Modal
Security GRC Specialist
New York
Sponsorship not specifiedDetected 92 days ago
AWSGCPAzureCloud PlatformsDevOpsCybersecurityComplianceSalesValuationCustomer SuccessCommunicationCollaboration
About the role
- GRC should enable the business, not slow it down
- The best candidates are technical, pragmatic, and collaborative
Responsibilities
- Own and operate compliance frameworks (e.g., SOC 2, ISO 27001, GDPR, etc.)
- Drive audits end-to-end: readiness, evidence collection, auditor coordination
- Lead responses to customer security questionnaires, RFPs, and due diligence requests
- Partner with Sales and Customer Success to unblock deals and build trust
- Develop and maintain security documentation (trust center, whitepapers, FAQs)
- Work directly with engineering teams to design and implement practical security controls
- Identify gaps and drive remediation projects (not just report them)
Requirements
- 3-7+ years in security GRC, compliance, or security engineering-adjacent roles
- Hands-on experience with frameworks like SOC 2, ISO 27001, or similar
- Experience supporting audits and customer-facing security conversations
- Ability to translate between compliance language and technical implementation
- Familiarity with automation in compliance workflows
Nice to have
- Experience with modern cloud environments (AWS/GCP/Azure) is a strong plus
Skills
- Continuously improve controls and reduce compliance overhead through automation
- Translate compliance requirements into technical, scalable solutions
- Run risk assessments across systems, vendors, and processes
- Track and report on security posture and compliance status
- Evaluate and implement GRC/security tools where appropriate
Company info
- AI needs a new infrastructure layer. We're building it at Modal.
- Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now.
- Our customers include category-defining companies like Lovable https://modal.com/blog/lovable-case-study, Ramp https://modal.com/blog/how-ramp-built-a-full-context-background-coding-agent-on-modal, Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale.
- We recently raised a $355M Series C https://modal.com/blog/modal-series-c at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September.
- AI needs a new infrastructure layer.
- We're building it at Modal.
- Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud.
- Each time, the company that rebuilt the layer underneath defined the decade.
- AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now.
- Our customers include category-defining companies like Lovable https://modal.com/blog/lovable-case-study, Ramp https://modal.com/blog/how-ramp-built-a-full-context-background-coding-agent-on-modal, Cognition, DoorDash, and Suno.
- They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale.
- We recently raised a $355M Series C https://modal.com/blog/modal-series-c at a $4.65B valuation, led by General Catalyst and Redpoint Ventures.
- We've crossed $300M+ ARR and grown fivefold since September.
- Our team includes creators of popular open-source projects (e.g.,Seaborn https://github.com/mwaskom/seaborn,Luigi https://github.com/spotify/luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience.
- We're looking for a hands-on Security GRC Specialist to own and scale our security and compliance programs while working closely with engineering and product teams.
- This role is central to building customer trust, enabling sales, and ensuring we meet evolving regulatory and security expectations without slowing down innovation.
- You won't just maintain compliance, you'll help shape how we build secure systems.
- Compliance & Security Programs
- Customer Trust & Sales Enablement
- Engineering Collaboration
- Risk & Governance
This listing is sourced directly from Modal's careers page and normalized into a canonical job model.