Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience. Are a systems thinker first.…
Bachelor's degree in computer science, information technology, or a related field. Security Tools and Technologies: Oversee the selection, implementation, and……
Assist in the risk assessment process and report on enterprise-wide and third-party. Along with the BISO and central GRC function, including the development,……
Governance, Risk, and Compliance maintain said policies, ensure controls are operating effectively via assessment and attestation, and own the vulnerability……
Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Risk Management, Business, or related field; equivalent combination of education and……
Experience working closely with engineering and design teams to deliver high-quality software products. You'll have the opportunity to shape a strategic product……
Experience in human services, healthcare, compliance, auditing, risk management, or a related field preferred. Strong organizational and time management skills.…
Position requires a bachelor's degree in computer science, information technology, engineering, business, or related field and five years of experience in……
Participate in the selection, design, and implementation of security solutions as part of a project team, ensuring alignment with organizational goals.…
Collaborates with risk owners and technical teams to develop realistic remediation plans that define specific tasks, milestones, resource requirements, and……
Collaborates with risk owners and technical teams to develop realistic remediation plans that define specific tasks, milestones, resource requirements, and……
INCIDENT & REQUEST MANAGEMENT: Reviews, analyzes and prioritizes incoming incident tickets and user requests. SAP SECURITY APPLICATION DEVELOPMENT & DEPLOYMENT:……
Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies……
Minimum seven years of experience in GRC, privacy, security, enterprise risk, or technology enablement with increasing management responsibility; experience……
Acceptable areas of study include Business, Accounting, Finance, or related field. Experience using AI-powered tools or analytics platforms (e.g., HiredScore,……
This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive……
ISO 27001: sustain ISMS certification and surveillance/re-assessment cycles across certified sites, including mandatory documentation, internal audits, and……
Assessment: Assessing the state of the classified cyber assurance program against industry standards, requirements (contractual and regulatory), and……
Provides technical knowledge, thought leadership, and consultative support to the business client, IT management, developers and staff in risk assessments,……
The Internal Audit team plans and executes audit projects in accordance with the audit plan and risk assessments, evaluating the efficiency and effectiveness of……
5 years in business continuity, disaster recovery, operational risk, or cyber resilience, with a demonstrated track record of leading technical continuity and……
5 years in business continuity, disaster recovery, operational risk, or cyber resilience, with a demonstrated track record of leading technical continuity and……
Bachelor’s degree in computer science, data science, management information systems, or like discipline from an accredited college or university or measurable……
Analyzes and interprets federal/state laws, regulations, and contractual obligations (e.g., state contracts, DPAs, security addenda) to identify requirements……
This role is responsible for driving and implementing security, compliance, and risk management programs on the ServiceNow eGRC platform at Uber, working with……
Lead execution of a portfolio of security compliance and certification initiatives, ensuring delivery against regulatory, certification, and customer……
The GRC Security Compliance Specialist works closely with cybersecurity, infrastructure, cloud, application, risk, audit, and business teams to validate control……
Use AI to find out how well the skills on your resume fit this job description.
About the Team
Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture.
About the Role
Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government (USG) ATOs and compliance frameworks, including but not limited to FedRAMP and Department of War (DoW),for OpenAI products and support agency-specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders.
We’re looking for people who bring:
Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors.
A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP).
Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders.
Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure.
This role is based in Washington, DC. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.
In this role, you will:
Drive the ATO process for FedRAMP and across multiple government clients in restricted environments with minimal oversight.
Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.
Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.
Act as a subject matter expert during audits and assessments, representing the organization with credibility and expertise.
Continuously refine processes to improve the efficiency and quality of compliance efforts.
You might thrive in this role if you:
An active US security clearance.
5+ years of compliance experience in positions involving information security, data security, or infrastructure or network security.
Familiarity with deployment models, including to cloud platforms (Azure, AWS) and the underlying infrastructure primitives (Kubernetes, Terraform).
Strong familiarity with core security concepts and technologies, such as authentication, encryption, vulnerability management, and audit logging.
The ability to work collaboratively and effectively in a cross-functional team environment.
Thrive in dynamic environments and can navigate ambiguity with ease.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see
OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement
.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through
this form
. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities.
OpenAI Global Applicant Privacy Policy
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
The minimum salary is $162K and the max salary is $310K.
$162K – $310K/yr (Employer provided)
$236K
/yr Median
Washington, DC
If an employer includes a salary or salary range on their job, we display it as "Employer Provided". If a job has no salary data, Glassdoor displays a "Glassdoor Estimate" if available. To learn more about "Glassdoor Estimates," see our FAQ page.
Working here doesn’t have to be a secret
Sign in to browse authentic reviews, anonymous ratings and salary data before you apply.