Brainco

Brainco

GRC Lead

San Francisco Bay Area · Senior

Sponsorship not specified$171k-$800kDetected 61 days ago
DatabricksAzureTerraformRESTMachine LearningComplianceProject ManagementCadenceHIPAAPatient Care

About the role

  • At Brain Co., we focus on applying frontier AI to real institutional challenges, working alongside governments, healthcare systems, and critical industries to modernize how essential services operate.
  • Brain Co. carries one of the most demanding regulatory loads of any company our size: SOC 2 Type II and HIPAA in place today, with ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and US/MENA data residency on the near-term roadmap.
  • That's what selling to governments, hospitals, and financial institutions costs - and done right, it's how we win the next ones.

Responsibilities

  • Own evidence, controls, gap remediation, and audit response, and automate the evidence pipeline so we're not rebuilding workpapers every cycle.
  • As our GRC Lead, you'll own the governance, risk, and compliance program end-to-end - and treat it as a strategic advantage, not a checklist.
  • You'll define the principles, write the policies, run the audits, build the automation, and partner directly with engineering, legal, sales, and customer - not advising from the sidelines.
  • This is a high-ownership role for someone who has built programs like this before and wants to build the next one from first principles.
  • Own the end-to-end GRC program: SOC 2 Type II and HIPAA today, and the path through ISO 27001, NIST 800-171, FedRAMP/GovRAMP, GLBA, and MENA-specific regimes that don't map cleanly to a US playbook.
  • Build the data handling backbone: how customer data is classified, where it lives, who can touch it, and how we prove it - across Azure, on-prem MENA deployments, and the bespoke deployments we run for governments and hospitals.
  • Run audits as a builder, not a project manager: Own evidence, controls, gap remediation, and audit response, and automate the evidence pipeline so we're not rebuilding workpapers every cycle.
  • Build the GRC function for an AI platform deployed in governments, hospitals, and critical industries worldwide - where the regulatory bar is real and the work matters.
  • Own the program 0→1.
  • Define the principles, design the system, and grow the function under you as the company scales.

Nice to have

  • FedRAMP/GovRAMP, IL4/IL5, or equivalent government-customer compliance experience.
  • Standing up GRC programs at AI or ML-heavy companies, including the novel evidence and disclosure questions that come with model training data, agent actions, and customer data flowing through AI systems.
  • Hands-on with compliance automation tooling (Vanta, Drata, Secureframe, etc.) and a willingness to replace it when it's the wrong tool.
  • Comfort reading the technical controls themselves (Terraform, IAM policies, audit logs) well enough to verify what an auditor is being told.
  • Direct experience operating across US and MENA (or other multi-jurisdictional) regulatory environments, including on-prem and data residency requirements.

Compensation

  • Earn competitive compensation and meaningful equity in a high-growth company.

Benefits

  • Competitive salary plus equity
  • Commuter benefits
  • Medical, Dental, and Vision
  • Earn competitive compensation and meaningful equity in a high-growth company.
  • Streamlined hospital patient care across national health systems → 40% better outcomes, 80% less admin work

Company info

  • Raised a $55M Series A from leading investors
  • Built a team of 70+ AI experts from Tesla, Google DeepMind, NVIDIA, and Databricks
  • About Brain Co.
  • Brain Co. is an applied AI startup co-founded by Jared Kushner and Elad Gil, and backed by leading Silicon Valley builders including Patrick Collison and Andrej Karpathy.
  • We are building AI applications for the world's most important institutions, delivering impact on real-world problems across governments, healthcare systems, and critical industries.
  • Have 8+ years building and running GRC programs in regulated environments including healthcare, financial services, government, or enterprise SaaS where the stakes were real and the audits weren't theatre.
  • Have taken a company through SOC 2 Type II from a cold start, and lived HIPAA, GLBA, FedRAMP, or equivalent work hands-on, not just signed off on policies someone else wrote.
  • View compliance as a competitive advantage and a forcing function for good engineering, not a checklist and not a bureaucracy to defend.
  • We are looking for leaders who want to help bring new technology into institutions that impact millions of people.
  • You'll be an IC on day one with the scope and trust to grow the function as the company scales.
  • Be the translator between technical reality and regulatory expectations: the person engineers trust to interpret a control, and the person customers and auditors trust to explain the system behind it.
  • Build the customer-trust surface - security questionnaires, trust portal, DPAs, BAAs, customer-facing docs - so customers understand how we handle their data before they have to ask.

This listing is sourced directly from Brainco's careers page and normalized into a canonical job model.