hirly

Gimlet

Member of Security Staff, Governance, Risk and Compliance

San Francisco, CA

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Gimlet first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Stated salary
$270,000 – $330,000 per year
Country
US
Work mode
On-site / unstated
First seen by hirly
10 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About us

Gimlet is building the first multi-silicon neocloud designed for fast, efficient AI inference.

We combine large-scale compute infrastructure with an execution platform that partitions AI workloads and maps each stage to the hardware best suited to run it.

We work with foundation labs, hyperscalers, and AI-native companies, giving our team access to technical problems spanning frontier models, production infrastructure, and emerging hardware.

About the role

Gimlet Labs is looking for a Member of Security Staff, Governance, Risk and Compliance to build and own the security and compliance foundation for an AI company operating across rapidly evolving AI systems serving production scale traffic for top frontier labs and hyperscalers.

This is a highly hands-on role for someone who can design the compliance program, implement the technical controls, and work directly with engineering to make security auditable, scalable, and practical. You will have significant ownership over the compliance stack, including policies, controls, evidence collection, audit readiness, vendor risk, and security tooling.

What success looks like

In the first 12-18 months, you will:

Partner directly with engineering, infrastructure, and product teams to identify security risks and design practical controls across AI platforms, cloud infrastructure, networking systems, APIs, and software delivery pipelines.

Build and operationalize security and compliance programs supporting frameworks such as SOC 2, ISO 27001, NIST CSF, NIST AI RMF, CSA CCM, and customer security requirements.

Drive improvements to cloud and application security controls, including IAM, network segmentation, encryption, logging, secrets management, vulnerability management, and secure SDLC practices.

Help define security approaches for AI systems, including model access controls, data protection, third-party AI tooling, auditability, and misuse prevention.

Build scalable processes for audit evidence collection, risk tracking, remediation management, and security reporting across technical and non-technical stakeholders.

Contribute to broader security and operational readiness efforts including vendor risk management, incident response preparedness, business continuity planning, and security policy development.

You may be a good fit if

Experience in security risk, compliance, GRC, cloud security, or infrastructure security.

Working knowledge of cloud platforms such as AWS, Azure, or Google Cloud.

Familiarity with networking concepts including firewalls, VPC/VNet design, VPNs, DNS, TLS, routing, segmentation, and zero trust principles.

Understanding of software security concepts, including secure SDLC, CI/CD, vulnerability management, secrets management, and API security.

Experience with compliance frameworks such as SOC 2, ISO 27001, NIST, CIS Controls, or CSA CCM.

Ability to document controls, gather evidence, assess gaps, and drive remediation with engineering teams.

Strong written and verbal communication skills.

Strong candidates may also have

Experience in an early-stage startup or high-ownership environment.

Experience supporting AI, machine learning, data infrastructure, or SaaS platforms.

Familiarity with AI governance frameworks such as NIST AI RMF or ISO/IEC 42001.

Experience with Kubernetes, containers, infrastructure as code, and cloud-native security tooling.

Certifications such as CISSP, CISA, CRISC, CCSP, CCSK, Security+, AWS Security Specialty, or Azure Security Engineer.

Experience implementing or administering GRC platforms, SIEMs, CSPM tools, vulnerability scanners, and ticketing workflows.

Why join now?

Gimlet is expanding from its core technology into a production neocloud spanning new hardware, customers, and data centers.

Solve hard problems.

Own meaningful work.

Build for production.

Help define what’s next.

Agency Policy: Gimlet Labs does not accept unsolicited resumes from recruitment agencies or search firms. Any unsolicited resumes submitted without a signed agreement will be considered the property of Gimlet Labs, and no fees will be paid.

Original posting on Gimlet's site ↗

Listed on hirly, a job board. hirly is not the employer: Gimlet is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job