party Risk", ["vendor risk", "third-party risk", "supplier risk"]], + ["Vulnerability Management", ["vulnerability", "patch management", "exposure management"]], + ["AI Governance", ["ai governance", "model governance", "responsible ai"]], + ["Cloud Governance", ["cloud governance", "cloud controls"]], + ["DevSecOps", ["devsecops", "cicd security", "pipeline security"]] +]; + +function envFlag(name, defaultValue) { + const value = process.env[name]; + if (value === undefined) return defaultValue; + return !["0", "false", "no"].includes(String(value).toLowerCase()); +} + +function splitEnv(name) { + return String(process.env[name] || "") + .split(",") + .map((item) => item.trim()) + .filter(Boolean); +} + +function configuredBoards(envName, catalogBoards) { + return [...new Set([...(catalogBoards || []), ...splitEnv(envName)])]; +} + +function toIsoDate(value) { + if (!value) return new Date().toISOString().slice(0, 10); + const date = new Date(value); + if (Number.isNaN(date.getTime())) return new Date().toISOString().slice(0, 10); + return date.toISOString().slice(0, 10); +} + +function addDays(value, days) { + const date = new Date(value); + if (Number.isNaN(date.getTime())) return null; + date.setDate(date.getDate() + days); + return date.toISOString().slice(0, 10); +} + +function slugify(value) { + return String(value || "") + .toLowerCase() + .replace(/&/g, " and ") + .replace(/[^a-z0-9]+/g, "-") + .replace(/(^-|-$)/g, ""); +} + +function titleCaseFromSlug(value) { + return String(value || "") + .split("-") + .filter(Boolean) + .map((part) => part.charAt(0).toUpperCase() + part.slice(1)) + .join(" "); +} + +function stripHtml(value) { + return String(value || "") + .replace(/</g, "<") + .replace(/>/g, ">") + .replace(/<[^>]+>/g, " ") + .replace(/ /g, " ") + .replace(/&/g, "&") + .replace(/"/g, "\"") + .replace(/'/g, "'") + .replace(/\s+/g, " ") + .trim(); +} + +function htmlToMarkdown(value) { + const headingLevels = { + h1: "#", + h2: "##", + h3: "###", + h4: "####", + h5: "#####", + h6: "######" + }; + + let html = String(value || ""); + if (!html.trim()) return ""; + + html = html + .replace(//gi, "") + .replace(//gi, "") + .replace(/]*href=["']([^"']+)["'][^>]*>([\s\S]*?)<\/a>/gi, (_, href, text) => { + const label = stripHtml(text); + if (!label) return href; + return `${label} (${href})`; + }); + + Object.entries(headingLevels).forEach(([tag, marker]) => { + const regex = new RegExp(`<${tag}[^>]*>([\\s\\S]*?)<\\/${tag}>`, "gi"); + html = html.replace(regex, (_, text) => `\n\n${marker} ${stripHtml(text)}\n\n`); + }); + + html = html + .replace(/]*>([\s\S]*?)<\/li>/gi, (_, text) => `\n- ${stripHtml(text)}`) + .replace(/]*>([\s\S]*?)<\/blockquote>/gi, (_, text) => `\n> ${stripHtml(text)}\n`) + .replace(/<(p|div|section|article|header|footer|aside|table|tr|tbody|thead)[^>]*>([\s\S]*?)<\/\1>/gi, (_, _tag, text) => { + const cleaned = stripHtml(text); + return cleaned ? `\n\n${cleaned}\n\n` : "\n"; + }) + .replace(/<\/?(ul|ol)[^>]*>/gi, "\n") + .replace(/<(br|hr)\s*\/?>/gi, "\n") + .replace(/<[^>]+>/g, "") + .replace(/</g, "<") + .replace(/>/g, ">") + .replace(/ /g, " ") + .replace(/&/g, "&") + .replace(/"/g, "\"") + .replace(/'/g, "'") + .replace(/\r/g, "") + .replace(/[ \t]+\n/g, "\n") + .replace(/\n{3,}/g, "\n\n"); + + return html + .split("\n") + .map((line) => line.trim()) + .join("\n") + .replace(/\n{3,}/g, "\n\n") + .trim(); +} + +function normalizeJobType(value) { + const normalized = String(value || "").trim(); + if (!normalized) return "Full-time"; + if (normalized === "FullTime") return "Full-time"; + if (normalized === "PartTime") return "Part-time"; + return normalized; +} + +function excerpt(value, maxLength) { + const cleaned = stripHtml(value); + if (cleaned.length <= maxLength) return cleaned; + return cleaned.slice(0, maxLength).replace(/\s+\S*$/, "") + "..."; +} + +function collectMatches(text, rules, maxItems) { + const normalized = " " + String(text || "").toLowerCase() + " "; + const matches = rules + .filter((rule) => rule[1].some((keyword) => normalized.includes(String(keyword).toLowerCase()))) + .map((rule) => rule[0]); + + return [...new Set(matches)].slice(0, maxItems || matches.length); +} + +function includesAny(text, terms) { + const normalized = String(text || "").toLowerCase(); + return terms.some((term) => normalized.includes(term)); +} + +function countMatches(text, terms) { + const normalized = String(text || "").toLowerCase(); + return terms.reduce((count, term) => count + (normalized.includes(term) ? 1 : 0), 0); +} + +function looksRelevant(title, text) { + const titleText = String(title || "").toLowerCase(); + const fullText = [titleText, String(text || "").toLowerCase()].join(" "); + const blockedTitleTerms = [ + "marketing", "social media", "payroll", "clinical", + "biology", "nutrition", "civil", "commercial", + "account executive", "customer success", "deal desk", "sales", + "content", "psychologist", "scientist", "intern", + "recruiter", "talent", "legal counsel" + ]; + const directRolelessSignals = [ + "grc", + "governance, risk & compliance", + "governance, risk and compliance", + "governance risk & compliance", + "governance risk and compliance", + "governance risk compliance", + "security compliance", + "security & compliance", + "security and compliance", + "security risk & compliance", + "security risk and compliance", + "risk & compliance automation", + "risk and compliance automation", + "compliance automation", + "fedramp", + "rmf", + "it governance", + "governance and trust", + "trust and compliance", + "it grc", + "grc platform", + "grc platforms", + "grc system", + "grc systems", + "grc automation" + ]; + const directTechnicalSignals = [ + "compliance engineer", + "compliance analyst", + "compliance specialist", + "compliance lead", + "compliance developer", + "security compliance engineer", + "security compliance analyst", + "security compliance specialist", + "security compliance lead", + "security and compliance engineer", + "security and compliance analyst", + "security and compliance lead", + "security & compliance engineer", + "security & compliance analyst", + "security & compliance lead", + "risk and compliance engineer", + "risk and compliance analyst", + "risk & compliance engineer", + "risk & compliance analyst", + "technical risk and compliance engineer", + "cloud security grc", + "fedramp cloud security", + "rmf cybersecurity analyst", + "controls monitoring analyst", + "it governance analyst" + ]; + const adjacentSecuritySignals = [ + "security risk", + "cyber risk", + "security governance", + "security trust", + "governance and trust", + "programs & controls", + "programs and controls", + "security controls", + "controls monitoring", + "controls assurance", + "technology risk", + "it risk", + "privacy compliance", + "privacy engineering", + "fedramp program" + ]; + const grcContextTerms = [ + "grc", "governance", "risk", "compliance", "control", + "controls", "control monitoring", "continuous controls", + "control validation", "evidence", "evidence collection", + "evidence automation", "audit", "audit readiness", + "risk assessment", "risk register", "risk management", + "policy", "policies", "procedures", "security assurance", + "customer security assurance", "third-party risk", + "vendor risk", "least privilege", "identity governance", + "iam", "access review", "privacy", "fedramp", "soc 2", + "soc2", "iso 27001", "iso27001", "hitrust", "tisax", + "nist", "rmf", "800-53", "800-171", "cmmc", "pci", + "hipaa", "gdpr", "ccpa", "continuous compliance", + "automation", "control automation", "compliance as code", + "drata", "vanta", "viso trust", "oscal", "python", + "powershell", "snowflake", "databricks", "api" + ]; + const frameworkTerms = [ + "fedramp", "soc 2", "soc2", "iso 27001", "iso27001", + "hitrust", "nist", "rmf", "800-53", "800-171", + "cmmc", "pci", "hipaa", "gdpr", "ccpa", "tisax" + ]; + const automationTerms = [ + "automation", "continuous compliance", "control automation", + "evidence automation", "compliance as code", "api", + "python", "powershell", "snowflake", "databricks", "oscal" + ]; + + if (includesAny(titleText, blockedTitleTerms)) return false; + + const hasDirectRolelessSignal = includesAny(titleText, directRolelessSignals); + const hasDirectTechnicalSignal = includesAny(titleText, directTechnicalSignals); + const hasAdjacentSecuritySignal = includesAny(titleText, adjacentSecuritySignals); + + if (!hasDirectRolelessSignal && !hasDirectTechnicalSignal && !hasAdjacentSecuritySignal) return false; + + const grcSignals = countMatches(fullText, grcContextTerms); + const frameworkSignals = countMatches(fullText, frameworkTerms); + const automationSignals = countMatches(fullText, automationTerms); + + if (hasDirectTechnicalSignal) { + return grcSignals >= 2; + } + + if (hasAdjacentSecuritySignal) { + return grcSignals >= 4 || (grcSignals >= 3 && (frameworkSignals >= 1 || automationSignals >= 1)); + } + + return grcSignals >= 3 || (grcSignals >= 2 && (frameworkSignals >= 1 || automationSignals >= 1)); +} + +function yamlString(value) { + return JSON.stringify(String(value || "")); +} + +function yamlList(key, values) { + if (!values || !values.length) return key + ": []"; + return key + ":\n" + values.map((value) => " - " + yamlString(value)).join("\n"); +} + +function formatCompensation(min, max, currency) { + if (!min && !max) return ""; + const fmt = new Intl.NumberFormat("en-US", { + style: "currency", + currency: currency || "USD", + maximumFractionDigits: 0 + }); + + const minValue = min ? fmt.format(min) : ""; + const maxValue = max ? fmt.format(max) : ""; + if (minValue && maxValue) return minValue + " - " + maxValue; + return minValue || maxValue; +} + +function serializeJob(job) { + const frontmatter = [ + "---", + "title: " + yamlString(job.title), + "company: " + yamlString(job.company), + "slug: " + yamlString(job.slug), + "status: " + yamlString(job.status || "published"), + "source: " + yamlString(job.source), + yamlList("sources", job.sources || [job.source]), + "source_url: " + yamlString(job.source_url), + "role_url: " + yamlString(job.role_url || job.apply_url), + "apply_url: " + yamlString(job.apply_url), + "posted_date: " + yamlString(job.posted_date), + "expires_date: " + yamlString(job.expires_date), + "location: " + yamlString(job.location), + yamlList("work_modes", job.work_modes), + yamlList("job_types", job.job_types), + yamlList("specializations", job.specializations), + yamlList("frameworks", job.frameworks), + yamlList("languages", job.languages), + "compensation: " + yamlString(job.compensation || ""), + "summary: " + yamlString(job.summary || ""), + "---", + "", + job.body || "No description was provided by the upstream source." + ]; + + return frontmatter.join("\n") + "\n"; +} + +async function fetchJson(url, headers) { + const response = await fetch(url, { + headers: Object.assign({ "User-Agent": USER_AGENT }, headers || {}) + }); + + if (!response.ok) { + throw new Error("Request failed: " + response.status + " " + response.statusText + " for " + url); + } + + return response.json(); +} + +async function resetDir(dir) { + await fs.rm(dir, { recursive: true, force: true }); + await fs.mkdir(dir, { recursive: true }); +} + +async function writeImportedJobs(sourceKey, jobs) { + const dir = path.join(IMPORT_ROOT, sourceKey); + await resetDir(dir); + + for (const job of jobs) { + const filePath = path.join(dir, job.slug + ".md"); + await fs.writeFile(filePath, serializeJob(job), "utf8"); + } +} + +function buildNormalizedJob(job) { + const content = [job.title, job.company, job.location, job.summary, job.body].join(" "); + const specializations = job.specializations && job.specializations.length + ? job.specializations + : collectMatches(content, SPECIALIZATION_RULES, 4); + const frameworks = collectMatches(content, FRAMEWORK_RULES, 5); + const languages = collectMatches(content, LANGUAGE_RULES, 5); + + return Object.assign({}, job, { + specializations, + frameworks, + languages, + summary: excerpt(job.summary || job.body || "", 180) + }); +} + +function normalizeRemoteOkJob(job) { + const body = htmlToMarkdown(job.description || ""); + const summary = stripHtml(job.description || ""); + const text = [job.position, job.company, body, (job.tags || []).join(" ")].join(" "); + if (!looksRelevant(job.position, text)) return null; + + const postedDate = toIsoDate(job.date || job.date_iso || Date.now()); + const slug = slugify(["remoteok", job.company, job.position].join("-")); + if (!slug) return null; + + return buildNormalizedJob({ + title: job.position, + company: job.company || "Unknown company", + slug, + source: "Remote OK", + sources: ["Remote OK"], + source_url: "https://remoteok.com/json", + role_url: job.url || job.apply_url || "", + apply_url: job.apply_url || job.url || "", + posted_date: postedDate, + expires_date: addDays(postedDate, 30), + location: job.location || "Remote", + work_modes: ["Remote"], + job_types: [normalizeJobType(job.employment_type)], + compensation: formatCompensation(job.salary_min, job.salary_max, "USD"), + summary, + body: body + }); +} + +function normalizeGreenhouseJob(boardToken, job) { + const body = htmlToMarkdown(job.content || ""); + const summary = stripHtml(job.content || ""); + const text = [job.title, summary, job.location && job.location.name, boardToken].join(" "); + if (!looksRelevant(job.title, text)) return null; + + const postedDate = toIsoDate(job.updated_at); + const slug = slugify(["greenhouse", boardToken, job.id, job.title].join("-")); + + return buildNormalizedJob({ + title: job.title, + company: titleCaseFromSlug(boardToken), + slug, + source: "Greenhouse", + sources: ["Greenhouse"], + source_url: "https://boards-api.greenhouse.io/v1/boards/" + boardToken + "/jobs?content=true", + role_url: job.absolute_url || "", + apply_url: job.absolute_url || "", + posted_date: postedDate, + expires_date: addDays(postedDate, 30), + location: (job.location && job.location.name) || "Remote", + work_modes: /remote/i.test(summary + " " + ((job.location && job.location.name) || "")) ? ["Remote"] : ["Hybrid / On-site"], + job_types: ["Full-time"], + summary, + body: body + }); +} + +function normalizeAshbyJob(boardName, job) { + const rawDescription = job.descriptionHtml || job.descriptionPlain || ""; + const description = htmlToMarkdown(rawDescription); + const summary = stripHtml(rawDescription); + const text = [job.title, job.jobTitle, job.location, summary, boardName].join(" "); + if (!looksRelevant(job.title || job.jobTitle, text)) return null; + + const postedDate = toIsoDate(job.publishedDate || job.updatedAt || Date.now()); + const slug = slugify(["ashby", boardName, job.id || job.jobId || job.title].join("-")); + const location = job.location || (job.primaryLocation && job.primaryLocation.label) || "Remote"; + + return buildNormalizedJob({ + title: job.title || job.jobTitle, + company: titleCaseFromSlug(boardName), + slug, + source: "Ashby", + sources: ["Ashby"], + source_url: "https://api.ashbyhq.com/posting-api/job-board/" + boardName + "?includeCompensation=true", + role_url: job.jobUrl || job.absoluteUrl || "", + apply_url: job.applyUrl || job.jobUrl || job.absoluteUrl || "", + posted_date: postedDate, + expires_date: addDays(postedDate, 30), + location, + work_modes: /remote/i.test([location, summary].join(" ")) ? ["Remote"] : ["Hybrid / On-site"], + job_types: [normalizeJobType(job.employmentType)], + compensation: job.compensation && job.compensation.summary ? job.compensation.summary : "", + summary, + body: description + }); +} + +async function importRemoteOk() { + const payload = await fetchJson("https://remoteok.com/json"); + const entries = Array.isArray(payload) ? payload.slice(1) : []; + return entries.map(normalizeRemoteOkJob).filter(Boolean); +} + +async function importGreenhouse() { + const boards = configuredBoards("GREENHOUSE_BOARDS", catalogGreenhouseBoards); + if (!boards.length) return []; + + const imported = []; + for (const board of boards) { + try { + const payload = await fetchJson("https://boards-api.greenhouse.io/v1/boards/" + encodeURIComponent(board) + "/jobs?content=true"); + const jobs = Array.isArray(payload.jobs) ? payload.jobs : []; + jobs.forEach((job) => { + const normalized = normalizeGreenhouseJob(board, job); + if (normalized) imported.push(normalized); + }); + } catch (error) { + console.warn("[greenhouse] skipped board " + board + ": " + (error.message || error)); + } + } + + return imported; +} + +async function importAshby() { + const boards = configuredBoards("ASHBY_JOB_BOARDS", catalogAshbyBoards); + if (!boards.length) return []; + + const imported = []; + for (const board of boards) { + try { + const payload = await fetchJson("https://api.ashbyhq.com/posting-api/job-board/" + encodeURIComponent(board) + "?includeCompensation=true"); + const jobs = Array.isArray(payload.jobs) ? payload.jobs : []; + jobs.forEach((job) => { + const normalized = normalizeAshbyJob(board, job); + if (normalized) imported.push(normalized); + }); + } catch (error) { + console.warn("[ashby] skipped board " + board + ": " + (error.message || error)); + } + } + + return imported; +} + +async function runSource(key, enabled, importer) { + if (!enabled) { + console.log("[" + key + "] skipped"); + return 0; + } + + const jobs = await importer(); + await writeImportedJobs(key, jobs); + console.log("[" + key + "] wrote " + jobs.length + " jobs"); + return jobs.length; +} + +async function main() { + await fs.mkdir(IMPORT_ROOT, { recursive: true }); + + let total = 0; + total += await runSource("remoteok", envFlag("REMOTEOK_ENABLED", true), importRemoteOk); + total += await runSource("greenhouse", configuredBoards("GREENHOUSE_BOARDS", catalogGreenhouseBoards).length > 0, importGreenhouse); + total += await runSource("ashby", configuredBoards("ASHBY_JOB_BOARDS", catalogAshbyBoards).length > 0, importAshby); + + if (total === 0) { + console.log("No jobs matched the current GRC filters."); + console.log("Tip: curated Greenhouse and Ashby boards are checked into the repo. Add GREENHOUSE_BOARDS or ASHBY_JOB_BOARDS to extend the board list."); + } +} + +if (require.main === module) { + main().catch((error) => { + console.error(error.stack || error.message); + process.exitCode = 1; + }); +} + +module.exports = { + htmlToMarkdown, + looksRelevant +}; diff --git a/scripts/job-board-sources.js b/scripts/job-board-sources.js new file mode 100644 index 0000000..913c33d --- /dev/null +++ b/scripts/job-board-sources.js @@ -0,0 +1,39 @@ +module.exports = { + greenhouseBoards: [ + "andurilindustries", + "appliedintuition", + "anthropic", + "cerebrassystems", + "cloudflare", + "discord", + "everlaw", + "fireblocks", + "idme", + "ionq", + "robinhood", + "sigmacomputing", + "spycloud", + "vercel", + "xai", + "zscaler" + ], + ashbyBoards: [ + "1password", + "atlan", + "confluent", + "Crusoe", + "elevenlabs", + "Flock Safety", + "hims-and-hers", + "junipersquare", + "lambda", + "Method", + "monarchmoney", + "Notion", + "ramp", + "replit", + "serverobotics", + "socure", + "writer" + ] +}; diff --git a/site/_includes/layouts/base.njk b/site/_includes/layouts/base.njk index a6b6833..e7ac45e 100644 --- a/site/_includes/layouts/base.njk +++ b/site/_includes/layouts/base.njk @@ -24,6 +24,8 @@