đ About this role
WRITER is seeking a GRC Specialist to shape and lead our governance, risk, and compliance strategy for the AI era.
As we pioneer AI/AGI technologies, we face a fast-changing regulatory landscape alongside established compliance frameworks. This role calls for a compliance leader who can balance rigorous adherence to standards with the flexibility to support rapid innovation. Youâll research emerging AI regulations, design scalable compliance programs, and manage risk in a way that acceleratesârather than hindersâour growth.
Youâll own the end-to-end compliance strategy for WRITER, covering everything from SOC2, ISO, and GDPR to emerging AI governance requirements, while partnering with technical and legal teams to ensure controls are implemented effectively. If you can translate complex regulatory obligations into practical, business-aligned programs, youâll have a profound impact on how WRITER builds safe, compliant, and trusted AI systems.
Role Boundaries & Collaboration
What You Own (Responsible)
Overall compliance program strategy and management
AI regulatory compliance research and implementation
Enterprise risk management framework
Third-party risk management program
Data privacy and governance programs
Audit coordination and management
What You Don't Own (Others Lead)
Technical implementation of security controls (other security teams own)
Operational security monitoring (Detection & Response owns)
Identity and access implementations (Enterprise/Corporate and Cloud/Infrastructure own)
Key Partnerships
With All Security Teams: You define compliance requirements; they implement technical controls
With AI Security: Partner on AI-specific regulatory requirements and risk assessments
With Enterprise/Corporate: They implement technical vendor assessments you define
With Legal: Collaborate on regulatory interpretation and privacy matters
đڏđťââď¸ Your responsibilities
Lead AI regulatory compliance â Research global AI regulations, develop compliance strategies, and align AI development with transparency, fairness, and safety requirements.
Own compliance programs â Manage SOC2, ISO 27001/27701/42001, GDPR, HIPAA, SOX readiness, and FedRAMP strategies.
Drive enterprise risk management â Design frameworks for assessing and mitigating AI-specific and enterprise-wide risks.
Manage third-party risk â Build vendor risk programs for AI/ML suppliers, cloud providers, and data processors.
Champion data privacy â Lead privacy programs for AI training data and user information, ensuring compliance with GDPR, CCPA, and emerging laws.
Coordinate audits and certifications â Oversee internal and external audits, evidence collection, and resolution of findings with minimal disruption.
Enable compliance through partnership â Define requirements and collaborate with security, engineering, and legal teams to implement controls.
âď¸ Is this you?
Required Experience
8+ years in governance, risk, and compliance for technology companies.
5+ years managing compliance programs (SOC2 and ISO certifications required).
Proven experience in emerging technology compliance, ideally AI/ML governance.
Deep expertise in global privacy regulations and implementation.
Strong program and stakeholder management skills.
Technical Expertise
Expert in security frameworks (SOC2, ISO, NIST, GDPR, HIPAA, FedRAMP).
Understanding of AI/ML technologies and their unique risk profiles.
Proficiency with GRC platforms, automation tools, and risk assessment methods.
Knowledge of cloud security compliance requirements.
Experience with data governance, classification, and privacy-by-design.
Execution & Impact
Track record of building compliance programs from the ground up.
History of passing audits with minimal findings.
Proven ability to translate regulations into actionable, business-aligned programs.
Strong analytical approach to risk and compliance metrics.
Preferred Qualifications
Experience with AI governance frameworks.
Background in technology or engineering.
Certifications such as CISA, CRISC, CIPP.
Experience with public company compliance requirements.
Knowledge of international data transfer mechanisms.
đŠ Benefits & perks (US Full-time employees)
Generous PTO, plus company holidays
Medical, dental, and vision coverage for you and your family
Paid parental leave for all parents (12 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Flexible spending account and dependent FSA options
Health savings account for eligible plans with company contribution
Annual work-life stipends for:
Home office setup, cell phone, internet
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation, company stock options and 401k
WRITER is an equal-opportunity employer and is committed to diversity. We don't make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
By submitting your application on the application page, you acknowledge and agree to WRITER's Global Candidate Privacy Notice.
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
WRITER is seeking an experienced Detection and Response Engineer to build and operate production-grade detections and automated responses for AI/ML infrastructure and model deployments.
Join WRITER as an Enterprise Security Engineer to lead identity, endpoint, MDM, and zero-trust efforts that protect employees and accelerate business growth.
Lead compliance oversight for American Expressâs U.S. Consumer deposit products, advising on regulatory requirements, new product governance, marketing review, controls and issue management.
Wilson Elser is hiring an experienced Senior Professional Liability Attorney to lead and grow its Accounting Practice, defending accounting professionals in high-stakes regulatory and malpractice matters.
StackAdapt is hiring a business-minded Commercial Counsel to draft and negotiate commercial agreements, advise on adtech, data/privacy and AI issues, and support revenue operations in a remote-first environment.
Lead compliance oversight for U.S. consumer deposit products at American Express, advising on regulatory requirements, new product governance, and risk controls to support safe growth and innovation.
American Express is hiring an Audit Director to lead change management and implementation of enterprise risk framework updates, audit tools, and enablement across the Internal Audit Group.
Serve Robotics is hiring a Corporate Paralegal to manage entity and corporate governance matters, support equity administration, and help run legal operations for its Los Angeles team.
American Express is hiring a Senior Manager to own and strengthen global program controls and governance for third-party merchant acquiring programs.
Experienced higher-education safety leader wanted to direct Compliance & Support Services at NYU, overseeing incident review, victim services, records, internal affairs, ID/card operations, and staff recruitment and development.
Lead Veolia's transportation compliance program for ESS fleets, ensuring DOT/FMCSA/PHMSA adherence, telematics-driven oversight, and robust training and reporting across operations.
Morgan & Morgan is hiring a detail-oriented Pre-Litigation Paralegal (Case Manager) in Irvine to manage personal injury caseloads, coordinate with clients and providers, and assist attorneys with settlement development.
Nueces County Court Administration seeks an unpaid 20-hour/week intern to assist with clerical, records, and document preparation duties at the County Courthouse.
An experienced compliance analyst to manage OFAC/sanctions screening, investigate potential matches, and act as a subject-matter resource within American Express' Global Financial Crimes Compliance team.
The CCR team at American Express is hiring an Analyst to partner with marketing and compliance stakeholders to review, approve, and operationalize compliant advertising and campaign processes.
Writer is the full-stack generative AI platform for enterprises. We empower your entire organization â support, operations, product, sales, HR, marketing, and more.
19 jobs