×
Register Here to Apply for Jobs or Post Jobs. X

Lead GRC Engineer

Job in San Francisco, San Francisco County, California, 94199, USA
Listing for: Higgsfield
Full Time position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 220000 - 280000 USD Yearly USD 220000.00 280000.00 YEAR
Job Description & How to Apply Below

Why work at Higgsfield AI?

Higgsfield AI is the fastest-scaling generative AI company in history, hitting $500M in annual revenue run rate, 25M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands.

We're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.

About the role:

We’re looking for a Lead GRC Engineer to build the technical foundation of our security and compliance program as Higgsfield scales.

This is not a traditional GRC role focused primarily on policies, audits, and evidence collection. We’re looking for a builder who can translate security, privacy, and compliance requirements into technical, automated, and continuously monitored controls.

You’ll work closely with Security, Engineering, Privacy, Legal, and other teams to design controls that work for Higgsfield today while building the infrastructure we’ll need several years from now.

What You’ll Do Build Controls & Compliance Infrastructure
  • Translate security, privacy, and compliance requirements into technical controls, automated checks, and enforcement mechanisms
    .

  • Build pipelines and integrations that aggregate control, asset, identity, and system data across cloud infrastructure, IdP, HRIS, source control, CI/CD, and SaaS applications.

  • Turn that data into automated control checks, live monitoring, dashboards, alerts, and audit-ready evidence.

  • Build preventative controls and release gates that identify or block security and privacy issues before they reach production.

  • Design controls that remain effective as our employees, locations, vendors, systems, infrastructure, and products rapidly change.

Automate Evidence & Continuous Assurance
  • Build a unified controls approach where evidence can be collected once and mapped across multiple frameworks and requirements.

  • Automate evidence collection, control testing, monitoring, and exception management rather than relying on point-in-time reviews.

  • Integrate with systems and controls already owned by Security, Engineering, IT, and other teams rather than creating parallel processes.

  • Continuously test whether controls are actually working and detect when they regress or drift.

  • Instrument control effectiveness so security and GRC stakeholders can understand risk posture from live data rather than periodic assessments
    .

Build AI-Native GRC Workflows
  • Design agentic and AI-assisted workflows for evidence analysis, control testing, monitoring, and audit-response preparation.

  • Apply strong judgment around what can be delegated to AI, what requires human review, and how both should be evidenced.

  • Help build the technical evidence base for AI-related certifications and assurance, including areas such as agent activity, evaluations, tool restrictions, and failure modes.

  • Partner with Product and Engineering as AI assurance standards and customer expectations continue to evolve.

Requirements:

  • 6+ years spanning security, GRC, software engineering, automation engineering, or related technical roles.
  • Demonstrated experience translating framework, regulatory, or policy requirements into technical implementations.
  • Hands‑on experience personally building or automating security and compliance controls.
  • Production‑grade scripting or programming experience, such as Python, including working with APIs and integrations.
  • Strong understanding of frameworks such as SOC 2 and ISO 27001 and what constitutes credible control evidence.
  • Ability to distinguish between a control that technically exists and one that is actually effective, enforced, and continuously monitored.
  • Experience building in rapidly changing or 0→1 environments without relying on mature infrastructure or large teams.
  • Strong judgment around automation, risk, exceptions, enforcement, and engineering velocity.
  • Ability to communicate technical controls and evidence clearly to auditors, customer security teams, engineers, and nontechnical stakeholders.

Compensation & Benefits

  • We offer a competitive and thoughtfully structured…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary