Security GRC Lead

Mercor

$150K — $180K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in security GRC, compliance engineering, or audit with 2+ years managing a SOC 2 Type 2 program end-to-end.
  • Experience in obtaining ISO 27001 certification from kickoff to issued certificate with a recognized registrar.
  • Proficient in Vanta (or similar tools) at an integration and admin level, capable of configuring and debugging.
  • Participated in at least one enterprise customer audit by a Big 4 firm for a frontier customer.
  • Ability to translate cloud-security language to auditor language and vice versa without losing detail.
  • Competent in coding controls and querying evidence with programming languages like Python or SQL.
  • Understand the differences between controls and compensating controls and can accurately represent them.

Responsibilities

  • Establish and manage the Mercor compliance operating cadence for SOC 2 Type 2 and ISO 27001 while planning for customer-requested frameworks.
  • Create an efficient customer-audit machine to handle inquiries from major tech companies while maintaining a quick response time.
  • Develop a comprehensive third-party risk program integrated with vendor onboarding processes.
  • Manage the policy lifecycle including version control and exception handling to maintain active document relevancy.
  • Implement 'controls-as-code' to streamline compliance processes and automate evidence collection.
  • Oversee data-handling procedures to close customer-data gaps and enhance security best practices.
  • Craft internal trust narratives and disclosures for customers and stakeholders.

Benefits

  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k Relocation bonus
  • $10K housing bonus for proximity to the office
  • $1.5K monthly stipend for meals
  • Free Equinox membership
  • $200 monthly laundry reimbursement
  • $200 monthly personal wellness reimbursement
  • Health, Dental, Vision insurance
Full Job Description
Role Description

You'll be the first GRC hire at a company that processes some of the most sensitive data on earth: training data, evals, and human-feedback pipelines for the frontier AI labs, plus payments and KYC for 300K+ experts. Compliance posture is a sales gate for every $50M+ contract Mercor signs. The audit calendar never ends.

This is not an audit-theater role. You'll own the operating cadence of a continuously-audited company: continuous SOC 2 monitoring in Vanta, the active ISO 27001 buildout, an annual KPMG-style customer audit every quarter, and a sub-48-hour questionnaire SLA. You'll write controls in code where it makes sense, push back on tools that fight you, and own the artifacts that close enterprise deals.

We use AI heavily in our own GRC work - Vanta has an MCP, our questionnaire bank is queryable, evidence is automated where the framework allows it. You should be comfortable using LLMs to draft, review, and respond at speed. If you've ever copy-pasted the same answer into 14 vendor questionnaires by hand, you'll appreciate not having to.

We're in-person five days a week at our SF headquarters, with first Fridays remote.
What You'll Build
  • The Mercor compliance operating cadence: SOC 2 Type 2 (continuous), ISO 27001 (standing up now), and the next two frameworks customers ask for (HIPAA, FedRAMP Moderate, EU AI Act conformity - your call on sequencing)
  • A customer-audit machine that responds to Anthropic, Google, Meta, NVIDIA, and OpenAI without burning out the security team - questionnaire SLA under 48h, KPMG-grade evidence packs on demand
  • The third-party risk program - formal intake, recurring review cadence, evidence requirements - tied into procurement so vendors can't be onboarded around it
  • Policy lifecycle owned end-to-end: version, attestation, exception handling, review cycle - not a SharePoint graveyard
  • Controls-as-code where it makes sense: Vanta integrations, Wiz policy packs, Panther rules tied to SOC 2 CC categories, automated evidence collection
  • Data-handling procedures: the customer-data-deletion gap, DSAR workflow, KMS scheduled destruction, offboarding handlers
  • The internal trust narrative: customer trust pages, security one-pagers, executive-ready disclosure templates when something goes sideways
What We're Looking For
  • 7+ years in security GRC, compliance engineering, or audit, with at least 2 years owning a SOC 2 Type 2 program end-to-end at a company under audit by enterprise customers
  • You've shipped at least one ISO 27001 certification from kickoff to issued certificate, including Stage 1 and Stage 2 with a real registrar
  • Fluent in Vanta (or Drata, Secureframe, Sprinto) at the integration and admin level, not just the reviewer UI - you've configured connectors, written custom tests, debugged broken evidence
  • You've sat on the company side of at least one enterprise customer audit conducted by a Big 4 firm (KPMG, EY, Deloitte, PwC) on behalf of a frontier customer
  • You translate cloud-security language to auditor language and back without losing precision - you can read a Wiz finding, a Panther rule, an IAM policy, and say what control it maps to
  • You write controls as code or query evidence with SQL when the platform falls short - Python, SQL, or shell, whatever it takes
  • You know the difference between "we don't have a control for that" and "we have a compensating control" and you don't fabricate the second one
  • Direct experience with the customer-trust surface: SIG, CAIQ, custom enterprise questionnaires, on-site auditor sessions, disclosure letters under legal review
Bonus Points
  • Built or operated a GRC program inside an AI lab, ML platform, or company serving frontier labs as customers
  • Familiar with AI-specific frameworks: NIST AI RMF, EU AI Act conformity, ISO 42001
  • Experience with FedRAMP Moderate, HIPAA, PCI DSS, or SOC 2 + HITRUST dual scope
  • You've automated questionnaire response with an LLM and know where it works and where it fails
  • Prior experience standing up a third-party risk program from zero - vendor intake, recurring review, contract teeth
  • Written a public trust page that customers actually trust
Benefits
  • Bi-annual performance bonus structure
  • Generous equity grant vested over 4 years
  • Up to $15k Relocation bonus
  • $10K housing bonus (if you live within 0.5 miles of our office)
  • $1.5K monthly stipend for meals
  • Free Equinox membership
  • $200 monthly laundry reimbursement
  • $200 monthly personal wellness reimbursement
  • Health, Dental, Vision insurance

Similar Jobs

More Jobs at Mercor

More Information Technology Jobs

Find similar Security GRC Lead jobs: