Baseten Logo

Baseten

GRC Manager

Reposted 6 Days Ago
Remote or Hybrid
Hiring Remotely in San Francisco, CA, USA
150K-250K Annually
Senior level
Remote or Hybrid
Hiring Remotely in San Francisco, CA, USA
150K-250K Annually
Senior level
The GRC Manager will establish and lead security governance and compliance programs, manage audits, develop policies, and work cross-functionally to ensure compliance with standards such as SOC 2 and ISO 27001.
The summary above was generated by AI

ABOUT BASETEN

Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F, led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products.

THE ROLE
We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance.

In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow.

RESPONSIBILITIES

  • Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.

  • Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.

  • Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations.

  • Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.

  • Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.

  • Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.

  • Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.

  • Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.

  • Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.

REQUIREMENTS

  • 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.

  • Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.

  • Proven track record managing compliance audits and certification programs end-to-end.

  • Experience with access management concepts, third-party risk

  • Experience working cross-functionally with technical and non-technical stakeholders to implement compliance and security controls.

  • Excellent organizational, documentation, and communication skills with attention to detail.

  • Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.

NICE TO HAVE

  • Experience with cloud security compliance in AWS or GCP environments.

  • Hands-on experience using GRC tools (e.g., Vanta, Drata, Secureframe, Anecdotes).

  • Understanding of AI/ML security considerations, data privacy, and model governance.

  • Previous experience building and scaling compliance programs in an early-stage or rapidly growing startup.

  • Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer).

BENEFITS

  • Competitive compensation, including meaningful equity.

  • 100% coverage of medical, dental, and vision insurance for employee and dependents

  • Flexible PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!)

  • Paid parental leave

  • Fertility and family-building stipend through Carrot

  • Company-facilitated 401(k)

  • Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.

Apply now to embark on a rewarding journey in shaping the future of AI! If you are a motivated individual with a passion for machine learning and a desire to be part of a collaborative and forward-thinking team, we would love to hear from you.

At Baseten, we are committed to fostering a diverse and inclusive workplace. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status.

We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example, the requirements of the San Francisco Fair Chance Ordinance, where applicable).

HQ

Baseten San Francisco, California, USA Office

San Francisco, CA, United States

Similar Jobs

2 Days Ago
In-Office or Remote
6 Locations
Senior level
Senior level
Information Technology • Software
Own and mature Neumo’s Governance, Risk, and Compliance program, including SOC 1, SOC 2, and PCI DSS audits, risk registers, data governance, control automation, vendor assessments, and exception processes. Manage 1–2 direct reports, coordinate remediation, leverage AI/LLM tools, participate in incident management, and communicate compliance posture and risk trends to executives and the board.
Top Skills: Ai/Llm ToolingArcherDrataIso 27001JIRANist CsfOnetrustPci DssServicenow GrcSoc 1Soc 2Vanta
7 Days Ago
Remote
United States
Senior level
Senior level
Software
Owns day-to-day relationships with GRC and compliance automation partners, managing referrals, deal registration, partner-sourced pipeline, dashboards, and forecasting. Coordinates Sales, Marketing, BDR, Audit, and Product teams; resolves escalations; improves partner and customer experiences; and builds scalable enablement, communication, and referral processes. The role requires strong analytics, cross-functional influence, relationship management, and familiarity with GRC, compliance, audit, or security frameworks.
Top Skills: DrataHipaaHitrustIso 27001PciSoc 2SoxVanta
14 Days Ago
Remote
United States
Senior level
Senior level
Artificial Intelligence • Information Technology • Software
Lead client-facing GRC engagements end-to-end, manage escalations, advise on compliance strategy, coach a pod of 3–5 analysts, architect technical security controls across SOC 2/ISO 27001/HIPAA/PCI DSS, execute multi-cloud certification projects, and use automation platforms (Drata, Vanta, Secureframe).
Top Skills: AWSAzureCmmcDrataFedrampGCPGdprHipaaIso 27001Nist 800-171Nist 800-53Nist CsfPci DssSecureframeSoc 2Vanta

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account