hirly

Thinking Machines Lab

Governance, Risk and Compliance Lead

San Francisco

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Thinking Machines Lab first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Stated salary
$225,000 – $350,000 per year
Country
US
Work mode
On-site / unstated
First seen by hirly
28 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About Thinking Machines

The mission of Thinking Machines is to build AI that extends human will and judgment. We are training frontier models with Inkling, developing Tinker to let people make models their own, and crafting interfaces that broaden human-AI communication. We believe the future worth building is human, and we're hiring people who want to build it.

About the Role

We're looking for a GRC Lead who personally drives our certifications (SOC 2, ISO 27001, FedRAMP and others as we grow) from scoping through audit close, and runs our compliance processes day to day. You'll collect the evidence, write the control documentation, and sit across from the auditor yourself.

You'll work closely with security, legal, safety, and engineering to answer compliance and risk questions directly, using your own technical understanding of how our systems work. Day to day, you'll be managing audits, controls, and risk assessments. Alongside that, you'll be building the roadmap for what this function needs to look like in a year.

What You'll Do

Own our certification roadmap end to end: scope each certification, build the control set, collect and organize evidence, and represent TML directly to auditors through to close.

Manage recurring compliance processes on a set cadence: control testing, audit prep and response, risk register maintenance, and policy attestations.

Answer compliance and risk questions from engineering, security, and product teams directly, by building enough technical fluency across our infrastructure, model deployment, and data handling to do so without escalating every question.

Track regulatory and framework requirements relevant to an AI company (GDPR, EU AI Act, and similar) and translate them into specific, actionable controls.

Identify gaps in current compliance coverage as the company adds new products, infrastructure, or jurisdictions, and propose what needs to change before it becomes a blocker.

Build and maintain the tooling and documentation that make the next audit cycle faster than the last one.

Plan a multi-quarter roadmap for the GRC function itself, while continuing to personally run the certifications and audits already on the books.

Skills and Qualifications

Minimum qualifications:

7+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.

Experience leading a SOC 2, ISO 27001, FedRAMP or comparable certification from scoping through audit close.

Hands-on experience collecting audit evidence and writing control documentation.

Experience managing a recurring compliance process, such as control testing, risk register maintenance, or policy attestations.

Experience learning new technical domains quickly and translating them for non-technical stakeholders.

Preferred qualifications:

We encourage you to apply even if you don't meet all preferred qualifications.

Background as a software engineer or in a technical engineering role, now applied to GRC, evidenced by scripts, tools, or automations you've personally built for evidence collection, control testing, or audit workflows.

Experience translating complex compliance requirements into scalable automation using AI agents and custom built tooling.

Experience growing a GRC function's capability (new certifications, tooling, or processes) as a company scaled.

You'll Thrive in This Role if

You want to run the certification yourself, end to end.

You're the one in the room with the auditor, walking through evidence.

You can hold this week's deadlines and next year's roadmap at the same time.

Logistics

Location: This role is based in San Francisco, California.

Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $225,000 - $350,000.

Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.

Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.

As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Original posting on Thinking Machines Lab's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job