Security GRC Lead
Quick Summary
SOC 2 Type 2 (continuous), ISO 27001 (standing up now), and the next two frameworks customers ask for (HIPAA, FedRAMP Moderate,
version, attestation, exception handling, review cycle - not a SharePoint graveyard Controls-as-code where it makes sense: integrations, policy packs, rules tied to SOC 2 CC categories,
Mercor's mission is to organize human intelligence to power the AI economy. We're a leading AI data company, building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercor's APEX benchmark family measures AI's real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work, translating that expertise directly back into agents.
Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious, fast-paced and deeply committed team. You’ll work alongside researchers, operators, and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco, NYC, or London offices.
You'll be the first GRC hire at a company that processes some of the most sensitive data on earth: training data, evals, and human-feedback pipelines for the frontier AI labs, plus payments and KYC for 300K+ experts.
This is not an audit-theater role. You'll own the operating cadence of a continuously-audited company: continuous SOC 2 monitoring, the active ISO 27001 buildout, an annual customer audit every quarter, and a sub-48-hour questionnaire SLA. You'll write controls in code where it makes sense, push back on tools that fight you, and own the artifacts that close enterprise deals.
We use AI heavily in our own GRC work. You should be comfortable using LLMs to draft, review, and respond at speed. If you've ever copy-pasted the same answer into 14 vendor questionnaires by hand, you'll appreciate not having to.
We're in-person five days a week at our SF headquarters, with first Fridays remote.
The Mercor compliance operating cadence: SOC 2 Type 2 (continuous), ISO 27001 (standing up now), and the next two frameworks customers ask for (HIPAA, FedRAMP Moderate, EU AI Act conformity - your call on sequencing)
A customer-audit machine that responds tocustomers
The third-party risk program - formal intake, recurring review cadence, evidence requirements - tied into procurement so vendors can't be onboarded around it
Policy lifecycle owned end-to-end: version, attestation, exception handling, review cycle - not a SharePoint graveyard
Controls-as-code where it makes sense: integrations, policy packs, rules tied to SOC 2 CC categories, automated evidence collection
Data-handling procedures: the customer-data-deletion gap, DSAR workflow, KMS scheduled destruction, offboarding handlers
The internal trust narrative: customer trust pages, security one-pagers, executive-ready disclosure templates when something goes sideways
7+ years in security GRC, compliance engineering, or audit, with at least 2 years owning a SOC 2 Type 2 program end-to-end at a company under audit by enterprise customers
You've shipped at least one ISO 27001 certification from kickoff to issued certificate, including Stage 1 and Stage 2 with a real registrar
Fluent in Vanta (or Drata, Secureframe, Sprinto) at the integration and admin level, not just the reviewer UI - you've configured connectors, written custom tests, debugged broken evidence
You translate cloud-security language to auditor language and back without losing precision - you can read a Wiz finding, a Panther rule, an IAM policy, and say what control it maps to
You write controls as code or query evidence with SQL when the platform falls short - Python, SQL, or shell, whatever it takes
You know the difference between "we don't have a control for that" and "we have a compensating control" and you don't fabricate the second one
Direct experience with the customer-trust surface: SIG, CAIQ, custom enterprise questionnaires, on-site auditor sessions, disclosure letters under legal review
Nice to Have
~1 min readBuilt or operated a GRC program inside an AI lab, ML platform, or company serving frontier labs as customers
Familiar with AI-specific frameworks: NIST AI RMF, EU AI Act conformity, ISO 42001
Experience with FedRAMP Moderate, HIPAA, PCI DSS, or SOC 2 + HITRUST dual scope
You've automated questionnaire response with an LLM and know where it works and where it fails
Prior experience standing up a third-party risk program from zero - vendor intake, recurring review, contract teeth
Written a public trust page that customers actually trust
Build the function, don't inherit it. This is the first GRC seat. You set the operating cadence, pick the tools (we're already on Vanta), define the rituals.
Compliance work that closes deals. Every audit you nail is a contract that signs. You'll see the revenue downstream of your work in the same week.
AI-native GRC. You'll use frontier models daily - evidence review, questionnaire drafting, control mapping - and have engineering support to build whatever tooling the off-the-shelf platforms won't.
Direct line to the auditor and the customer. No layers between you and the people who matter - the audit firm, the customer security team, our outside counsel. You own the relationship end-to-end.
A real security org behind you. TachTech (cloud), Latacora (MDR), Mandiant (IR), HackerOne (BB) are already running. You're not building the security program from scratch - you're putting the governance and assurance layer on top of one that already ships.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- September 9, 2026
- First seen
- September 25, 2026
- Last seen
- September 26, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 43%
- Scored at
- September 25, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.