SlipstreamJobsFresh Startup & VC-Backed Jobs

Security GRC Lead

Mercor - San Francisco, CA, USA - In-office - posted 2026-09-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Mercor is seeking the first Security GRC (Governance, Risk, and Compliance) hire to build and operate a comprehensive compliance program for a Series C AI data company valued at $10 billion. The company processes sensitive training data, evaluations, and human-feedback pipelines for frontier AI labs, plus manages payments and KYC for 300,000+ domain experts. Compliance posture is a critical sales gate for every major enterprise contract. In this role, you will own the complete operating cadence of a continuously-audited organization, including SOC 2 Type 2 continuous monitoring via Vanta, active ISO 27001 buildout, quarterly customer audits (KPMG-grade), and sub-48-hour questionnaire response SLAs. You'll establish and operationalize controls, build a customer-audit machine that responds to requests from Anthropic, Google, Meta, NVIDIA, and OpenAI without burning out the security team, and develop a formal third-party risk program tied into procurement. Key responsibilities include: designing the compliance operating cadence and sequencing frameworks (SOC 2, ISO 27001, HIPAA, FedRAMP Moderate, EU AI Act conformity); implementing controls-as-code using Vanta integrations, Wiz policy packs, and Panther rules; establishing data-handling procedures including customer-data-deletion workflows and DSAR processes; managing policy lifecycle end-to-end; and building the internal trust narrative with customer trust pages and executive-ready disclosure templates. You'll leverage AI heavily in GRC work—using LLMs to draft, review, and respond to questionnaires at speed, and have engineering support to build custom tooling where off-the-shelf platforms fall short. This is not audit theater; you'll own real compliance outcomes that directly close enterprise deals. The role is based in San Francisco with in-person work five days per week (first Fridays remote).

Similar roles