Skip to content

Open nowPosted 7 hours ago

Compliance Manager

Reflection AI46 open roles

Where
New York, NY
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCompliance ManagerReflection AI · New York, NY
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Reflection AI's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Reflection AI postings stay open a median of 42 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted 7 hours ago

Reflection AI median: 42 days open

The posting

OUR MISSION

Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all.

ROLE OVERVIEW

Reflection AI's Compliance and AI Governance function spans six pillars: AI Governance, Data Governance, Trade Compliance, Privacy Operationalization, Government Contracting Compliance, and Corporate Compliance. The team builds the policies, controls, and operating rhythms that let the company move fast while staying defensible with regulators, customers, and partners.

We're looking for a senior generalist who can flex across multiple pillars rather than own a single lane. You'll take ambiguous, cross-cutting problems (a new regulation, a customer due-diligence request, an internal process gap) and turn them into working programs: policies, SOPs, training, and monitoring. This role is a force multiplier for the pillar leads and a direct partner to the Head of Compliance and AI Governance.

WHAT YOU'LL DO

- Stand up and maintain compliance processes and SOPs across pillars (e.g., insider risk, background checks, external reporting process, vendor/compliance tooling)

- Support our security framework compliance posture (SOC 2, ISO 27001, NIST 800-53/800-171, CMMC) by maintaining evidence, coordinating with control owners, and prepping for audits and assessments

- Own or support day-to-day TPRM operations: vendor security questionnaires, risk tiering, onboarding reviews, and tracking remediation of vendor findings

- Respond to inbound customer and partner security/compliance questionnaires, pulling in subject-matter owners as needed

- Partner with pillar leads (AI Governance, Data Governance, Trade Compliance, Privacy, Gov Contracting) to fill gaps, cover surge work, and keep cross-pillar initiatives moving

- Draft and maintain policies, process documentation, and training materials for internal and external audiences

- Track regulatory developments (AI, data, privacy) and translate them into concrete internal workstreams

- Prepare materials for leadership and cross-functional updates (steering committees, exec reporting, knowledge-share sessions)

- Identify process gaps and build the scaffolding (trackers, templates, intake forms) to close them

WHAT WE'RE LOOKING FOR

- 4-7 years in compliance, risk, legal operations, or a related GRC function, ideally in tech or a regulated industry

- Direct experience with at least one security framework (SOC 2, ISO 27001, NIST) and with TPRM/vendor risk processes (questionnaires, risk tiering, onboarding review)

- Demonstrated ability to own a problem end to end with minimal supervision, across unfamiliar subject matter

- Strong written communication; comfortable turning ambiguous asks into clear policies and SOPs

- Experience working cross-functionally with Legal, Security, Privacy, People, and Engineering stakeholders

- Comfortable context-switching across multiple active workstreams

- Exposure to AI governance, data privacy (GDPR/CCPA), export controls (ITAR/EAR), or federal contracting compliance (CMMC, FAR/DFARS)

- Experience with GRC or compliance tooling (e.g., Vanta or similar platforms)

- Experience responding to customer-facing security questionnaires or supporting enterprise sales/procurement cycles

- Prior experience in a high-growth or startup environment where the compliance function is still being built

WHAT WE OFFER:

We believe that to make intelligence open and accessible to all, you need to start at the foundation. Joining Reflection means building from the ground up as part of a talent-dense team. You will help define our future as a company, and help define the future of open foundational models.

We want you to do the most impactful work of your career with the confidence that you and the people you care about most are supported.

- Top-tier compensation: Salary and equity structured to recognize and retain our talent globally.

- Stock options: Everyone who joins and contributes to Reflection's success gets to share in the upside through stock options.

- Health & wellness: Comprehensive medical, dental, vision, and life, with an annual wellness allowance.

- Meals: Lunch and dinner are provided in the office daily.

- Life & family: 22 weeks paid parental leave for all new birthing and non-birthing parents, including adoptive and surrogate journeys.

- Vacation days: Unlimited paid time off in the U.S. and 30 days in the U.K.

- Sponsorship support: We sponsor visas to help exceptional talent join our team and support long-term immigration pathways where applicable.

- Team building: We have regular off-sites, happy hours, and team celebrations.

Export Control Notice: This position may require access to technology or source code subject to the U.S. Export Administration Regulations. Any offer of employment for this role may be conditioned on the Company's ability to provide the candidate with access to such technology or source code in compliance with applicable U.S. export control laws, which may require the Company to seek government authorization.

Candidate and Employee Privacy Notice: We collect and process personal data about applicants for the purposes described in our Candidate and Employee Privacy Notice https://cdn.sanity.io/files/irpbdun9/production/ee08c38bf22bd45a3f3a81f6a7abddb9210726b7.pdf

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Reflection AI's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Reflection AI's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Reflection AI's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.