GRC Manager

Baseten

$100K — $140K *
US-AnywhereRemote in San Francisco, CA
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in GRC, Security Compliance, or Information Security roles, especially in SaaS/cloud environments.
  • Strong grasp of security standards like SOC 2, ISO 27001, NIST, and GDPR.
  • Proven experience managing compliance audits and certification processes.
  • Familiarity with risk management methodologies and governance frameworks.
  • Cross-functional project experience involving both technical and non-technical stakeholders.
  • Excellent organizational and communication skills with keen attention to detail.
  • Ability to work effectively in a fast-paced startup environment.

Responsibilities

  • Design and maintain security governance frameworks and policies aligned with industry best practices.
  • Build and oversee the risk assessment program to identify and mitigate security risks.
  • Lead compliance efforts for SOC 2, ISO 27001, GDPR, and other regulations.
  • Coordinate audits and certification processes, managing evidence collection and remediation plans.
  • Manage assessments of third-party vendors for compliance with security standards.
  • Collaborate with cross-functional teams to integrate compliance into daily operations.
  • Support customer due diligence and security questionnaire processes.

Benefits

  • Competitive compensation with equity options.
  • 100% medical, dental, and vision insurance coverage for employees and dependents.
  • Generous paid time off, including a Winter Break (off from Christmas Eve to New Year's Day).
  • Paid parental leave policy.
  • Company-supported 401(k) plan.
  • Networking and learning opportunities with various machine learning startups.
Full Job Description
THE ROLE
We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten's security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance.

In this role, you'll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You'll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten's commitment to security and compliance as we grow.

RESPONSIBILITIES
  • Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten's risk posture and industry best practices.
  • Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.
  • Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations.
  • Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.
  • Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten's security and compliance standards.
  • Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.
  • Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.
  • Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.
  • Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.

REQUIREMENTS
  • 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.
  • Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.
  • Proven track record managing compliance audits and certification programs end-to-end.
  • Experience with access management concepts, third-party risk
  • Experience working cross-functionally with technical and non-technical stakeholders to implement compliance and security controls.
  • Excellent organizational, documentation, and communication skills with attention to detail.
  • Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.

NICE TO HAVE
  • Experience with cloud security compliance in AWS or GCP environments.
  • Hands-on experience using GRC tools (e.g., Vanta, Drata, Secureframe, Anecdotes).
  • Understanding of AI/ML security considerations, data privacy, and model governance.
  • Previous experience building and scaling compliance programs in an early-stage or rapidly growing startup.
  • Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer).


BENEFITS
  • Competitive compensation, including meaningful equity.
  • 100% coverage of medical, dental, and vision insurance for employee and dependents
  • Flexible PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!)
  • Paid parental leave
  • Fertility and family-building stipend through Carrot
  • Company-facilitated 401(k)
  • Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.

Apply now to embark on a rewarding journey in shaping the future of AI! If you are a motivated individual with a passion for machine learning and a desire to be part of a collaborative and forward-thinking team, we would love to hear from you.

Similar Jobs

More Jobs at Baseten

More Information Technology Jobs

Find similar GRC Manager jobs: