← Back to results

Member of Security Staff, Governance, Risk and Compliance

Join Gimlet Labs as a Member of Security Staff to build and own the security and compliance foundation for an AI company.

Location
San Francisco, CA, United States
Compensation
Not disclosed
Level
staff
Type
full time

Posted by employer 4 months ago

First seen on Joblaze 3 hours ago

Last verified on the company career page 3 hours ago

Apply at Gimlet Labs → Save job Scanned from gimletlabs.ai

What you'll build

  • Partner with engineering, infrastructure, and product teams to identify security risks
  • Build and operationalize security and compliance programs
  • Drive improvements to cloud and application security controls
  • Help define security approaches for AI systems
  • Build scalable processes for audit evidence collection

Must have

  • Experience in security risk, compliance, GRC, cloud security, or infrastructure security
  • Working knowledge of cloud platforms such as AWS, Azure, or Google Cloud
  • Familiarity with networking concepts
  • Understanding of software security concepts
  • Experience with compliance frameworks

Nice to have

  • Experience in an early-stage startup or high-ownership environment
  • Experience supporting AI, machine learning, data infrastructure, or SaaS platforms
  • Familiarity with AI governance frameworks
  • Experience with Kubernetes, containers, infrastructure as code
  • Certifications such as CISSP, CISA, CRISC

Not disclosed in this posting: compensation, years of experience, work arrangement, visa sponsorship.

Joblaze summary

In this role, the Member of Security Staff will focus on establishing and managing the security and compliance framework for Gimlet Labs, ensuring that AI systems meet rigorous standards. Key skills include expertise in cloud security, risk management, and familiarity with compliance frameworks like SOC 2 and ISO 27001. This position is ideal for candidates with a background in security risk and compliance, particularly those who thrive in fast-paced, high-ownership environments. The team is engaged in cutting-edge AI infrastructure, providing a unique opportunity to tackle complex security challenges.

Joblaze insights

  • Listed today — first seen on Joblaze October 5, 2026. Last confirmed on Gimlet Labs's careers page October 5, 2026.
  • AWS appears in 35.1% of 97 comparable staff security roles in United States; NIST CSF appears in 1% of 97 comparable staff security roles in United States.

Quick facts

What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Azure, CSA CCM, Encryption, Google Cloud, IAM.
What seniority level is this role?
Gimlet Labs targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Member of Security Staff, Governance, Risk and Compliance role at Gimlet Labs.

From the original posting

About the role

Gimlet Labs is looking for a Member of Security Staff, Governance, Risk and Compliance to build and own the security and compliance foundation for an AI company operating across rapidly evolving AI systems serving production scale traffic for top frontier labs and hyperscalers.

This is a highly hands-on role for someone who can design the compliance program, implement the technical controls, and work directly with engineering to make security auditable, scalable, and practical. You will have significant ownership over the compliance stack, including policies, controls, evidence collection, audit readiness, vendor risk, and security tooling.

What success looks like

In the first 12-18 months, you will:

  • Partner directly with engineering, infrastructure, and product teams to identify security risks and design practical controls across AI platforms, cloud infrastructure, networking systems, APIs, and software delivery pipelines.

  • Build and operationalize security and compliance programs supporting frameworks such as SOC 2, ISO 27001, NIST CSF, NIST AI RMF, CSA CCM, and customer security requirements.

  • Drive improvements to cloud and application security controls, including IAM, network segmentation, encryption, logging, secrets management, vulnerability management, and secure SDLC practices.

  • Help define security approaches for AI systems, including model access controls, data protection, third-party AI tooling, auditability, and misuse prevention.

  • Build scalable processes for audit evidence collection, risk tracking, remediation management, and security reporting across technical and non-technical stakeholders.

  • Contribute to broader security and operational readiness efforts including vendor risk management, incident response preparedness, business continuity planning, and security policy development.

You may be a good fit if

  • Experience in security risk, compliance, GRC, cloud security, or infrastructure security.

  • Working knowledge of cloud platforms such as AWS, Azure, or Google Cloud.

  • Familiarity with networking concepts including firewalls, VPC/VNet design, VPNs, DNS, TLS, routing, segmentation, and zero trust principles.

  • Understanding of software security concepts, including secure SDLC, CI/CD, vulnerability management, secrets management, and API security.

  • Experience with compliance frameworks such as SOC 2, ISO 27001, NIST, CIS Controls, or CSA CCM.

  • Ability to document controls, gather evidence, assess gaps, and drive remediation with engineering teams.

  • Strong written and verbal communication skills.

Strong candidates may also have

  • Experience in an early-stage startup or high-ownership environment.

  • Experience supporting AI, machine learning, data infrastructure, or SaaS platforms.

  • Familiarity with AI governance frameworks such as NIST AI RMF or ISO/IEC 42001.

  • Experience with Kubernetes, containers, infrastructure as code, and cloud-native security tooling.

  • Certifications such as CISSP, CISA, CRISC, CCSP, CCSK, Security+, AWS Security Specialty, or Azure Security Engineer.

  • Experience implementing or administering GRC platforms, SIEMs, CSPM tools, vulnerability scanners, and ticketing workflows.

  • Solve hard problems.

  • Own meaningful work.

  • Build for production.

  • Help define what’s next.

Standard company text repeated across Gimlet Labs's postings is omitted here.

Similar positions

Gimlet Labs
Member of Technical Staff - Distributed Systems
Gimlet Labs · San Francisco, CA, United States
Cursor
Security GRC Engineer
Cursor · San Francisco
Gimlet Labs
Member of Technical Staff - Infrastructure
Gimlet Labs · San Francisco, CA, United States
Gimlet Labs
Member of Technical Staff - Kernels & GPU Performance
Gimlet Labs · San Francisco, CA, United States
Gimlet Labs
Legal Intern
Gimlet Labs · San Francisco, CA, United States