Brainco
GRC Lead
San Francisco Bay Area · Senior
Sponsorship not specified$171k-$800kDetected 61 days ago
DatabricksAzureTerraformRESTMachine LearningComplianceProject ManagementCadenceHIPAAPatient Care
About the role
- At Brain Co., we focus on applying frontier AI to real institutional challenges, working alongside governments, healthcare systems, and critical industries to modernize how essential services operate.
- Brain Co. carries one of the most demanding regulatory loads of any company our size: SOC 2 Type II and HIPAA in place today, with ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and US/MENA data residency on the near-term roadmap.
- That's what selling to governments, hospitals, and financial institutions costs - and done right, it's how we win the next ones.
Responsibilities
- Own evidence, controls, gap remediation, and audit response, and automate the evidence pipeline so we're not rebuilding workpapers every cycle.
- As our GRC Lead, you'll own the governance, risk, and compliance program end-to-end - and treat it as a strategic advantage, not a checklist.
- You'll define the principles, write the policies, run the audits, build the automation, and partner directly with engineering, legal, sales, and customer - not advising from the sidelines.
- This is a high-ownership role for someone who has built programs like this before and wants to build the next one from first principles.
- Own the end-to-end GRC program: SOC 2 Type II and HIPAA today, and the path through ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and MENA-specific regimes that don't map cleanly to a US playbook.
- Build the data handling backbone: how customer data is classified, where it lives, who can touch it, and how we prove it - across Azure, on-prem MENA deployments, and the bespoke deployments we run for governments and hospitals.
- Run audits as a builder, not a project manager: Own evidence, controls, gap remediation, and audit response, and automate the evidence pipeline so we're not rebuilding workpapers every cycle.
- Build the GRC function for an AI platform deployed in governments, hospitals, and critical industries worldwide - where the regulatory bar is real and the work matters.
- Own the program 0→1.
- Define the principles, design the system, and grow the function under you as the company scales.
Nice to have
- FedRAMP/GovRAMP, IL4/IL5, or equivalent government-customer compliance experience.
- Standing up GRC programs at AI or ML-heavy companies, including the novel evidence and disclosure questions that come with model training data, agent actions, and customer data flowing through AI systems.
- Hands-on with compliance automation tooling (Vanta, Drata, Secureframe, etc.) and a willingness to replace it when it's the wrong tool.
- Comfort reading the technical controls themselves (Terraform, IAM policies, audit logs) well enough to verify what an auditor is being told.
- Direct experience operating across US and MENA (or other multi-jurisdictional) regulatory environments, including on-prem and data residency requirements.
Compensation
- Earn competitive compensation and meaningful equity in a high-growth company.
Benefits
- Competitive salary plus equity
- Commuter benefits
- Medical, Dental, and Vision
- Earn competitive compensation and meaningful equity in a high-growth company.
- Streamlined hospital patient care across national health systems → 40% better outcomes, 80% less admin work
Company info
- Raised a $55M Series A from leading investors
- Built a team of 70+ AI experts from Tesla, Google DeepMind, NVIDIA, and Databricks
- About Brain Co.
- Brain Co. is an applied AI startup co-founded by Jared Kushner and Elad Gil, and backed by leading Silicon Valley builders including Patrick Collison and Andrej Karpathy.
- We are building AI applications for the world's most important institutions, delivering impact on real-world problems across governments, healthcare systems, and critical industries.
- Have 8+ years building and running GRC programs in regulated environments including healthcare, financial services, government, or enterprise SaaS where the stakes were real and the audits weren't theatre.
- Have taken a company through SOC 2 Type II from a cold start, and lived HIPAA, GLBA, FedRAMP, or equivalent work hands-on, not just signed off on policies someone else wrote.
- View compliance as a competitive advantage and a forcing function for good engineering, not a checklist and not a bureaucracy to defend.
- We are looking for leaders who want to help bring new technology into institutions that impact millions of people.
- You'll be an IC on day one with the scope and trust to grow the function as the company scales.
- Be the translator between technical reality and regulatory expectations: the person engineers trust to interpret a control, and the person customers and auditors trust to explain the system behind it.
- Build the customer-trust surface - security questionnaires, trust portal, DPAs, BAAs, customer-facing docs - so customers understand how we handle their data before they have to ask.
Apply directly at Brainco →Create a free account for alerts like thisView Brainco immigration profile
This listing is sourced directly from Brainco's careers page and normalized into a canonical job model.