Profound

Tech / AI / Software

SecurityGRCSpecialist

$150–240k New York, New York, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Security GRC Specialist at Profound. Skills: security GRC, compliance, security engineering. Own and scale our security and compliance programs. Own and operate our compliance frameworks: SOC 2, ISO 27001, GDPR, and others as we grow”

What You'll Achieve.

scale our security and compliance programs; reduce compliance overhead through automation; unblock deals and build trust with security teams at Fortune 500 customers; earn its keep

Industry & Context.

Tech / AI / Software
Problems you'll solve

Translate compliance requirements into technical, scalable solutions; Identify gaps and drive remediation, not just report them

What They're Looking For.

Must Have

3 to 7+ years in security GRC, compliance, or adjacent security engineering roles, Hands-on experience with SOC 2, ISO 27001, or similar frameworks, Experience supporting audits and leading customer-facing security conversations, Comfortable working with engineers and reasoning about cloud infrastructure, APIs, identity systems, and data flows, Able to translate between compliance language and engineering reality in both directions

Nice to Have

Experience with modern cloud environments (AWS, GCP, or Azure) is a plus, Familiarity with automation in compliance workflows, Background in security engineering, DevOps, or identity and access management

What You'll Do.

Own and scale our security and compliance programs

Own and operate our compliance frameworks: SOC 2

and others as we grow

Drive audits end to end: readiness

Continuously improve controls and reduce compliance overhead through automation

Lead responses to enterprise security questionnaires

and due diligence requests

Partner with Sales and Customer Success to unblock deals and build trust with security teams at Fortune 500 customers

Develop and maintain our trust center

and customer-facing documentation

Work directly with engineering to design and implement practical security controls across our cloud infrastructure

and customer-facing surfaces

Partner on identity and access work (SSO

IdP integrations) where security

and customer-facing requirements intersect

Translate compliance requirements into technical

Identify gaps and drive remediation

Run risk assessments across systems

Maintain policies and standards that are lightweight

Track and report on our security posture and compliance status to leadership

Improve how we manage compliance: evidence collection

Evaluate and implement GRC and security tooling where it earns its keep

How You'll Work.

Team & Collaboration

working closely with engineering, sales, and customer success; Partner with Sales and Customer Success to unblock deals and build trust with security teams at Fortune 500 customers; Work directly with engineering to design and implement practical security controls; Partner on identity and access work where security, compliance, and customer-facing requirements intersect; written communication, especially with enterprise customers and cross-functional partners

Communication Scope

written communication, especially with enterprise customers and cross-functional partners; customer-facing security conversations

Process & Methodology

Drive audits end to end, Lead responses to enterprise security questionnaires, RFPs, and due diligence requests, Identify gaps and drive remediation, Run risk assessments across systems, vendors, and processes, Track and report on our security posture and compliance status to leadership, Improve how we manage compliance

Full Job Description

Profound is on a mission to help companies understand and control their AI presence. We are hiring a Security GRC Specialist to own and scale our security and compliance programs while working closely with engineering, sales, and customer success. Profound sells to enterprises with serious security expectations, and our GRC function is central to closing deals, sustaining customer trust, and meeting the regulatory bar for the markets we operate in. This is not a "watch the dashboard and file the report" role. You'll shape how we build secure systems, push remediation through with engineering, and make sure compliance accelerates the business rather than slowing it down. WHAT YOU'LL DO - Own and operate our compliance frameworks: SOC 2, ISO 27001, GDPR, and others as we grow - Drive audits end to end: readiness, evidence collection, auditor coordination - Continuously improve controls and reduce compliance overhead through automation - Lead responses to enterprise security questionnaires, RFPs, and due diligence requests - Partner with Sales and Customer Success to unblock deals and build trust with security teams at Fortune 500 customers - Develop and maintain our trust center, security whitepapers, and customer-facing documentation - Work directly with engineering to design and implement practical security controls across our cloud infrastructure, data pipelines, and customer-facing surfaces - Partner on identity and access work (SSO, SAML, SCIM, IdP integrations) where security, compliance, and customer-facing requirements intersect - Translate compliance requirements into technical, scalable solutions - Identify gaps and drive remediation, not just report them - Run risk assessments across systems, vendors, and processes - Maintain policies and standards that are lightweight, current, and actually useful - Track and report on our security posture and compliance status to leadership - Improve how we manage compliance: evidence collection, control mapping, automati

Free ATS check

Applying for this Security GRC Specialist role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Profound?

Real rants from real employees. Read before you apply.

Read Company Rants →