
xAI · New York
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly m...
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of
knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who
appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are
expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and
consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have
strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
We are seeking an experienced and strategic Governance, Risk, and Compliance (GRC) team member as we expand into government and
public sector applications of AI. This critical role will ensure that SpaceXAI operates within regulatory, ethical, operational,
and federal boundaries while fostering a culture of integrity and resilience. You will collaborate with cross-functional teams to
safeguard our mission-driven work in AI development and deployment, including support for sensitive and classified environments.
IL5/IL6, NIST 800-53 rev 5, NIST 800-171/CMMC, Risk Management Framework).
certifications, reports, and Authorized to Operate (ATO) status.
and cloud deployments.
Action and Milestones (POAMs), and STIGs.
throughout the project lifecycle.
collaboration, and control implementation.
products/changes/features, and process enhancements.
requirements, and technologies in the AI landscape.
credibility.
technical risks for leadership.
engagements.
technology, cloud, or AI-driven environment.
oversight, and taking projects from conception to launch.
communicating risks to leadership.
policies (including validation via ACAS and similar tools).
Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision,
and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other
discounts and perks.
resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to
obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.
SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
HEALTH CAN’T WAIT. Not for symptoms to get worse. Not for a six‑month appointment. Not for a system to catch up. But that’s exactly how healthcare works today. You wait, until you can’t. Alan exists to end the wait. Health is a universal right, and we believe this right can only become real when it’s coupled with prevention. We need to stop treating health as something we repair and start treating it as something we build, every day. It’s not solely a question of willpower. It’s the healthcare system itself that needs to work for everyone, in a sustainable way. So we are building the new standard in prevention insurance. Alan is the first company that integrates insurance, prevention, and care into a single, acclaimed user experience. We are on an incredible journey to build a global leading company, with a unique culture. We already partner with 40K+ companies of all sizes, serving more than 1M+ members, and have reached €800M+ in ARR. Prevention as the new norm. That's what we're building with our team of 800+ people. If it speaks to you: we're hiring across France, Spain, Belgium, and Canada. And beyond. Alan operates at the intersection of health insurance, prevention, and regulated data. The person in this role owns the security governance and risk posture of a company that handles sensitive health data for 1M+ members, operates under DORA and HDS certification requirements, and is regulated by the ACPR. They work in close partnership with Legal, Internal Audit, and the broader Risk function. It's a highly collaborative role. 🛡️ YOUR MISSION: GOVERNANCE, RISK & COMPLIANCE Own and operate the ISO 27001 ISMS. You are the accountable owner of the Information Security Management System: scope definition, Statement of Applicability, internal audit programme, and management review. You've led at least one full certification or recertification cycle and know what breaks down in the months between audits. Be the security expert on regulatory and privacy matters. Legal leads on DORA, HDS, RGPD, PGSSI-S, and regulatory relationships. Your role is to bring the technical and operational security substance: translating regulatory requirements into controls, flagging implementation gaps, and making sure the security programme is solid when the regulatory team negotiates with the ACPR or ANS. Run risk as an ongoing programme, in partnership with the broader risk function. You lead security risk cartography using EBIOS RM and ensure it feeds into, and is informed by, the company-wide risk framework. You facilitate risk workshops, produce treatment plans, and bring the security lens to forums where non-security risks are also on the table. You know when a security risk is really a business risk. Own the controls framework, but distribute ownership of controls themselves. You define the framework, set the standards, and track coverage, but the controls live with the teams who build and run the things they protect. You work closely with Infrastructure, Platform, and Engineering to ensure foundational building blocks (identity, network, secrets management, logging) are designed with security requirements built in from the start. You work alongside those teams as a partner. Run audit cycles with rigour, in close partnership with Internal Audit. You manage the security audit programme and coordinate with certification bodies. You work with Internal Audit to align scopes, avoid duplication, and present a coherent picture of control effectiveness to the board. You've sat in joint audit planning sessions and know how to make that relationship work well. Manage third-party risk. You run vendor security assessments and define contractual security requirements (security annexes, DPAs). You partner with our Risk team, which oversees third-party risk, and own the security dimension. Bring the health sector context. You understand the ANS framework, CERT Santé requirements, and what it means to handle sensitive health data in day-to-day operations. You're a useful partner to Legal when the question is "what does this regulation actually require us to do technically?" Own incident governance and support DORA reporting. You classify and escalate ICT incidents internally, own BCP and DRP governance, and provide the security substance for DORA incident reports. 🚀 WHAT YOU'LL BUILD AND WHO YOU'LL WORK WITH Compliance Framework: ISO 27001, DORA, HDS, NIS2. Multiple regulators, multiple countries, one coherent governance backbone. Build the system that lets Alan scale from 1M to many millions of members without rebuilding compliance every time. Automated Audit & Evidence Engine: Replace manual evidence collection with scripted pipelines plugged directly into engineering systems. Turn audit cycles into a continuous capability instead of a quarterly rush. Risk Cartography: Risk treated as an operational signal that feeds directly into business and engineering decisions, with EBIOS RM at the core. You'll work closely with Legal, DPO, Internal Audit, and the broader Risk function, and partner day-to-day with Infrastructure, Platform, Engineering, Product, and Operations. You're the bridge between regulatory complexity and operational simplicity. ⚡ WHY THIS ROLE IS SPECIAL Direct Impact: You own the trust foundation that lets Alan handle health data for 1M+ members and operate in highly regulated markets. Your work is the precondition for everything else Alan does. Complex Problems: 4 regulators across 4 countries, sensitive health data, and a regulatory landscape that keeps shifting (DORA, NIS2, AI Act), all to be modeled into a single, coherent control system. Ownership & Growth: Board and executive exposure, real influence on company-wide risk decisions, and the autonomy to shape Alan's security culture across 800+ people. 🤝 WHAT YOU WILL ALSO DO: TECHNICAL ENABLEMENT Automate compliance work wherever possible. You script evidence collection, automate control testing, and connect GRC tooling to engineering pipelines. You've used Python or similar to reduce the manual work of an audit cycle, and you actively look for the next process to streamline. Configure and own GRC tooling. You can administer platforms like CISO Assistant, ServiceNow GRC, or Archer, designing workflows, building dashboards, and making them genuinely useful for the teams that feed them data. Speak cloud governance fluently. You understand shared responsibility in HDS-qualified environments, know what CSPM tools surface and what they miss, and can reason about policy-as-code (OPA, SCP) without needing an engineer to translate. Read architecture well enough to challenge it. You can review a proposed architecture, identify control gaps in identity, network segmentation, encryption, or logging, and push back credibly with engineers even though you're not one. Interpret vulnerability data and drive prioritisation. You read scan outputs, work with engineering teams to prioritise remediation by business impact over CVSS score alone, and track resolution KPIs over time. ⭐️ QUALIFICATIONS, MINDSET AND SOFT SKILLS You translate risk into business language. You can brief a board or an audit committee and leave them genuinely informed. You know the difference between a finding that requires an emergency board call and one that belongs in a quarterly report. You influence without authority. You align Legal, DPO, Risk, Engineering, Product, and Operations on security requirements without creating blockers or adversarial dynamics. People come to you early because you make their work easier. You manage programmes with audit-grade rigor. You run structured, traceable roadmaps. You know where every commitment is, who owns it, and when it's due. You escalate proactively and don't let dependencies surprise you. You build a genuine security culture. Your awareness programmes land because they're relevant to the people who take them. You foster proportionate risk ownership across the company, so teams make better day-to-day decisions. You think in principles when frameworks shift. DORA is live. NIS2 transposition pace varies. The AI Act is arriving. When the regulatory landscape moves, you reason from first principles and adapt without waiting to be told what to do. 🌍 HOW WE WORK Location: You must be legally eligible to work from France. Remote work: We offer remote work flexibility, but we value in-person collaboration 🎯 IMPORTANT NOTE: WE HIRE PEOPLE, NOT ROLES. If you're excited about this opportunity but don't check every box, we'd love to hear from you. Everyone, no matter how underrepresented, should feel free to apply, as it can only bring learnings or success. If you identify yourself as a woman: Did you know that research shows women often apply only when meeting 100% of requirements? Remember, this is just a guide, not a checklist. We'll be thrilled to receive your application! 🔖 Check out our About Alan and Career pages, as well as our Medium, blog and Glassdoor page for more info. YOU WANT TO KNOW MORE ABOUT ALAN? 🙌 Perks & Benefits: Alaners are provided with a stimulating environment and perks ensuring they are happy, efficient and spend only high-quality time with co-workers. 🤘A strong culture: People joining Alan are often surprised and delighted by our innovative working method. We have a set of cultural values that guide our approach to work
ABOUT BUREAU Bureau is a unified risk decisioning platform for Compliance, Fraud, and Transaction risks. Our platform is a single decision-making engine, powered by a 1 billion+ identity knowledge graph. Over 150 Banks, fintechs, retailers, and digital platforms use Bureau to verify identities faster and stop fraud earlier globally. Bureau has raised $50M+ from renowned Silicon Valley and global investors including Sorenson Capital and PayPal Ventures and is expanding rapidly from APAC to Americas, Europe, and beyond. WHY BUREAU? Bureau is building the infrastructure that makes digital identities and transactions safe and trustworthy for billions of people. The mission is big, the problems are complex, and the impact is real. We hire people who want that level of responsibility. People who move fast, build systems from scratch, and care deeply about turning strategy into execution. If you want predictability or narrow scope, this won't be your place. If you want to shape how a scaling global company operates—keep reading. ABOUT THE ROLE - INFORMATION SECURITY ENGINEER We are looking for a Security Engineer who can own both the hands-on technical security stack and our governance/compliance programs. What you’ll be doing In this role, you will: * Harden and monitor our cloud & container infrastructure (AWS/EKS, endpoints, network). * Run vulnerability management, security tooling and incident response. * Help maintain our ISMS and support audits (ISO 27001, SOC 2, RBI, DPDP, etc.). This is ideal for someone who doesn’t want to be only “checklist GRC” or only “pure blue-team”, but wants a blended role across security engineering + GRC.Key Responsibilities 1. Cloud & Infrastructure Security (Hands-on) * Work with DevOps to secure our AWS/EKS environment: * IAM hardening, security groups, VPC, KMS, S3, RDS, etc. * Review infra-as-code (Terraform/Helm) for security issues and misconfigurations. * Own or co-own key security tools: * Endpoint / EDR (e.g., CrowdStrike / SentinelOne), * Cloud security (CSPM / CNAPP, GuardDuty, Security Hub, WAF, etc.), * Container / runtime security where applicable. * Implement and maintain logging & monitoring for security events (CloudTrail, ALB/NLB logs, K8s logs, etc.), and integrate them with SIEM / alerting. 2. Vulnerability Management & Security Operations * Own the vulnerability management lifecycle: * Run periodic scans for cloud, endpoints, containers and apps. * Triage findings, prioritise based on risk, and drive closure with engineering. * Coordinate external pentests / bug bounties and track remediation. * Support incident response: * Help investigate alerts, gather evidence, and contribute to RCA and CAPA. * Maintain and update incident runbooks. 3. Governance, Risk & Compliance (ISMS, Audits, DPDP) * Maintain and enhance the Information Security Management System (ISMS): * Policies, procedures, SoA, risk register, control evidence and audit trails. * Support internal and external audits: ISO 27001, SOC 2, RBI/CERT-In, Data Protection. * Prepare and manage audit evidence, observations, closure reports and certification documentation. * Assist with risk assessments: * Maintain the risk register, risk treatment plans and residual risk reviews. * Conduct vendor security due diligence and maintain vendor security records (MSA, NDA, DPA, DPIA, etc.). * Support privacy & regulatory compliance operations (GDPR/DPDP basics: retention, consent, grievance logging). 4. Access, Asset & Control Assurance * Participate in and help automate access reviews, asset inventory checks, and configuration compliance checks. * Track control performance (vuln SLAs, access reviews, backup tests, etc.) and ensure gaps are documented and closed. * Maintain security awareness and training trackers (onboarding, annual refreshers, phishing simulations). What You’ll Bring * Bachelor’s degree in Computer Science, IT, Cybersecurity or related discipline. * ~4 years of experience in security engineering, cloud security, or GRC/compliance (any mix, but must be comfortable hands-on). * Good understanding of: * Security engineering fundamentals: Linux, networking, IAM, encryption, least privilege. * Cloud platforms (AWS preferred; GCP/Azure a plus) and their security services. * Core frameworks: ISO 27001, SOC 2, basic risk management and audit lifecycle. * Comfortable with: * Writing/debugging basic scripts (Bash/Python) for automation and data extraction. * Tools like Jira, Confluence, Excel/Sheets and at least one GRC / security platform (e.g., Scrut/Drata/Secureframe, etc.). * Strong documentation skills and ability to talk to both engineers and non-technical stakeholders. Preferred (Good to Have) / Willing to Learn * Cloud security certifications (e.g., AWS Security / AWS Cloud Practitioner). * ISO 27001:2022 Lead Auditor/Implementer, CompTIA Security+, ISC2 CC. * Experience with: * EDR/XDR tools, * CSPM/CNAPP (e.g., Wiz, Prisma, Defender for Cloud), * SIEM, WAF, runtime/container security (Falco, etc.). * Exposure to GDPR/DPDP or other data protection regimes. Who You Are * You enjoy both: * Getting your hands dirty in logs, configs and cloud consoles, and * Keeping things clean in policies, risk registers and audit trackers. * You’re structured and process-oriented, but still pragmatic and capable of shipping improvements. * You’re comfortable collaborating with DevOps, backend, data, HR and legal to get security actually implemented, not just written down. * You want to grow into either Security Engineering leadership (owning tools/architecture) or GRC leadership (owning audits and certifications) over the next few years. OUR CULTURE * We hire self-motivated people and get out of their way * We value performance, not hours worked * Speed, ownership, and impact matter most COMPENSATION * Competitive salary + potential equity * Health benefits, flexible PTO, learning budget
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: * You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. * You will: * Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute within it. * Build the foundation the function runs on — a codified source of truth for controls, policies, and evidence, fed by live pipelines and continuous controls monitoring. * Be the engineering backbone for Security Assurance & Trust Enablement, Third-Party Ecosystem Risk, and Risk Management * Make risk visible and data-driven — turning control and risk data into real-time signals for the team and leadership. * Pioneer where compliance is heading — compliance-agents-as-code in the SDLC, AI- and agent-driven workflows, and machine-readable continuous compliance (FedRAMP 20x). * This role is perfect for you if: * You think in systems: you'd rather design the thing that eliminates a whole class of manual work than automate one task at a time. * You love building and shipping internal tools and solutions that people actually use. * You're relentlessly curious — you poke, you investigate, and you dig into how controls can silently fail, drift, or get bypassed so you can catch it automatically. * You treat every roadblock as just an obstacle to route around — you don't back down, because there's always a path. * You like range — juggling several problems across security, risk, compliance, and engineering beats grinding on a single one. * You're energized by turning compliance from a documentation exercise into demonstrable, continuous, machine-readable evidence. Responsibilities: * Architect GRC's Engineering Foundation: Build the pipelines and codified source of truth the function runs on — controls, policies, and framework mappings captured as structured, version-controlled data and fed by live control and system state — so one control maps evidence across SOC 2, ISO, NIST, and beyond instead of being re-collected for every audit. * Build Continuous Controls Monitoring: Automate evidence collection, control testing, and monitoring across cloud and internal systems, and write and tune the detection that flags drift and misconfiguration against baseline — so audit readiness is continuous and gaps surface the moment they appear, not at audit time. * Turn Data into Risk Signal: Build dashboards and SQL-driven reporting that turn raw control and risk data into KPIs, giving the team and leadership real-time visibility into risk posture. * Drive Data-Informed Risk Assessments: Conduct security and technology risk assessments and recommend mitigations using data — keeping the risk management program running while cutting its manual overhead. * Automate Operational Toil: Eliminate the recurring manual work the team carries — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reporting — with durable automation that gives time back across every workstream. * Shift Compliance Left with Code and AI: Embed compliance checks into the CI/CD flow as policy-as-code so controls are validated as code ships, prototype self-healing policies reconciled against live infrastructure, and scale agentic / AI-assisted workflows across the function. * Future-proof for Continuous Compliance: Build toward machine-readable, continuously validated evidence (FedRAMP 20x-style Key Security Indicators), positioning Plaid to meet continuous-compliance expectations as we enter new markets and pursue new authorizations. Qualifications: * Software & Data Engineering Foundations: * Strong Python and SQL, with a proven track record of building API/webhook integrations that connect disparate systems. * Experience owning an internal tool or service end to end — design, build, operate, and maintain — with real users depending on it. * Hands-on experience with AWS and cloud-native security controls, including the ability to query cloud, GitHub, and SaaS logs. * Proficiency with dashboarding / data-visualization tools (e.g., Mode) to turn control and risk data into KPIs and signal. * Applied GRC Engineering: * Experience building and operating continuous controls monitoring end to end — collecting signal from live systems, writing and tuning the detection logic that compares state to a baseline, alerting, and driving remediation. * Demonstrated ability to model controls, policies, and framework mappings as structured, version-controlled data rather than docs and spreadsheets. * Hands-on experience with IaC (Terraform) and policy-as-code (OPA/Rego, Sentinel), including embedding compliance checks into CI/CD. * Proven ability to eliminate recurring operational toil — evidence pulls, access and vendor reviews, questionnaires, risk-register upkeep, status reports — with durable automation rather than one-off scripts. * Compliance & risk knowledge: * Working knowledge of SOC 2, ISO 27001/27701, and NIST CSF/800-53, with the ability to map controls to evidence and crosswalk a single control across frameworks. * Experience conducting security or technology risk assessments and translating findings into data-driven mitigation. * Familiarity with the shift to continuous compliance (FedRAMP 20x, machine-readable Key Security Indicators) and how it changes evidence and control design. * AI fluency & tooling: * Demonstrated ability to build and scale agentic / AI-assisted workflows (Claude, OpenAI) as leverage for the whole team. * Cross-functional effectiveness: * Ability to work independently and cross-functionally across security, infrastructure, and engineering, with strong prioritization and the ability to influence without authority. Nice to have: * Direct experience with FedRAMP or FedRAMP 20x, or other public-sector / continuous-compliance authorizations. * Experience with audit ›/ compliance automation platforms (Anecdotes, Drata, Vanta, Paramify, or similar). * Exposure to security incident response and triage. * Experience in a high-growth fintech or financial-services environment. * Degree in Computer Science, Cybersecurity, or a related field. Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid! Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com. Please review our Candidate Privacy Notice here. Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.