Mercor Logo

Mercor

Security GRC Lead

Posted 4 Days Ago
Be an Early Applicant
In-Office
San Francisco, CA, USA
350K-425K Annually
Senior level
In-Office
San Francisco, CA, USA
350K-425K Annually
Senior level
Own Mercor’s security GRC and compliance programs, including continuous SOC 2 monitoring, ISO 27001 certification, customer audits, third-party risk, policy lifecycle management, controls-as-code, data-handling procedures, and enterprise security questionnaires. Build the company’s first GRC function, automate evidence collection and questionnaire responses, manage auditor and customer relationships, and support frameworks such as HIPAA, FedRAMP, and EU AI Act conformity.
The summary above was generated by AI
About Mercor

Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.

 

Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.

Role Description

You'll be the first GRC hire at a company that processes some of the most sensitive data on earth: training data, evals, and human-feedback pipelines for the frontier AI labs, plus payments and KYC for 300K+ experts. Compliance posture is a sales gate for every $50M+ contract Mercor signs. The audit calendar never ends.

This is not an audit-theater role. You'll own the operating cadence of a continuously-audited company: continuous SOC 2 monitoring in Vanta, the active ISO 27001 buildout, an annual KPMG-style customer audit every quarter, and a sub-48-hour questionnaire SLA. You'll write controls in code where it makes sense, push back on tools that fight you, and own the artifacts that close enterprise deals.

We use AI heavily in our own GRC work - Vanta has an MCP, our questionnaire bank is queryable, evidence is automated where the framework allows it. You should be comfortable using LLMs to draft, review, and respond at speed. If you've ever copy-pasted the same answer into 14 vendor questionnaires by hand, you'll appreciate not having to.

We're in-person five days a week at our SF headquarters, with first Fridays remote.

What You'll Build
  • The Mercor compliance operating cadence: SOC 2 Type 2 (continuous), ISO 27001 (standing up now), and the next two frameworks customers ask for (HIPAA, FedRAMP Moderate, EU AI Act conformity - your call on sequencing)

  • A customer-audit machine that responds to Anthropic, Google, Meta, NVIDIA, and OpenAI without burning out the security team - questionnaire SLA under 48h, KPMG-grade evidence packs on demand

  • The third-party risk program - formal intake, recurring review cadence, evidence requirements - tied into procurement so vendors can't be onboarded around it

  • Policy lifecycle owned end-to-end: version, attestation, exception handling, review cycle - not a SharePoint graveyard

  • Controls-as-code where it makes sense: Vanta integrations, Wiz policy packs, Panther rules tied to SOC 2 CC categories, automated evidence collection

  • Data-handling procedures: the customer-data-deletion gap, DSAR workflow, KMS scheduled destruction, offboarding handlers

  • The internal trust narrative: customer trust pages, security one-pagers, executive-ready disclosure templates when something goes sideways

What We're Looking For
  • 7+ years in security GRC, compliance engineering, or audit, with at least 2 years owning a SOC 2 Type 2 program end-to-end at a company under audit by enterprise customers

  • You've shipped at least one ISO 27001 certification from kickoff to issued certificate, including Stage 1 and Stage 2 with a real registrar

  • Fluent in Vanta (or Drata, Secureframe, Sprinto) at the integration and admin level, not just the reviewer UI - you've configured connectors, written custom tests, debugged broken evidence

  • You've sat on the company side of at least one enterprise customer audit conducted by a Big 4 firm (KPMG, EY, Deloitte, PwC) on behalf of a frontier customer

  • You translate cloud-security language to auditor language and back without losing precision - you can read a Wiz finding, a Panther rule, an IAM policy, and say what control it maps to

  • You write controls as code or query evidence with SQL when the platform falls short - Python, SQL, or shell, whatever it takes

  • You know the difference between "we don't have a control for that" and "we have a compensating control" and you don't fabricate the second one

  • Direct experience with the customer-trust surface: SIG, CAIQ, custom enterprise questionnaires, on-site auditor sessions, disclosure letters under legal review

Bonus Points
  • Built or operated a GRC program inside an AI lab, ML platform, or company serving frontier labs as customers

  • Familiar with AI-specific frameworks: NIST AI RMF, EU AI Act conformity, ISO 42001

  • Experience with FedRAMP Moderate, HIPAA, PCI DSS, or SOC 2 + HITRUST dual scope

  • You've automated questionnaire response with an LLM and know where it works and where it fails

  • Prior experience standing up a third-party risk program from zero - vendor intake, recurring review, contract teeth

  • Written a public trust page that customers actually trust

Why Mercor
  • Build the function, don't inherit it. This is the first GRC seat. You set the operating cadence, pick the tools (we're already on Vanta), define the rituals.

  • Compliance work that closes deals. Every audit you nail is a contract that signs. You'll see the revenue downstream of your work in the same week.

  • AI-native GRC. You'll use frontier models daily - evidence review, questionnaire drafting, control mapping - and have engineering support to build whatever tooling the off-the-shelf platforms won't.

  • Direct line to the auditor and the customer. No layers between you and the people who matter - the audit firm, the customer security team, our outside counsel. You own the relationship end-to-end.

  • A real security org behind you. TachTech (cloud), Latacora (MDR), Mandiant (IR), HackerOne (BB) are already running. You're not building the security program from scratch - you're putting the governance and assurance layer on top of one that already ships.

Benefits
  • Bi-annual performance bonus structure

  • Generous equity grant vested over 4 years

  • Up to $15k Relocation bonus

  • $10K housing bonus (if you live within 0.5 miles of our office)

  • $1.5K monthly stipend for meals

  • Free Equinox membership

  • $200 monthly laundry reimbursement

  • $200 monthly personal wellness reimbursement

  • Health, Dental, Vision insurance

HQ

Mercor San Francisco, California, USA Office

San Francisco, California , United States, 94105

Similar Jobs

4 Hours Ago
In-Office
16-29 Hourly
Junior
16-29 Hourly
Junior
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Manages member and provider referral intake, admission and discharge information, service requests, and incoming and outgoing cases. Coordinates with hospitals, clinics, facilities, and clinical teams while performing non-clinical triage, outreach, submissions, notifications, and issue resolution. The role operates in a high-volume customer service environment and requires knowledge of medical coding, insurance-related care coordination, and referral processing.
Top Skills: Cpt CodesIcd-10Icd-9MS Office
5 Hours Ago
In-Office
16-29 Hourly
Junior
16-29 Hourly
Junior
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Provide front-desk patient support including check-in/check-out, demographic and insurance verification, scheduling, cash handling, medical records management, answering phones, and processing authorizations and releases.
Top Skills: EmrExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft Word
5 Hours Ago
In-Office
92K-164K Annually
Senior level
92K-164K Annually
Senior level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Leads complex claims extract implementations, client onboarding, vendor integrations, data interfaces, and enterprise programs. Coordinates cross-functional teams, dependencies, releases, risks, budgets, and governance while overseeing QA, testing, ServiceNow requests, metrics, and SLA compliance. Drives process improvement, automation, customer experience, and NPS outcomes. Acts as a subject matter expert and mentor for project managers and analysts, supporting Agile teams and staffing decisions.
Top Skills: AgileJIRASafeScrumServicenow

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account