Cybersecurity Grc Manager

Cerebras · Semiconductors · Headquarters +1 · Remote · Security & IT

Cerebras is seeking a Cybersecurity GRC Manager to mature and scale governance, risk, and compliance programs. This role involves using AI tools to streamline GRC workflows, automate control testing, and manage security risk. The ideal candidate will have deep technical security acumen, GRC expertise, and experience with industry frameworks. This is a strategic, cross-functional role focused on ensuring the security, privacy, and regulatory compliance of the organization's posture.

What you'd actually do

  1. Drive a compliance operating model that includes automated control testing, self-service reporting, and AI-enhanced risk analysis. Implement continuous control monitoring and evidence collection pipelines integrated into cloud-native and on-prem environments.
  2. Partner with engineering and product teams to define and codify security and compliance requirements as part of the SDLC. Introduce automated security/compliance tests into CI/CD pipelines to support shift-left practices.
  3. Use generative AI for compliance gap detection, policy mapping, risk triaging, and customer assurance functions.
  4. Oversee security and privacy assurance activities and assessments, internal/external audits, and attestation/certification initiatives (e.g., SOC 2, ISO 27001). Lead internal readiness for third-party audits and external assessments and maintain ongoing compliance posture.
  5. Utilize automation and GRC platforms to optimize gathering and maintenance of audit readiness documentation and audit evidence.

Skills

Required

  • Bachelor’s degree in computer science, Cybersecurity, or related engineering field
  • Minimum 5 years of progressive experience in cybersecurity, security engineering, and/or risk management
  • Proven success managing compliance programs in cloud-native, SaaS/PaaS environments with high automation maturity
  • Demonstrated ability to manage customer-facing compliance engagements and audit preparation
  • Deep knowledge of, and experience working with, industry frameworks (NIST SP800-53, ISO 27001, SOC 2, CCPA, GDPR, HIPAA)
  • Strong familiarity with AI/ML usage in security programs and risk analysis
  • Experience implementing and administering GRC tools/platforms
  • Proficiency in cloud security, AI security, secure development / DevSecOps practices, and infrastructure-as-code (IaC) security tooling
  • Experience implementing automated compliance and control validation pipelines
  • Excellent communication, stakeholder management, and executive reporting skills
  • Ability to influence cross-functional teams and operate in fast-paced, high-growth environments
  • Strong analytical, critical thinking, and decision-making capabilities

Nice to have

  • advanced degree preferred
  • Experience with designing and implementing autonomous “agentic AI” solutions

What the JD emphasized

  • Proficiency with AI tools (LLMs, prompt engineering, generative‑AI workflows) is a core requirement
  • Experience with designing and implementing autonomous “agentic AI” solutions is preferred
  • Deep knowledge of, and experience working with, industry frameworks (NIST SP800-53, ISO 27001, SOC 2, CCPA, GDPR, HIPAA)
  • Strong familiarity with AI/ML usage in security programs and risk analysis