Skip to content
The board
JobStartup
ProductEngineering

GRC Program Manager, US Government Compliance

OpenAI · Security

Pay
$162K – $310K • Offers Equity
Where
Washington, DC
Posted
Apr 23

Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture.

Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector.

What you'd do

  • Drive the ATO process for FedRAMP and across multiple government clients in restricted environments with minimal oversight.
  • Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.
  • Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.
  • Act as a subject matter expert during audits and assessments, representing the organization with credibility and expertise.
  • Continuously refine processes to improve the efficiency and quality of compliance efforts.
  • An active US security clearance.
  • 5+ years of compliance experience in positions involving information security, data security, or infrastructure or network security.
  • Familiarity with deployment models, including to cloud platforms (Azure, AWS) and the underlying infrastructure primitives (Kubernetes, Terraform).
  • Strong familiarity with core security concepts and technologies, such as authentication, encryption, vulnerability management, and audit logging.
  • The ability to work collaboratively and effectively in a cross-functional team environment.