GRC Manager
Build and maintain security governance frameworks aligned with industry best practices
Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices. Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks. Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations.
Why This Role?
Play a key role in ensuring the platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance
Key Responsibilities
- Design, implement, and maintain security governance frameworks, policies, and procedures
- Build and manage the company-wide risk assessment program
- Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards
- Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed
- Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards
- Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical pro
Requirements
- Experience building, supporting, and enhancing security governance, compliance, and privacy programs
- Experience working cross-functionally with engineering, operations, legal, and leadership teams
- Experience developing policies, managing audits, and implementing controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and
- Experience building scalable processes to manage risk, support customer assurance, and uphold commitment to security and compliance
Required Skills
Keywords
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
ABOUT BASETEN Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F https://www.baseten.co/blog/announcing-our-series-f/, led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products. THE ROLE We are seeking an experienced and detail-oriented GRC (Governance, Risk, and Compliance) Manager to build, support, and continuously enhance Baseten’s security governance, compliance, and privacy programs. As one of the early members of our security organization, you will play a key role in ensuring our platform meets and exceeds the highest standards for privacy, trust, and regulatory compliance. In this role, you’ll work cross-functionally with engineering, operations, legal, and leadership teams to develop policies, manage audits, and implement controls aligned with frameworks such as SOC 2, ISO 27001, ISO 27701, and FedRAMP. You’ll be instrumental in building scalable processes to manage risk, support customer assurance, and uphold Baseten’s commitment to security and compliance as we grow. RESPONSIBILITIES - Governance & Policy Development: Design, implement, and maintain security governance frameworks, policies, and procedures that align with Baseten’s risk posture and industry best practices. - Risk Management: Build and manage the company-wide risk assessment program, identifying, tracking, and mitigating key security and compliance risks. - Compliance Operations: Lead efforts to achieve and maintain compliance with SOC 2, ISO 27001/27701, HIPAA, FedRAMP and other applicable standards and regulations. - Audit & Certification Management: Coordinate external audits and certification processes, ensuring evidence collection, control validation, and remediation plans are executed efficiently. - Third-Party Risk Management: Oversee vendor security assessments and ensure third-party providers meet Baseten’s security and compliance standards. - Cross-Functional Collaboration: Partner with Engineering, Product, and Operations teams to embed compliance and risk management into day-to-day operations and technical processes. - Customer Trust & Assurance: Support customer security questionnaires, due diligence efforts, and documentation requests from prospective and existing clients. - Training & Awareness: Develop and deliver security and compliance training to ensure company-wide understanding of key policies and responsibilities. - Continuous Improvement: Stay current on evolving regulatory requirements and lead initiatives to mature our compliance and risk management programs. REQUIREMENTS - 5+ years of experience in GRC, Security Compliance, or Information Security roles, ideally in a SaaS or cloud-native environment. - Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, NIST, and GDPR. - Proven track record managing compliance audits and certification programs end-to-end. - Experience with access management concepts, third-party risk - Experience working cross-functionally with technical and non-technical stakeholders to implement compliance and security controls. - Excellent organizational, documentation, and communication skills with attention to detail. - Ability to thrive in a fast-paced, high-growth startup environment while maintaining structure and process discipline. NICE TO HAVE - Experience with cloud security compliance in AWS or GCP environments. - Hands-on experience using GRC tools (e.g., Vanta, Drata, Secureframe, Anecdotes). - Understanding of AI/ML security considerations, data privacy, and model governance. - Previous experience building and scaling compliance programs in an early-stage or rapidly growing startup. - Relevant certifications (e.g., CISA, CISSP, CISM, ISO 27001 Lead Implementer). BENEFITS - Competitive compensation, including meaningful equity. - 100% coverage of medical, dental, and vision insurance for employee and dependents - Flexible PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!) - Paid parental leave - Fertility and family-building stipend through Carrot - Company-facilitated 401(k) - Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities. Apply now to embark on a rewarding journey in shaping the future of AI! If you are a motivated individual with a passion for machine learning and a desire to be part of a collaborative and forward-thinking team, we would love to hear from you. At Baseten, we are committed to fostering a diverse and inclusive workplace. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example, the requirements of the San Francisco Fair Chance Ordinance, where applicable).
Salary Context
Similar Engineering roles on LokerDollar pay around $215k/yr (range $19.575k–2745.996k/yr, n=409 active listings).
Hiring at Baseten
Baseten has 27 other active roles on LokerDollar and has been hiring here since Jun 23, 2026 — across Engineering.
View all Baseten openings →Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
Frequently asked questions
- Is GRC Manager at Baseten a remote job?
- This role is based in Remote. See the listing for remote/onsite details.
- What is the salary for GRC Manager at Baseten?
- The listed pay range for this role is $150k–250k/yr.
- What type of employment is GRC Manager at Baseten?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at Baseten.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- 10 Remote Jobs Nobody Wants (Yet!)Are there remote openings with few applicants? We'll show you 10 high-demand, low-supply positions – and why your skills might be a perfect fit.
- Remote USD Jobs in July 2026: Top OpeningsDiscover the latest remote USD job openings for July 2026, featuring top companies like Tailor, Vanta, and Kyndryl, with salaries up to $166,000 per year.
- Remote Freelance Jobs June 2026: Trends & PayA global look at seven new remote freelance gigs, pay ranges, a contrarian take, and practical tips for landing USD‑paid work.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume