Skip to content

Open nowPosted 5 hours ago

GRC Engineer

aegis-ai28 open roles

Where
United States
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGRC Engineeraegis-ai · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on aegis-ai's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. aegis-ai postings stay open a median of 5 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 5 hours ago

aegis-ai median: 5 days open

The posting

OVERVIEW

We're a team of ex-Google engineers who built some of the largest defensive platforms on the planet — Safe Browsing and reCAPTCHA. Now, we're striking out on our own to tackle an even bigger challenge: stopping the new wave of adversarial AI attacks already hitting organizations today.

We're going after a $5B+ market, ripe for disruption. Traditional detection methods are too slow to keep up. Adversaries are using AI to craft customized, high-evasion attacks — and old-school rules-based systems don't stand a chance.

THE ROLE

We're looking for a GRC Engineer to advance AegisAI's security program. We sell to security teams, which means our buyers grade us the way we grade our own vendors: audits, frameworks, questionnaires, policies, proof. Your job is to own that proof: keep it current, airtight, and fast to produce.

The title says engineer on purpose. We run compliance the way we run infrastructure: controls mapped once across frameworks, evidence collected automatically through APIs instead of screenshots, and an audit that falls out of how we operate every day rather than a yearly scramble. You'll own our SOC 2 end to end, keep our policies current as we scale, advance the business continuity and incident response muscle behind our customer commitments, and answer the security reviews that gate our biggest deals.

You'll work directly with the head of security, our engineers, and the customers who ask the hard questions. What you build here becomes the reason deals close faster.

WHAT YOU'LL DO

Own Compliance end to end: Keep the program audit-ready year round and run the auditor relationship.

Pave the road to what's next: Keep us ahead of what our customers ask for, so when the business needs its next certification or framework, we're already on track.

Run our risk management program: Maintain the risk register, keep treatments moving, and ensure we have an accurate picture of risk at all times.

Own the policy suite: Keep our policies, standards and procedures current as we grow, aligned with how we operate, and clear to the customers who read them.

Own BC/DR and incident response: Maintain and exercise our plans and playbooks, own the customer notification commitments behind them, and make sure everyone knows their part before it's needed.

Answer the questions that gate deals: Own customer security questionnaires and TPRM reviews end to end, grow the answer library so answers stay accurate and consistent, and keep turnaround fast.

Run vendor and subprocessor risk: Review the vendors we depend on, keep DPAs and the subprocessor list current, scale third-party risk management as our vendor footprint grows, and handle customer data requests end to end.

Map controls across frameworks: Maintain our control set against the industry frameworks we build on, audit against it, and make one piece of evidence count everywhere it can.

Expand evidence automation: Pull more proof straight from systems through APIs and scripts, so audits and questionnaires draw from live data.

WHO YOU ARE

- 4+ years in GRC, security compliance or audit at a SaaS company, and you've run a SOC 2 Type II end to end at least once.

- You've answered enterprise security questionnaires and you write clearly enough that your answers close the thread.

- Technical enough to read an architecture diagram, question an engineer's answer, and tell the difference between a control that exists and one that's written down.

- You script. Python or similar, comfortable with APIs, and allergic to collecting the same evidence twice.

- Working knowledge of the major privacy regimes and what they mean for a data processor.

- Organized, self-directed, and honest about what you don't know yet.

Bonus points:

- You've implemented ISO 27001, or carried a company through certification.

- Compliance automation platform experience, especially custom tests and the API side of one.

- AI governance exposure: ISO 42001, NIST AI RMF, or building an AI policy from scratch.

- You've built or tested BC/DR for a production SaaS.

- Privacy certifications (CIPP or similar).

- You've worked at a security vendor and know the standard your answers get held to.

OUR CULTURE

- Flat, flexible, and fast.

- You'll own your decisions.

- You'll have clear KPIs for success — but how you get there is up to you.

- If you want compliance work that protects our customers and wins deals instead of filling binders, and want to work with a team that moves at the speed of the real world, join us.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against aegis-ai's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on aegis-ai's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    aegis-ai's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.