Lead GRC Engineer

HiggsfieldSan Francisco, CA
$220,000 - $280,000Hybrid

About The Position

Higgsfield AI is seeking a Lead GRC Engineer to establish the technical underpinnings of their security and compliance program as the company expands. This role is distinct from traditional GRC positions, focusing on translating security, privacy, and compliance requirements into automated, continuously monitored technical controls. The Lead GRC Engineer will collaborate with Security, Engineering, Privacy, Legal, and other departments to architect controls suitable for current needs and future scalability.

Requirements

  • 6+ years spanning security, GRC, software engineering, automation engineering, or related technical roles.
  • Demonstrated experience translating framework, regulatory, or policy requirements into technical implementations.
  • Hands-on experience building or automating security and compliance controls.
  • Production-grade scripting or programming experience, such as Python, including working with APIs and integrations.
  • Strong understanding of frameworks such as SOC 2 and ISO 27001 and what constitutes credible control evidence.
  • Ability to distinguish between a control that technically exists and one that is actually effective, enforced, and continuously monitored.
  • Experience building in rapidly changing or 0→1 environments without relying on mature infrastructure or large teams.
  • Strong judgment around automation, risk, exceptions, enforcement, and engineering velocity.
  • Ability to communicate technical controls and evidence clearly to auditors, customer security teams, engineers, and nontechnical stakeholders.

Responsibilities

  • Translate security, privacy, and compliance requirements into technical controls, automated checks, and enforcement mechanisms.
  • Build pipelines and integrations to aggregate control, asset, identity, and system data across cloud infrastructure, IdP, HRIS, source control, CI/CD, and SaaS applications.
  • Develop automated control checks, live monitoring, dashboards, alerts, and audit-ready evidence from aggregated data.
  • Create preventative controls and release gates to identify or block security and privacy issues before production.
  • Design controls that remain effective amidst rapid changes in employees, locations, vendors, systems, infrastructure, and products.
  • Build a unified controls approach for collecting evidence once and mapping it across multiple frameworks and requirements.
  • Automate evidence collection, control testing, monitoring, and exception management, moving away from point-in-time reviews.
  • Integrate with existing systems and controls owned by Security, Engineering, IT, and other teams to avoid parallel processes.
  • Continuously test control effectiveness and detect regressions or drift.
  • Instrument control effectiveness to provide security and GRC stakeholders with live data on risk posture.
  • Design agentic and AI-assisted workflows for evidence analysis, control testing, monitoring, and audit-response preparation.
  • Apply judgment regarding AI delegation, human review requirements, and evidence management.
  • Contribute to building the technical evidence base for AI-related certifications and assurance, including agent activity, evaluations, tool restrictions, and failure modes.
  • Partner with Product and Engineering to adapt to evolving AI assurance standards and customer expectations.

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Competitive 401(k) retirement plan with company matching
  • Bonus eligibility
  • Stock option program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service