JobRaahGet matched free

Jobs

GRC Engineer

Reflectionai · New York, NY · United States · On-site

Posted Oct 9, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

OUR MISSION Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all. ROLE SUMMARY Reflection AI's Compliance and AI Governance function spans six pillars: AI Governance, Data Governance, Trade Compliance, Privacy Operationalization, Government Contracting Compliance, and Corporate Compliance. The team builds the policies, controls, and operating rhythms that let the company move fast while staying defensible with regulators, customers, and partners. This role sits at the intersection of compliance and engineering, partnering most closely on technical controls required by Security frameworks, AI Governance frameworks, Privacy, and Data Governance pillars to translate policy requirements into technical controls that scale. We're looking for a Governance, Risk, & Compliance engineer who wants to work on compliance as a product problem rather than a paperwork problem. You'll build and maintain the technical infrastructure (tooling, pipelines, automated controls, evidence collection) that lets the compliance program operate at engineering scale instead of through manual review. A core part of the job is keeping our security framework compliance (SOC 2, ISO 27001, NIST) running on automated evidence rather than manual screenshotting, and building out the technical side of our Trade Compliance, Privacy, Data Governance, and TPRM program. You'll be the technical translator between compliance requirements and the engineering and security teams that have to implement them. WHAT YOU'LL DO - Design and build automated controls and monitoring that satisfy security framework requirements (SOC 2, ISO 27001, NIST 800-53/800-171, CMMC): access reviews, data minimization, model/data lineage, continuous evidence collection - Partner with Engineering, Security, and IT to implement technical requirements arising from security frameworks, deemed export controls, and privacy regulations - Build and maintain internal tooling that supports compliance workflows (intake forms, screening checks, reporting dashboards, GRC platform integrations such as Vanta) - Translate regulatory and policy requirements into concrete technical specifications engineering teams can implement - Support technical due diligence for inbound customer security questionnaires, audits, and outbound vendor assessments - Maintain integrations between compliance/GRC systems and source-of-truth systems (identity, data infrastructure, model pipelines) - Help scope and support technical environment separations or system boundaries required for regulatory compliance (e.g., subsidiary or enclave environments) WHAT WE'RE LOOKING FOR - 3-6 years of software engineering, security engineering, or DevOps/infrastructure experience - Hands-on experience supporting at…