Enter a job title or keyword

Security GRC Lead

Mercor


Job Location:

San Francisco, CA - USA

Yearly Salary: USD 350000 - 425000
Posted: 29 September 2026 (Yesterday)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Department:

Security

Job Summary

About Mercor

Mercors mission is to organize human intelligence to power the AI economy. Were a leading AI data company building the layer between human expertise and frontier models. Millions of domain experts on the platform are paid over $4 million per day to train frontier AI models. Mercors APEX benchmark family measures AIs real-world impact on professional work. Mercor Enterprise brings this same infrastructure to Fortune 500 companies: helping companies capture how their best people actually work translating that expertise directly back into agents.

Mercor is creating a new category of work where expertise powers AI advancement. Achieving this requires an ambitious fast-paced and deeply committed team. Youll work alongside researchers operators and AI companies at the forefront of shaping the systems that are redefining society. Mercor is a profitable Series C company valued at $10 billion. We work in-person five days a week in our San Francisco NYC or London offices.

Role Description

Youll be the first GRC hire at a company that processes some of the most sensitive data on earth: training data evals and human-feedback pipelines for the frontier AI labs plus payments and KYC for 300K experts.

This is not an audit-theater role. Youll own the operating cadence of a continuously-audited company: continuous SOC 2 monitoring the active ISO 27001 buildout an annual customer audit every quarter and a sub-48-hour questionnaire SLA. Youll write controls in code where it makes sense push back on tools that fight you and own the artifacts that close enterprise deals.

We use AI heavily in our own GRC work. You should be comfortable using LLMs to draft review and respond at speed. If youve ever copy-pasted the same answer into 14 vendor questionnaires by hand youll appreciate not having to.

Were in-person five days a week at our SF headquarters with first Fridays remote.

What Youll Build
  • The Mercor compliance operating cadence: SOC 2 Type 2 (continuous) ISO 27001 (standing up now) and the next two frameworks customers ask for (HIPAA FedRAMP Moderate EU AI Act conformity - your call on sequencing)

  • A customer-audit machine that responds tocustomers

  • The third-party risk program - formal intake recurring review cadence evidence requirements - tied into procurement so vendors cant be onboarded around it

  • Policy lifecycle owned end-to-end: version attestation exception handling review cycle - not a SharePoint graveyard

  • Controls-as-code where it makes sense: integrations policy packs rules tied to SOC 2 CC categories automated evidence collection

  • Data-handling procedures: the customer-data-deletion gap DSAR workflow KMS scheduled destruction offboarding handlers

  • The internal trust narrative: customer trust pages security one-pagers executive-ready disclosure templates when something goes sideways

What Were Looking For
  • 7 years in security GRC compliance engineering or audit with at least 2 years owning a SOC 2 Type 2 program end-to-end at a company under audit by enterprise customers

  • Youve shipped at least one ISO 27001 certification from kickoff to issued certificate including Stage 1 and Stage 2 with a real registrar

  • Fluent in Vanta (or Drata Secureframe Sprinto) at the integration and admin level not just the reviewer UI - youve configured connectors written custom tests debugged broken evidence

  • You translate cloud-security language to auditor language and back without losing precision - you can read a Wiz finding a Panther rule an IAM policy and say what control it maps to

  • You write controls as code or query evidence with SQL when the platform falls short - Python SQL or shell whatever it takes

  • You know the difference between we dont have a control for that and we have a compensating control and you dont fabricate the second one

  • Direct experience with the customer-trust surface: SIG CAIQ custom enterprise questionnaires on-site auditor sessions disclosure letters under legal review

Bonus Points
  • Built or operated a GRC program inside an AI lab ML platform or company serving frontier labs as customers

  • Familiar with AI-specific frameworks: NIST AI RMF EU AI Act conformity ISO 42001

  • Experience with FedRAMP Moderate HIPAA PCI DSS or SOC 2 HITRUST dual scope

  • Youve automated questionnaire response with an LLM and know where it works and where it fails

  • Prior experience standing up a third-party risk program from zero - vendor intake recurring review contract teeth

  • Written a public trust page that customers actually trust

Why Mercor
  • Build the function dont inherit it. This is the first GRC seat. You set the operating cadence pick the tools (were already on Vanta) define the rituals.

  • Compliance work that closes deals. Every audit you nail is a contract that signs. Youll see the revenue downstream of your work in the same week.

  • AI-native GRC. Youll use frontier models daily - evidence review questionnaire drafting control mapping - and have engineering support to build whatever tooling the off-the-shelf platforms wont.

  • Direct line to the auditor and the customer. No layers between you and the people who matter - the audit firm the customer security team our outside counsel. You own the relationship end-to-end.

  • A real security org behind you. TachTech (cloud) Latacora (MDR) Mandiant (IR) HackerOne (BB) are already running. Youre not building the security program from scratch - youre putting the governance and assurance layer on top of one that already ships.

Benefits
  • Bi-annual performance bonus structure

  • Generous equity grant vested over 4 years

  • Up to $15k Relocation bonus

  • $10K housing bonus (if you live within 0.5 miles of our office)

  • $1.5K monthly stipend for meals

  • Free Equinox membership

  • $200 monthly laundry reimbursement

  • $200 monthly personal wellness reimbursement

  • Health Dental Vision insurance


About Company

Company Logo

Find top-tier, remote, AI roles for your expertise. Available only on Mercor.

View Profile View Profile