Senior GRC Specialist
Cohere $200K - $245K/year Posted 4 days ago
About the role
Cohere's Governance, Risk, and Compliance team operates as a centralized function within the Security organization, reinforcing customer trust, ensuring adherence to regulatory requirements, and advancing internal governance and control practices across the company. As a Senior GRC Specialist you'll help build and shape Cohere's compliance and governance foundation as expectations around security, privacy, public sector readiness, and responsible AI continue to evolve. This is not a purely policy-focused GRC role: Cohere wants someone who pairs compliance expertise with practical technical problem-solving, including automation, lightweight tool building, and process improvement.
Responsibilities
- Build, implement, and scale compliance programs, controls, and processes across frameworks and regulatory requirements including SOC 2, ISO 27001, HIPAA, ISO 42001, and FedRAMP/DoD.
- Support and mature compliance efforts related to AI governance, including work aligned to ISO 42001 and the EU AI Act.
- Drive compliance readiness for FedRAMP, DoD, and related public sector requirements, while supporting broader enterprise and customer-facing compliance obligations.
- Partner with Security, Engineering, Modeling, Product, Legal, and other cross-functional teams to translate requirements into practical, scalable controls.
- Improve compliance operations through automation, tooling, and scalable workflows, building scripts or lightweight tools for evidence collection, reporting, control tracking, and audit readiness.
- Manage cross-functional projects, timelines, remediation efforts, and audit preparation, and support audits, assessments, and customer or regulatory compliance requests.
Qualifications
- 7+ years of progressive experience building and scaling compliance programs across multiple frameworks, including SOC 2, ISO 27001, and HIPAA, with extensive experience in FedRAMP, DoD, or public sector and highly regulated environments.
- Experience with AI governance and frameworks such as ISO 42001.
- Strong project management and cross-functional execution skills, with technical fluency and comfort working alongside Engineering and Security teams.
- Experience with automation, workflow tooling, or process design; hands-on Python or similar scripting for lightweight automation is a plus.
- Strong written communication, organization, and attention to detail.
- Nice to have: mature risk management frameworks such as FAIR or quantitative risk methodologies, additional standards such as NIST CSF, NIST RMF, NIST AI RMF, or CMMC, and experience in cloud-native or SaaS product environments.
Skills
How to apply
Apply directly on the employer's application page. Your application goes straight to them.
Republished listing
This opportunity was discovered on Cohere's public careers page and is republished here for discovery purposes. Applications are handled by the employer.
Cohere team? Claim this listing or ask us to remove it.