Sr. Security Engineer
Job description
About the role
SpaceXAI is building an AI organization that can accurately understand the universe and aid humanity in its pursuit of knowledge, and this role is central to that ambition. You will own and scale the security and AI governance compliance posture as the company grows rapidly across multiple sectors. The ideal hire combines deep fluency across modern security and AI frameworks with hands-on GRC engineering skills to translate control requirements into technical implementations. You will partner directly with engineers to bake compliance into architecture and CI/CD, replacing point-in-time checklist work with continuous, engineered assurance. This position operates with a high degree of autonomy within a flat organizational structure, expecting initiative and direct contribution to the company mission. You will collaborate across engineering, legal, product, and leadership to keep AI systems audit-ready across enterprise, commercial, and public-sector environments while championing a culture of security and compliance.
Key facts
What you'll do
- Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking.
- Build and maintain Compliance-as-Code and continuous compliance capabilities - policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows - so the company can move fast without cutting corners.
- Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil.
- Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery.
- Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture.
- Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater.
- Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces).
- Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
- Implement measurable metrics and reporting for compliance coverage, risk posture, and audit outcomes to support data-driven decisions and executive oversight.
- Drive standardization of security and compliance tooling across environments to improve efficiency, consistency, and reliability as the organization scales.
- Collaborate with data science and model ownership teams to establish model governance processes, including documentation, change management, and monitoring for AI-specific risks.
- Ensure that security and compliance practices support rapid iteration and deployment while maintaining the integrity, confidentiality, and availability of systems and data.
- Contribute to the design of secure and compliant AI workflows, integrating controls into MLOps pipelines and production environments from the earliest stages.
- Act as a subject matter expert for internal and external stakeholders, providing clarity on regulatory expectations and how the company's technical controls meet those requirements.
Requirements
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
- 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities.
- Demonstrated experience implementing and maintaining security compliance frameworks and controls in cloud environments.
- Hands-on experience with Compliance-as-Code approaches and tools such as policy-as-code, evidence automation, and continuous validation.
- Strong working knowledge of security and AI frameworks such as NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, SOC 2, and the EU AI Act.
- Experience with GRC platforms such as Vanta and the ability to integrate them with cloud, identity, and engineering tooling.
- Solid understanding of cloud security, identity and access management, data privacy regulations, and risk management practices.
- Excellent written and verbal communication skills to articulate technical control narratives to both technical and non-technical audiences.
Practical notes
- Location flexibility across New York, New York; Palo Alto, California; and Washington, D.C.
- Full-time engagement with expectations for hands-on contribution and direct impact on mission-critical compliance and security programs.
- No specific visa or travel details provided in SOURCE.
- No compensation band or benefits details provided in SOURCE.
- No explicit deadlines or application steps stated in SOURCE.
The role is positioned within a small, highly motivated team that values engineering excellence, rapid execution, and deep curiosity. You will be expected to operate with ownership, communicate clearly, and deliver measurable results in a fast-moving environment. This position is ideal for a practitioner who thrives on challenging problems and wants to shape the governance and compliance foundation of an AI-focused company building at the intersection of security and artificial intelligence. Your work will directly influence how the organization scales compliance, manages AI risks, and prepares for audits across diverse regulatory regimes.