Senior AI Grc Engineer

Vanta Vanta · Enterprise · U.S. · Remote · Security

This role focuses on establishing and leading governance, risk, and compliance (GRC) initiatives for both internal AI adoption and customer-facing AI products. The Senior AI GRC Engineer will build and monitor scalable guardrails for AI, ensuring responsible and sustainable use, and will also work on automating GRC programs using AI agents and deterministic automation. The role involves partnering with various engineering teams and championing AI & GRC Engineering best practices.

What you'd actually do

  1. Drive Vanta’s internal AI governance programs (e.g., ISO 42001) while also evaluating new frameworks for Vanta to adopt
  2. Lead our cross-functional Hardening Enterprise AI Team (GRC Engineering, Corporate Engineering, Product Engineering, Security Engineering) in researching, implementing, and continuously monitoring scalable & compliant AI guardrails that optimally balance risk mitigation, compliance, and productivity
  3. Partner closely with the rest of GRC Engineering and other Vanta’ns to ensure AI governance, risk management, and compliance are baked into Vanta’s programs, projects, and SDLCs
  4. Champion sustainable AI usage across Vanta by being an early adopter and expert user of our AI tools and guardrails, regularly sharing best practices and use cases to foster responsible AI adoption across the company
  5. Scale & streamline our GRC programs by building agentic AI & deterministic automation

Skills

Required

  • Experience using AI agents, tools, and platforms to automate workflows and build tools, especially Anthropic products, OpenAI products, LangChain products, and/or Cursor
  • Experience using code and web APIs to automate workflows and build tools, especially with TypeScript, Go, and/or Python
  • Expertise in modern cloud-native web application development practices and related security best practices, especially in the context of AWS, containerized workloads, serverless architectures, and frontier AI platforms
  • Expertise in AI governance, risk, and compliance frameworks, such as ISO 42001, AIUC-1, EU AI Act, NIST AI RMF, UK AI Safety Framework, etc.
  • Experience with compliance programs for SOC 2, ISO 27001/17/18, ISO 27701, GDPR, etc.
  • Experience putting GRC Engineering principles and values into practice, especially control monitoring automation, systems & design thinking, and threat-informed GRC

Nice to have

  • prior security experience

What the JD emphasized

  • AI governance
  • AI guardrails
  • AI adoption
  • AI products
  • AI agents
  • AI tools
  • AI platforms
  • AI governance
  • risk management
  • compliance
  • AI & GRC Engineering best practices
  • AI agents
  • deterministic automation
  • AI governance
  • risk
  • compliance
  • AIUC-1
  • EU AI Act
  • NIST AI RMF
  • UK AI Safety Framework
  • SOC 2
  • ISO 27001
  • ISO 27701
  • GDPR
  • control monitoring automation
  • systems & design thinking
  • threat-informed GRC
  • AI
  • AI
  • AI

Other signals

  • AI governance
  • AI guardrails
  • AI adoption
  • AI products