Governance, Risk and Compliance Lead

Thinking Machines LabSan Francisco, CA
Onsite

About The Position

Thinking Machines Lab is seeking a GRC Lead to personally drive certifications such as SOC 2, ISO 27001, and FedRAMP from scoping through audit close, and to manage daily compliance processes. This role involves collecting evidence, writing control documentation, and directly interacting with auditors. The GRC Lead will collaborate closely with security, legal, safety, and engineering teams, leveraging their technical understanding of the company's systems to address compliance and risk-related inquiries. Key responsibilities include managing audits, controls, and risk assessments, as well as developing a roadmap for the GRC function's future growth.

Requirements

  • 7+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.
  • Experience leading a SOC 2, ISO 27001, FedRAMP or comparable certification from scoping through audit close.
  • Hands-on experience collecting audit evidence and writing control documentation.
  • Experience managing a recurring compliance process, such as control testing, risk register maintenance, or policy attestations.
  • Experience learning new technical domains quickly and translating them for non-technical stakeholders.

Nice To Haves

  • Background as a software engineer or in a technical engineering role, now applied to GRC, evidenced by scripts, tools, or automations you've personally built for evidence collection, control testing, or audit workflows.
  • Experience translating complex compliance requirements into scalable automation using AI agents and custom built tooling.
  • Experience growing a GRC function's capability (new certifications, tooling, or processes) as a company scaled.

Responsibilities

  • Own our certification roadmap end to end: scope each certification, build the control set, collect and organize evidence, and represent TML directly to auditors through to close.
  • Manage recurring compliance processes on a set cadence: control testing, audit prep and response, risk register maintenance, and policy attestations.
  • Answer compliance and risk questions from engineering, security, and product teams directly, by building enough technical fluency across our infrastructure, model deployment, and data handling to do so without escalating every question.
  • Track regulatory and framework requirements relevant to an AI company (GDPR, EU AI Act, and similar) and translate them into specific, actionable controls.
  • Identify gaps in current compliance coverage as the company adds new products, infrastructure, or jurisdictions, and propose what needs to change before it becomes a blocker.
  • Build and maintain the tooling and documentation that make the next audit cycle faster than the last one.
  • Plan a multi-quarter roadmap for the GRC function itself, while continuing to personally run the certifications and audits already on the books.

Benefits

  • generous health, dental, and vision benefits
  • unlimited PTO
  • paid parental leave
  • relocation support as needed
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service