Grc Specialist

Cohere Cohere · AI Frontier · Toronto, ON · Product

Cohere is seeking a GRC Specialist to build and scale compliance programs, controls, and processes, with a focus on AI governance and public sector readiness. This role involves partnering with cross-functional teams, improving operations through automation and tooling, and supporting audits. The ideal candidate has experience with multiple compliance frameworks, technical fluency, and scripting for automation.

What you'd actually do

  1. Build, implement, and scale compliance programs, controls, and processes across frameworks and regulatory requirements including SOC 2, ISO 27001, HIPAA, ISO 42001, Product Compliance, and FedRAMP/DoD (+others)
  2. Support and mature compliance efforts related AI governance including work aligned to ISO 42001 and the EU AI Act
  3. Drive compliance readiness for FedRAMP, DoD, and related public sector requirements, while supporting broader enterprise and customer-facing compliance obligations
  4. Partner with Security, Engineering, Modeling, Product, Legal, and other cross-functional teams to translate requirements into practical, scalable controls
  5. Improve compliance operations through automation, tooling, and scalable workflows

Skills

Required

  • Building and scaling compliance programs across multiple frameworks and regulatory requirements, including SOC 2, ISO 27001, HIPAA, with extensive experience in FedRAMP, DoD, and public sector or highly regulated environments
  • AI governance and frameworks such as ISO 42001
  • Strong project management and cross-functional execution skills
  • Technical fluency and comfort working with Engineering and Security teams
  • Automation, workflow tooling, or process design

Nice to have

  • Experience designing and implementing mature risk management frameworks, including FAIR, quantitative risk methodologies, and other structured enterprise risk models
  • Consulting experience in regulated environments, including multi-jurisdictional compliance programs and regulatory requirements across the U.S. and international markets
  • Experience with additional frameworks such as NIST CSF, NIST RMF, NIST AI RMF, CMMC, or similar standards
  • Experience working in cloud-native, SaaS, or highly technical product environments
  • Experience preparing reports, metrics, and presentations for senior leadership, including communicating compliance posture, program progress, and risk insights to executive stakeholders.
  • Python or similar scripting for lightweight automation

What the JD emphasized

  • FedRAMP
  • DoD
  • public sector
  • AI governance
  • ISO 42001
  • EU AI Act
  • HIPAA
  • SOC 2
  • ISO 27001