Hiring.Camp

Governance, Risk and Compliance Lead

Thinking Machines Lab

·

Today

Salary
$225k – $350k
Location
San Francisco · San Francisco, California, United States
Department
Technical
Seniority
Lead
Visa
Sponsored
Source
Greenhouse

Description

Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence. We're building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals. 

We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything.

About the Role

We're looking for a GRC Lead who personally drives our certifications (SOC 2, ISO 27001, FedRAMP and others as we grow) from scoping through audit close, and runs our compliance processes day to day. You'll collect the evidence, write the control documentation, and sit across from the auditor yourself.

You'll work closely with security, legal, safety, and engineering to answer compliance and risk questions directly, using your own technical understanding of how our systems work. Day to day, you'll be managing audits, controls, and risk assessments. Alongside that, you'll be building the roadmap for what this function needs to look like in a year.

What You'll Do

  • Own our certification roadmap end to end: scope each certification, build the control set, collect and organize evidence, and represent TML directly to auditors through to close.
  • Manage recurring compliance processes on a set cadence: control testing, audit prep and response, risk register maintenance, and policy attestations.
  • Answer compliance and risk questions from engineering, security, and product teams directly, by building enough technical fluency across our infrastructure, model deployment, and data handling to do so without escalating every question.
  • Track regulatory and framework requirements relevant to an AI company (GDPR, EU AI Act, and similar) and translate them into specific, actionable controls.
  • Identify gaps in current compliance coverage as the company adds new products, infrastructure, or jurisdictions, and propose what needs to change before it becomes a blocker.
  • Build and maintain the tooling and documentation that make the next audit cycle faster than the last one.
  • Plan a multi-quarter roadmap for the GRC function itself, while continuing to personally run the certifications and audits already on the books.

Skills and Qualifications

Minimum qualifications:

  • 7+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.
  • Experience leading a SOC 2, ISO 27001, FedRAMP or comparable certification from scoping through audit close.
  • Hands-on experience collecting audit evidence and writing control documentation.
  • Experience managing a recurring compliance process, such as control testing, risk register maintenance, or policy attestations.
  • Experience learning new technical domains quickly and translating them for non-technical stakeholders.

Preferred qualifications:

We encourage you to apply even if you don't meet all preferred qualifications.

  • Experience translating complex compliance requirements into scalable automation using AI agents and custom built tooling.
  • Experience growing a GRC function's capability (new certifications, tooling, or processes) as a company scaled.

You'll Thrive in This Role if

  • You want to run the certification yourself, end to end.
  • You're the one in the room with the auditor, walking through evidence.
  • You can hold this week's deadlines and next year's roadmap at the same time.

Logistics

  • Location: This role is based in San Francisco, California.
  • Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $225,000 - $350,000.
  • Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.
  • Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.
  • As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Thinking Machines Lab will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the California Fair Chance Act, the San Francisco Fair Chance Ordinance, and any other applicable state or local fair chance ordinance or law.

Skills

PyTorchCybersecuritySOCComplianceSOC 2GDPRISO 27001

Similar Jobs

30

Governance, Risk, and Compliance and Data Privacy Office Director

Dow is · Midland (MI, USA), United States of America +1 · Onsite

Today

Principal IT Governance and Risk Consultant

Pseg · Bethpage, New York, US · Remote, Hybrid, Onsite

Today

Governance, Risk, and Compliance Manager

Tensorwave · Las Vegas, Nevada · Onsite

Yesterday

Program Architect - Governance, Risk, and Compliance

Onebrief · United States | Remote · Remote

Yesterday

Senior Governance, Risk and Compliance Specialist

Leidos · 7169 Moore St Canberra ACT Australia +1

Yesterday

Business Manager - Governance and Risk

Scottish Government Recruitment · Edinburgh, United Kingdom, GB · Hybrid

2 days ago

Governance, Risk and Compliance Director

THC Site · Saudi Arabia

2 days ago

Information Security Specialist - Technology Asset Governance and Risk Management

Td · 310/320 Front Street West Corporate, Toronto, Ontario, Canada · Hybrid

2 days ago

AVP - Governance, Risk and Controls

M&G · Mumbai Central Avenue, India

3 days ago

Head of Governance, Risk and Compliance - Cyber Security

Thisisglobal · Holborn - London, United Kingdom

3 days ago

Governance, Risk and Compliance Engineer

MillerKnoll is · Bengaluru - IBU Cunningham Road, India

3 days ago

Governance, Risk, and Compliance Manager - Healthcare

Weaver · HOUSTON, TX +1

1 week ago

Governance, Risk, and Compliance Experienced Associate or Senior Associate

Weaver · HOUSTON, TX +1

1 week ago

Sr. Lead Information Security Governance, Risk, and Compliance (GRC) Analyst

Usap · Remote, US · Remote

1 week ago

Junior Lecturer: Risk and Governance

Milpark Education Pty Ltd

1 week ago

Governance, Risk, and Compliance Specialist, AWS Security

Amazon

1 week ago

Specialist II, Governance, Risk and Compliance (TCF)

Cnx · PHL Quezon City - EXXA Tower, 8th Floor, Philippines

1 week ago

Information Security Specialist - Technology Asset Governance and Risk Management (US)

Td · Mt Laurel - Technology Center - 17000 Horizon Way, Mount Laurel, New Jersey, United States of America +2 · Hybrid

1 week ago

Governance and Risk Lead

Penbrothers · Mandaluyong City, Metro Manila · Remote

1 week ago

Governance, Risk and Compliance Analyst

Babel Street · Reston, Virginia, United States; Somerville, Massachusetts, United States +1 · Hybrid

2 weeks ago

Group Company Secretary & Head of Global Risk, Governance and Compliance

TWE Global · 3000 Melbourne, VIC, Australia

2 weeks ago

Customer Success Manager - GRC (Governance, Risk, and Compliance)

Workiva · Remote - IL, United States of America +2 · Remote

2 weeks ago

Governance, Risk, and Compliance Intern (Fall 2026)

Notion · San Francisco, California · Hybrid

2 weeks ago

Principal Security Analyst - Governance, Risk, and Compliance

Blackbaud · Remote - Anywhere - USA, United States of America · Remote

2 weeks ago

Cybersecurity Governance, Risk, and Compliance - Regulatory Associate

Pfizer · GRC - Thessaloniki, Chortiatis, Greece

2 weeks ago

Cybersecurity Governance, Risk, and Compliance - Regulatory Associate

Pfizer · GRC - Thessaloniki, Chortiatis, Greece

2 weeks ago

Governance Risk and Compliance Analyst

Polsinelli · Kansas City, MO +26

2 weeks ago

Senior Associate, Cyber Governance and Risk

Pfizer · GRC - Thessaloniki, Chortiatis, Greece

2 weeks ago

Senior Associate, Cyber Governance and Risk

Pfizer · GRC - Thessaloniki, Chortiatis, Greece

2 weeks ago

SAP GRC (Governance, Risk, and Compliance) Consultant

Accenturefederalservices · Washington, DC +1 · Onsite

3 weeks ago