GRC Manager
Baseten · San Francisco, CA · 1 wk ago
HybridOTHR$150k–$250k/yrFull-time
Responsibilities
- Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices.
- Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks.
- Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations.
- Care for coordination of external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently.
- Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards.
- Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes.
- Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients.
- Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities.
- Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs.
Requirements
- 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment.
- Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR.
- Proven track record managing compliance audits and certification programs end-to-end.
- Experience with access management concepts, third-party risk.
- Experience working cross-functionally with technical and non-technical stakeholders to implement compliance and security controls.
- Excellent organizational, documentation, and communication skills with attention to detail.
- Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline.
Nice to Have
- Experience with cloud security compliance in AWS or GCP environments.
- Hands-on experience using GRC tools (e.g., Vanta, Drata, Secureframe, Anecdotes).
- Understanding of AI/ML security considerations, data privacy, and model governance.
- Previous experience building and scaling compliance programs in an early-stage or rapidly growing startup.
- Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer).