Skip to content

Open nowPosted 7 hours ago

GRC and Security Compliance Lead

Deepgram92 open roles

Pay
$165,000 – $223,300 a year
Where
USA - Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGRC and Security Compliance LeadDeepgram · USA - Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Deepgram's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Deepgram postings stay open a median of 43 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 7 hours ago

Deepgram median: 43 days open

The posting

COMPANY OVERVIEW

Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are ‘Powered by Deepgram’, including Twilio, Cloudflare, Sierra, Decagon, Vapi, Daily, Cresta, Granola, and Jack in the Box. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software, with unmatched accuracy, low latency, and cost efficiency. Backed by a recent Series C led by leading global investors and strategic partners, Deepgram has processed over 50,000 years of audio and transcribed more than 1 trillion words. There is no organization in the world that understands voice better than Deepgram.

COMPANY OPERATING RHYTHM

At Deepgram, we expect an AI-first mindset—AI use and comfort aren’t optional, they’re core to how we operate, innovate, and measure performance.

Every team member who works at Deepgram is expected to actively use and experiment with advanced AI tools, and even build your own into your everyday work. We measure how effectively AI is applied to deliver results, and consistent, creative use of the latest AI capabilities is key to success here. Candidates should be comfortable adopting new models and modes quickly, integrating AI into their workflows, and continuously pushing the boundaries of what these technologies can do.

Additionally, we move at the pace of AI. Change is rapid, and you can expect your day-to-day work to evolve just as quickly. This may not be the right role if you’re not excited to experiment, adapt, think on your feet, and learn constantly, or if you’re seeking something highly prescriptive with a traditional 9-to-5.

THE OPPORTUNITY

Deepgram is looking for a GRC and Security Compliance Lead to own the written and evidentiary backbone of our security and privacy program — the documents and evidence that auditors, enterprise customers, and our own engineers rely on to know what we actually do.

We hold SOC 2, ISO 27001, and PCI DSS obligations, we answer a steady stream of enterprise security questionnaires, and we publish public commitments about how we handle data and how our models are built. Today that work is spread across too few people. You will own it: the evidence, the policies, the public posture documents, and the system that keeps all three consistent with each other.

Context matters here, because the claims you will be writing are unusually specific. Most of our infrastructure is bare metal in colocation datacenters — containerized on Docker, managed with Ansible, and deployed through GitHub Actions — with AWS used for overflow capacity and a small set of services. That means our control environment spans physical and colocation controls, on-premise hosts, and cloud, not a single cloud provider's shared-responsibility model. Deepgram also processes audio — often some of the most sensitive data our customers hold — across several deployment models: hosted with model-improvement opted in, hosted with model-improvement opted out (effectively zero data retention), single-tenant Deepgram Dedicated deployments with regional data residency, and fully self-hosted deployments running in the customer's own environment. Getting a public statement right means understanding which of those a given claim applies to.

Writing is the core skill in this role, and we mean writing that survives a skeptical reader — an auditor, a Fortune 500 security reviewer, an engineer who knows the system better than you do. Where a claim needs technical verification, you define what has to be proven and partner with Security Engineering to prove it; you are not expected to do that engineering work yourself.

This role reports to the Director of Information Security and works closely with Security Engineering, Legal, Research, and Solutions/Sales Engineering.

We are open on level. Strong analyst-level and senior candidates are both in scope, and we will calibrate title, scope, and compensation to demonstrated experience.

RESPONSIBILITIES

- Own audit evidence end to end for SOC 2, ISO 27001, and PCI DSS — what evidence is required, who produces it, where it lives, and whether it would actually satisfy a reviewer. Be the auditor's primary point of contact through fieldwork.

- Own control mapping across frameworks. Build and maintain the crosswalk so one control and one piece of evidence satisfies SOC 2, ISO 27001, PCI DSS, and customer questionnaires — rather than running the same work three times.

- Own the colocation and infrastructure vendor side of compliance: datacenter provider SOC reports and attestations, physical security and carve-out language, and how shared responsibility actually divides between us and each provider.

- Own security questionnaires and the security sections of RFPs. Maintain the answer library, keep it current as the product changes, and know which answers to fight for and which to concede.

- Author and own the lifecycle of our internal policies and standards: drafting, review and approval cycles, annual review, exceptions and carve-outs, and retiring what no longer reflects reality.

- Own our public-facing posture documents — Trust Center content, the AI Safety statement, Model Cards (with Research), the Privacy Policy (with Legal), and the deployment-model and self-hosted documentation customers rely on during review.

- Own the documentation system itself: where documents live, how they are versioned and reviewed, and how a customer-facing claim traces back to an internal source of truth. Nothing we say publicly should be unattributable.

- Maintain accurate data flow maps and records of processing across hosted, dedicated, and self-hosted deployments — and own the process that keeps them accurate as the product changes.

- Run compliance and security awareness training and enablement, including clear guidance to Sales Engineering on what they may and may not commit to on a customer call.

- Partner with Security Engineering so evidence is generated once, by automation — from Ansible, GitHub, and our logging and monitoring stack — and reused, and flag where a manual evidence pull should become an automated one.

- Support the privacy program: contribute to DPIAs and transfer impact assessments, subprocessor and vendor privacy reviews, and DSAR intake, in partnership with the Privacy Operations Lead.

SKILLS NEEDED

- Substantial experience in GRC, security compliance, or technical compliance documentation — enough that you have carried at least one audit cycle end to end from the evidence side and owned the outcome.

- Exceptional writer. This is the central requirement, not a soft skill. You can turn a messy technical reality into a document a skeptical auditor, customer, or engineer will accept.

- Hands-on involvement in at least one formal audit — SOC 2, ISO 27001, or PCI DSS — as the person producing and defending evidence, not only as a reader of the report.

- Experience mapping controls across more than one framework, and a real opinion about how to avoid duplicated compliance work.

- Technically fluent and unintimidated: you can read an architecture diagram, follow a data flow through datacenter and cloud infrastructure, understand what a log line or a retention setting actually implies, and ask the question that exposes a gap — without needing someone to translate for you.

- Startup-friendly judgment. You know which questionnaire answers are worth fighting for and which to concede, and when a policy needs a carve-out rather than a mandate. Controls and policies that ignore how the company actually ships get routed around, and we would rather you name the trade-off than write the ideal version.

- Working knowledge of GDPR, CCPA/CPRA, and where AI regulation is heading — enough to write public posture documents that hold up.

- Bias toward building systems and templates rather than becoming the person every request has to route through.

- Comfortable with ambiguity and with making a defensible call when the standard is unsettled.

NICE TO HAVE

- Certification such as CISA, ISO 27001 Lead Implementer/Auditor, CIPM, CIPT, or CIPP/E.

- Audit experience in an on-premise, colocation, or hybrid environment — not only cloud-native.

- Experience with compliance automation platforms (Vanta, Drata, or similar) and trust center tooling, including where they fall short outside a pure-cloud environment.

- Familiarity with AI governance frameworks — NIST AI RMF, ISO/IEC 42001, EU AI Act — and with model documentation practice.

- Experience with ML/AI data pipelines and training-data governance.

- Compliance work in a hybrid model — multi-tenant SaaS alongside self-hosted or on-premise deployments.

- Comfort with SQL, light scripting, or AI and agentic tooling to pull and assemble your own evidence rather than filing a ticket for it.

- Exposure to HIPAA or FedRAMP.

Notice: We're aware of individuals impersonating Deepgram recruiters. All legitimate Deepgram recruiting communication comes from an @deepgram.com http://deepgram.com email address. If you've received a message claiming to be Deepgram, please forward it to [email protected].

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Deepgram's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Deepgram's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Deepgram's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.