Baseten Logo

Baseten

GRC Manager

Posted 22 Days Ago
In-Office or Remote
3 Locations
150K-250K Annually
Senior level
In-Office or Remote
3 Locations
150K-250K Annually
Senior level
The GRC Manager will establish and lead security governance and compliance programs, manage audits, develop policies, and work cross-functionally to ensure compliance with standards such as SOC 2 and ISO 27001.
The summary above was generated by AI

ABOUT BASETEN

Baseten powers inference for the world's most dynamic AI companies, like OpenEvidence, Clay, Mirage, Gamma, Sourcegraph, Writer, Abridge, Bland, and Zed. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. With our recent $150M Series D funding, backed by investors including BOND, IVP, Spark Capital, Greylock, and Conviction, we’re scaling our team to meet accelerating customer demand.

THE ROLE

We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) to establish, lead, and continuously enhance Baseten’s security governance and compliance programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance.

In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, and GDPR. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow.

RESPONSIBILITIES

  • Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.

  • Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.

  • Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001, GDPR, and other applicable standards and regulations.

  • Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.

  • Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.

  • Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.

  • Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.

  • Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.

  • Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.

REQUIREMENTS

  • 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.

  • Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.

  • Proven track record managing compliance audits and certification programs end-to-end.

  • Familiarity with risk management methodologies, control design, and governance frameworks.

  • Experience working cross-functionally with technical and non-technical stakeholders to implement compliance controls.

  • Excellent organizational, documentation, and communication skills with attention to detail.

  • Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.

NICE TO HAVE

  • Experience with cloud security compliance in AWS or GCP environments.

  • Hands-on experience using GRC tools (e.g., Vanta, Drata, Tugboat Logic, Secureframe).

  • Understanding of AI/ML security considerations, data privacy, and model governance.

  • Previous experience scaling compliance programs in an early-stage or rapidly growing startup.

  • Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer).

BENEFITS

  • Competitive compensation, including meaningful equity.

  • 100% coverage of medical, dental, and vision insurance for employee and dependents

  • Generous PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!)

  • Paid parental leave

  • Company-facilitated 401(k)

  • Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.

Apply now to embark on a rewarding journey in shaping the future of AI! If you are a motivated individual with a passion for machine learning and a desire to be part of a collaborative and forward-thinking team, we would love to hear from you.

At Baseten, we are committed to fostering a diverse and inclusive workplace. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status.

Top Skills

AWS
GCP
Grc Tools

Similar Jobs

2 Days Ago
Remote
U.S.
124K-146K Annually
Mid level
124K-146K Annually
Mid level
Software
Lead strategic educational programs on Governance, Risk, and Compliance at Vanta, ensuring customer engagement and adherence to regulations while measuring impact.
Top Skills: CamtasiaIntercomLms PlatformsZendesk
11 Days Ago
Remote or Hybrid
United States
Senior level
Senior level
Aerospace
The Infosec & GRC Manager will lead the company's cybersecurity and compliance strategy, ensuring secure infrastructure and managing information security programs across international operations.
Top Skills: AnsibleCisspCloudFormationCmmcCrowdstrikeCyber Essentials PlusGdprGoIso 27001Microsoft Entra IdNist 800-171OktaParamifyPowershellPythonSplunkTenableTerraformVantaWizZscaler
13 Hours Ago
Remote
6 Locations
Senior level
Senior level
Cloud • Security
The Enterprise Account Manager is responsible for driving new sales into large Enterprise Accounts, maintaining relationships, collaborating with technical teams, and meeting sales targets while managing a complex sales cycle.
Top Skills: CybersecuritySalesSoftware

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account