Security GRC Specialist
Job in
South San Francisco, San Mateo County, California, 94083, USA
Listed on 2026-08-17
Listing for:
Jobtailor
Full Time
position Listed on 2026-08-17
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
- Own Phylo’s security and compliance roadmap.
- Lead SOC 2, ISO 27001 and GDPR readiness, audits, evidence collection, and remediation.
- Build HIPAA-ready processes for workloads involving protected health information.
- Assess and plan for FedRAMP, NIST, privacy, and life-sciences requirements where applicable.
- Partner with engineers to implement scalable controls across cloud infrastructure, applications, and AI systems.
- Lead customer questionnaires, RFPs, due diligence, and security conversations.
- Run risk assessments and drive remediation across systems, vendors, and processes.
- Maintain lightweight policies, customer-facing security documentation, and compliance reporting.
- Automate evidence collection, monitoring, and other compliance workflows.
- 5+ years in security GRC, compliance, or a security engineering-adjacent role
- Experience leading SOC 2, ISO 27001, HIPAA, FedRAMP, or similar programs
- Strong understanding of cloud and application security
- Ability to translate regulatory requirements into technical controls
- Experience supporting audits and enterprise customer security reviews
- Strong cross-functional communication and program ownership
- A pragmatic, hands-on approach suited to an early-stage company.
- Nice to Have:
Experience building a security program from an early stage - Background in healthcare, life sciences, enterprise AI, or cloud infrastructure
- Experience with HIPAA, FedRAMP, NIST SP 800-53, HITRUST, or GDPR
- Familiarity with AI governance frameworks such as NIST AI RMF or ISO 42001
- Experience automating GRC and compliance workflows
Demonstrates expertise in security governance, risk management, and compliance (GRC) with a focus on SOC 2, ISO 27001, and HIPAA. Proven ability to implement scalable security controls and automate compliance workflows in cloud and AI environments.
Highest-signal resume keywords- Security Governance, Risk Management, And Compliance (GRC)
- SOC 2, ISO 27001, And HIPAA Program Leadership
- Cloud And Application Security Expertise
- Regulatory Requirements Translation Into Technical Controls
- Experience Automating GRC And Compliance Workflows
Hard Skills
- SOC 2
- ISO 27001
- HIPAA
- FedRAMP
- NIST SP 800-53
- GDPR
- Risk Assessment
- Compliance Reporting
- Evidence Collection Automation
- Security Program Development
- Cross-Functional Communication
- Program Ownership
- Pragmatic Problem-Solving
- Healthcare
- Life Sciences
- Enterprise AI
- AI Governance Frameworks
- Cloud Infrastructure
- AI Systems
- Compliance Workflows
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×