SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead GRC Engineer

Higgsfield AI - San Francisco, CA, USA - Hybrid - posted 2026-08-28

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 220,000 - 280,000 / annual

Higgsfield AI is seeking a GRC Engineer to build the technical foundation of security and compliance infrastructure as the company scales. This role bridges security, privacy, compliance, and engineering—translating regulatory requirements into automated, continuously monitored technical controls rather than traditional policy-focused GRC work. You will design and build control infrastructure that aggregates data from cloud infrastructure, identity providers, HRIS, source control, CI/CD, and SaaS applications. Your work will include creating automated control checks, live monitoring dashboards, alerts, and audit-ready evidence collection. You'll design preventative controls and release gates that identify or block security and privacy issues before production, while ensuring controls remain effective as the company rapidly scales. A key focus is automating evidence collection and continuous assurance. Rather than point-in-time reviews, you'll build unified control approaches where evidence is collected once and mapped across multiple frameworks. You'll continuously test control effectiveness, detect drift, and instrument visibility into risk posture from live data. As Higgsfield scales its AI products, you'll also design agentic and AI-assisted workflows for evidence analysis, control testing, and audit response. You'll help build the technical evidence base for AI-related certifications and work with Product and Engineering as AI assurance standards evolve. You bring 6+ years in security, GRC, software engineering, or automation roles, with hands-on experience building and automating controls. You're proficient in production-grade scripting (Python preferred), understand frameworks like SOC 2 and ISO 27001, and can distinguish between controls that technically exist and those that are actually effective and enforced. You thrive in rapidly changing, 0→1 environments and communicate technical concepts clearly to auditors, security teams, engineers, and non-technical stakeholders.

Similar roles