SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 175,000 - 0 / annual
Turing is an AI-focused company headquartered in San Francisco that works with frontier AI labs to generate high-quality datasets, reinforcement learning environments, and research benchmarks. The company also partners with Fortune 500 enterprises to build and deploy agentic AI systems in mission-critical workflows.
You will serve as a Senior GRC Analyst responsible for running the company's governance, risk, and compliance program day-to-day. This is a strong individual-contributor role for someone with deep compliance expertise who can lead audits confidently and translate control requirements into practical, executable work across the organization.
Key responsibilities include:
- Owning and coordinating compliance audits and certifications (SOC 2, ISO 27001, and others), including evidence collection, auditor coordination, and remediation tracking
- Maintaining and improving the control framework, mapping controls across multiple frameworks to reduce duplicate work
- Conducting risk assessments—identifying, documenting, and tracking risks to resolution
- Running the vendor/third-party risk program, including security reviews and ongoing monitoring
- Supporting customer security reviews, questionnaires, and trust center maintenance
- Developing, maintaining, and socializing security policies and standards
- Partnering with control owners across the company to ensure controls operate effectively and driving remediation when needed
- Identifying opportunities to automate manual GRC work and partnering with GRC engineering to implement solutions
Within your first few months, you will own key parts of the audit and risk programs, become a go-to partner for control owners, and begin transforming manual GRC work into repeatable, increasingly automated processes.
REQUIREMENTS:
- Several years of experience (typically 4+ years) in GRC, compliance, audit, or risk
- Hands-on experience supporting or leading SOC 2 and/or ISO 27001 audits
- Solid understanding of control frameworks, risk assessment methodologies, and vendor risk management
- Strong organization and attention to detail, with ability to manage multiple workstreams and deadlines
- Clear communicator who can work effectively with both technical and non-technical teams
- Comfort with GRC/compliance tooling
NICE TO HAVE:
- Relevant certifications (CISA, CISSP, CIPP, or similar)
- Experience with compliance automation and continuous controls monitoring
- Familiarity with cloud environments and how technical controls are implemented
- Experience supporting enterprise sales and customer security due diligence