GRC Manager
basetenUSAFull Time1w ago
AWSGCPMachine LearningAIMLSparkSecuritySOCComplianceSaaSLegalOperations
Job description
GRC Manager at baseten.
About the role
Baseten is looking for a GRC Manager to develop and improve our security governance, compliance, and privacy programs. This role is crucial for ensuring our platform meets high standards for trust and regulatory adherence. You will be an early member of the security team, helping to build scalable processes as the company grows.
Key facts
What you'll do
- Design and maintain security governance frameworks, policies, and procedures.
- Create and manage a company-wide program for assessing, tracking, and reducing security and compliance risks.
- Lead efforts to achieve and maintain compliance with standards like SOC 2, ISO 27001/27701, HIPAA, and FedRAMP.
- Coordinate external audits and certifications, ensuring efficient evidence collection and remediation.
- Oversee security assessments for vendors to ensure third-party compliance.
- Collaborate with engineering, product, and operations teams to integrate compliance into daily processes.
- Assist customers with security questionnaires, due diligence, and documentation requests.
- Develop and deliver security and compliance training across the company.
- Stay informed on regulatory changes and lead initiatives to enhance compliance programs.
Requirements
- 5 or more years of experience in GRC, Security Compliance, or Information Security, preferably in a SaaS or cloud environment.
- Strong understanding of security frameworks such as SOC 2, ISO 27001, NIST, and GDPR.
- Demonstrated ability to manage compliance audits and certification programs from start to finish.
- Experience with access management concepts and third-party risk.
- Proven ability to work with both technical and non-technical teams to implement security controls.
- Excellent organizational, documentation, and communication skills with a focus on detail.
- Capacity to thrive in a fast-paced, high-growth startup while maintaining structured processes.
Nice to have
- Experience with cloud security compliance in AWS or GCP.
- Practical experience with GRC tools like Vanta, Drata, Secureframe, or Anecdotes.
- Understanding of AI/ML security considerations, data privacy, and model governance.
- Prior experience building and scaling compliance programs in an early-stage or rapidly growing startup.
- Relevant certifications such as CISA, CISSP, CISM, or ISO 27001 Lead Implementer.
Skills & tools
- SOC 2
- ISO 27001
- ISO 27701
- HIPAA
- FedRAMP
- NIST
- GDPR
- AWS
- GCP
- Vanta
- Drata
- Secureframe
- Anecdotes
Practical notes
Baseten offers comprehensive benefits including 100% coverage for medical, dental, and vision insurance for employees and their dependents. The company provides flexible PTO, including a winter break from Christmas Eve to New Year's Day, paid parental leave, a fertility and family-building stipend through Carrot, and a company-facilitated 401(k).