This role is responsible for developing and maintaining compliance policies, coordinating and managing internal and external audits, conducting risk assessments……
Background in UX research, testing, and front-end graphic design. Bachelor’s degree in Cybersecurity, Information Systems, Business, or a related field.…
Demonstrated ability to translate technical risk into business impact and action. Reviewing the enterprise risk register, identifying where risks are aging,……
They’ll leverage a technical understanding of cloud environments and aim to implement automation across FedRAMP and other government ecosystems.…
You’ll be instrumental in driving a pragmatic, risk-driven, and scalable GRC program with a strong emphasis on modern, engineering first approaches.…
BBH's total rewards package recognizes your contributions with more than just a paycheck—providing you with benefits that enhance your experience at BBH from……
Oversee completion of the FFIEC Cybersecurity Assessment Tool (CAT) or equivalent framework; conduct technology and security risk assessments; and provide……
Hire, mentor, and develop a team of SMEs covering commercial frameworks, government frameworks, test authoring, framework quality uplift, and framework……
Collaborate with BISOs, third-party assessors and stakeholders to schedule gap assessment interviews, attend gap assessment and certification assessment……
Coach, mentor, and develop Product Managers on your teams, providing guidance on product strategy, execution, stakeholder management, and career growth.…
Minimum 3 years of leading implementing and/or assessing: Information technology audit, Information Technology General Controls (ITGC), Information security……
You’ll partner closely with engineering, business operations, and our go-to-market teams to develop a world-class GRC function empowered by automation,……
The GPM for Governance, Risk, & Compliance (GRC) is responsible for ensuring the products they own deliver meaningful customer outcomes and contribute to……
The ideal candidate brings 3–5 years of privacy program experience in a consumer-facing technology environment, has operationalized privacy compliance from the……
Oversee state licensing programs for lending and money transmission activities, including license maintenance, renewals, reporting obligations, examinations,……
Bachelor’s degree in business, finance, risk management, information technology or related field. Master’s degree in business administration, finance, risk……
Ability to translate technical security issues into clear risk‑based explanations for non‑technical audiences. Post‑incident reporting and lessons learned.…
Proven ability to lead risk reduction or remediation initiatives across multiple technical teams . Experience developing executive reporting, metrics, risk……
Operate as a second line of defense function, providing independent oversight, challenge, and guidance to first line teams without owning controls or delivery……
Support strategic customer trust needs, including security questionnaires, customer calls, Trust Center updates, and high-priority deal support.…
The Risk & Controls Project Manager leads cross-functional initiatives to define, implement, and sustain risk and control policies across technology domains—……
[Required] Bachelor's degree, preferably in a technical discipline (Computer Science, Mathematics, Engineering, or related field), or equivalent combination of……
Enable consistent operational execution of privacy requirements through governance mechanisms (e.g., records of processing support, data retention/deletion……
INCIDENT & REQUEST MANAGEMENT: Reviews, analyzes and prioritizes incoming incident tickets and user requests. SAP SECURITY APPLICATION DEVELOPMENT & DEPLOYMENT:……
Demonstrated ability to develop risk appetite statements, KRI/KPIs, and enterprise-level risk reporting. Experience in SAS, SQL, SPSS, Tableau or other data……
Ability to communicate effectively with both technical and operational stakeholders. This role will focus on supporting a critical security plan initiative by……
Bachelor’s degree in Information Security, Information Technology, Computer Science, or related field (or equivalent experience). 11 paid holidays per year.…
Use AI to find out how well the skills on your resume fit this job description.
About the Team
Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture.
About the Role
Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government (USG) ATOs and compliance frameworks, including but not limited to FedRAMP and Department of War (DoW),for OpenAI products and support agency-specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders.
We’re looking for people who bring:
Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors.
A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP).
Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders.
Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure.
This role is based in Washington, DC. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.
In this role, you will:
Drive the ATO process for FedRAMP and across multiple government clients in restricted environments with minimal oversight.
Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.
Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.
Act as a subject matter expert during audits and assessments, representing the organization with credibility and expertise.
Continuously refine processes to improve the efficiency and quality of compliance efforts.
You might thrive in this role if you:
An active US security clearance.
5+ years of compliance experience in positions involving information security, data security, or infrastructure or network security.
Familiarity with deployment models, including to cloud platforms (Azure, AWS) and the underlying infrastructure primitives (Kubernetes, Terraform).
Strong familiarity with core security concepts and technologies, such as authentication, encryption, vulnerability management, and audit logging.
The ability to work collaboratively and effectively in a cross-functional team environment.
Thrive in dynamic environments and can navigate ambiguity with ease.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see
OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement
.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through
this form
. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
The minimum salary is $162K and the max salary is $310K.
$162K – $310K/yr (Employer provided)
$236K
/yr Median
United States
If an employer includes a salary or salary range on their job, we display it as "Employer Provided". If a job has no salary data, Glassdoor displays a "Glassdoor Estimate" if available. To learn more about "Glassdoor Estimates," see our FAQ page.
Working here doesn’t have to be a secret
Sign in to browse authentic reviews, anonymous ratings and salary data before you apply.