Summary
Aegis AI Security is a security company founded by former Google engineers focused on defending organizations against adversarial AI attacks. The GRC Engineer will advance the company’s security program by owning SOC 2 compliance, risk management, policies, business continuity, incident response, vendor risk, customer security reviews, control mapping, and evidence automation.
Responsibilities
- Own Compliance end to end: Keep the program audit-ready year round and run the auditor relationship
- Pave the road to what's next: Keep us ahead of what our customers ask for, so when the business needs its next certification or framework, we're already on track
- Run our risk management program: Maintain the risk register, keep treatments moving, and ensure we have an accurate picture of risk at all times
- Own the policy suite: Keep our policies, standards and procedures current as we grow, aligned with how we operate, and clear to the customers who read them
- Own BC/DR and incident response: Maintain and exercise our plans and playbooks, own the customer notification commitments behind them, and make sure everyone knows their part before it's needed
- Answer the questions that gate deals: Own customer security questionnaires and TPRM reviews end to end, grow the answer library so answers stay accurate and consistent, and keep turnaround fast
- Run vendor and subprocessor risk: Review the vendors we depend on, keep DPAs and the subprocessor list current, scale third-party risk management as our vendor footprint grows, and handle customer data requests end to end
- Map controls across frameworks: Maintain our control set against the industry frameworks we build on, audit against it, and make one piece of evidence count everywhere it can
- Expand evidence automation: Pull more proof straight from systems through APIs and scripts, so audits and questionnaires draw from live data
Skills
- 4+ years in GRC, security compliance or audit at a SaaS company, and you've run a SOC 2 Type II end to end at least once
- You've answered enterprise security questionnaires and you write clearly enough that your answers close the thread
- Technical enough to read an architecture diagram, question an engineer's answer, and tell the difference between a control that exists and one that's written down
- You script. Python or similar, comfortable with APIs, and allergic to collecting the same evidence twice
- Working knowledge of the major privacy regimes and what they mean for a data processor
- Organized, self-directed, and honest about what you don't know yet
- You've implemented ISO 27001, or carried a company through certification
- Compliance automation platform experience, especially custom tests and the API side of one
- AI governance exposure: ISO 42001, NIST AI RMF, or building an AI policy from scratch
- You've built or tested BC/DR for a production SaaS
- Privacy certifications (CIPP or similar)
- You've worked at a security vendor and know the standard your answers get held to
Qualifications
Must Haves
- 4+ years in GRC, security compliance or audit at a SaaS company, and you've run a SOC 2 Type II end to end at least once
- You've answered enterprise security questionnaires and you write clearly enough that your answers close the thread
- Technical enough to read an architecture diagram, question an engineer's answer, and tell the difference between a control that exists and one that's written down
- You script. Python or similar, comfortable with APIs, and allergic to collecting the same evidence twice
- Working knowledge of the major privacy regimes and what they mean for a data processor
- Organized, self-directed, and honest about what you don't know yet
Nice to Haves
- You've implemented ISO 27001, or carried a company through certification
- Compliance automation platform experience, especially custom tests and the API side of one
- AI governance exposure: ISO 42001, NIST AI RMF, or building an AI policy from scratch
- You've built or tested BC/DR for a production SaaS
- Privacy certifications (CIPP or similar)
- You've worked at a security vendor and know the standard your answers get held to
Benefits
- Remote work
- Flexible work arrangement