About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture. About the Role Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government (USG) ATOs and compliance frameworks, including but not limited to FedRAMP and Department of War (DoW),for OpenAI products and support agency-specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders. We’re looking for people who bring: Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors. A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP). Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders. Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure. This role is base
GRC Program Manager
Salary not disclosed
Check market pay for comparable Program Manager roles before applying.
Role overview
Job description
A World-Changing Company Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.
The Role As a GRC Program Manager, you are the engine behind Palantir's Governance, Risk, and Compliance programs. You partner with compliance engineers, security teams, and developers to design and scale the processes that keep our Commercial, International, and US Government businesses operating at the highest regulatory standards. You track and stabilize projects, remove roadblocks, and anticipate stakeholder needs to free up our specialists to focus on the problems they are best equipped to solve.
What they are looking for
Skills & requirements
Department · Information Security
Keep exploring
Similar active roles
Fresh roles matched to this title and market.
About the Team OpenAI’s mission is to ensure that general-purpose artificial intelligence benefits all of humanity. We believe that achieving our goal requires effective engagement with public policy stakeholders and the broader community impacted by AI. Accordingly, our Global Affairs team builds authentic, collaborative relationships with public officials and the broader AI policymaking community to inform and support our shared work in these domains. We ensure that insights from policymakers inform our work and – in collaboration with our colleagues and external stakeholders – seek to shape policy so that it aligns with and supports our mission. About the Role As AI agents move from answering questions to taking action across the internet, the standards that govern identity, delegated authority, discovery, communications, agentic-commerce and payment interfaces, agent-facing web access, agent-specific provenance, and auditability will determine whether agents can operate safely, interoperably, and with clear accountability. OpenAI is looking for an Agent Standards Manager to lead execution of our external technical standards strategy for a defined set of agent standards workstreams. This role will work closely with Agent Security, Applied and Platform teams, Product, Legal, GRC, Global Affairs, and GTM to turn OpenAI’s technical architecture and controls into credible specifications, protocol profiles, assurance criteria, and implementation guidance—and to bring emerging external requirements back into product and security roadmaps before they become blockers. The positions developed here are technical standards positions, not broad public-policy positions. This is a builder’s role as much as an external-facing role. You will execute a prioritized standards plan, author and negotiate protocols, build coalitions, secure the right internal approvals, and represent OpenAI in assigned technical forums. You will also help create repeatable processes that let the compa
About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. We are technical in what we build but operational in how we do our work, and we partner deeply with Product, Security, Legal, Privacy, GTM, and Field Security to help OpenAI move quickly while maintaining trust with customers, auditors, regulators, and the public. About the Role We are looking for an experienced Product Lifecycle Assurance IC to help scale OpenAI’s GRC function across our product stack to ensure products address customer and regulatory compliance requirements at launch and regressions are detected promptly and corrected. You will partner closely with Product, Security, Legal, and Privacy teams to make sure OpenAI can move quickly while maintaining our security, privacy and compliance claims and giving customers, auditors, and regulators assurance about how OpenAI handles user data. You are responsible for product assurance end-to-end from inception to post-launch (continuous) monitoring. You leverage existing workflows, reviews, and data and enhance, augment and build the components needed to create an end-to-end product assurance program. This role is not about supporting SOC or ISO audits; it's a highly cross-functional and deeply technical operations role to ensure that OAI products meet the compliance bar at launch, regressions are prevented and detected, and our compliance state can be evidenced. This role also helps ensure that our product launch governance program operates effectively across key safety, privacy, legal and security stakeholders and lessons-learned from incidents and regressions are used to improve the program. You or in partnership with engineering teams, build key controls in our infrastructure stack, developer workflows and launch tooling to provide developers with guardrails, perform CI/CD confor
About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership
At Scale, we are driving the future of AI and Machine Learning across a variety of industries. As the Program Manager for Compliance, you will play a pivotal role in the continued success of Scale. Your role will be instrumental in ensuring the effective operation of our Compliance department and our GRC function, allowing us to maintain the highest standards in our industry. Reporting to the Director & Associate General Counsel, Compliance, you will be a dedicated program manager for Scale's enterprise compliance program and the person who turns policy into practice across anti-bribery and anti-corruption, gifts and entertainment, conflicts of interest, third-party risk and sanctions, policy lifecycle, and company-wide training. This is a hands-on builder, not a maintenance role. You will support Commercial, Public Sector, and international business lines, working closely with Legal, Procurement, Finance, Security, and go-to-market teams. You will: Help build, design, improve, and streamline Scale's core compliance programs, including anti-bribery and anti-corruption (ABAC), gifts and entertainment, conflicts of interest, and third-party risk and sanctions screening. Collaborate with stakeholders across the company to improve compliance policies, processes, and procedures. Monitor regulatory developments relevant to Scale's business, translate them into concrete policy and process changes, and track compliance obligations flowing out of customer contracts. Partner with leadership to build, mature, and operationalize the company's enterprise risk management (ERM) framework, identifying and assessing key business risks. Build the reporting layer: metrics and periodic reporting that give Legal & GRC leadership a defensible picture of program health. Flex into audit and assurance work during peak certification periods, and own inbound customer and investor compliance diligence questionnaires. Ideally you'd have: 5+ years building or operating ethics and c
About the Team OpenAI’s Legal team helps advance our mission by tackling novel legal issues in AI. Our team brings together professionals across technology, privacy, intellectual property, corporate, employment, tax, regulatory, and litigation. Our regulatory compliance work turns legal requirements into practical programs that support responsible AI development and deployment. About the Role As a Legal Program Manager focused on regulatory compliance, you will build and manage cross-functional programs that translate counsel’s guidance into practical, sustainable operations. Your initial focus may include content moderation and/or frontier AI governance, with the mix shaped by team priorities and your strengths. You will partner with internal and external counsel, other legal program managers, and technical and business teams to coordinate implementation, evidence collection, reporting, and ongoing compliance. You’ll build repeatable systems that scale across regulations, products, and jurisdictions, helping teams navigate emerging requirements with clarity and sound judgment. This full-time role is based in San Francisco, CA, or New York, NY. In this role, you will: Lead regulatory compliance programs end to end: define scope, owners, milestones, dependencies, risks, and escalation paths, and drive execution with counsel and cross-functional partners. Translate counsel’s regulatory guidance into repeatable workflows, controls, and documentation. Depending on your portfolio, this may include content moderation disclosures, transparency reporting, reporting and appeals workflows, or frontier AI model launch readiness, evaluation and risk-management evidence, and incident reporting. Build strong partnerships across Product, Engineering, User Operations, Governance, Risk and Compliance (GRC), Global Affairs, Communications, and Go-to-Market to align program priorities and deliverables. Support regulatory inquiries, audits and investigations with counsel, organizing ev
🔔 Get job alerts
New GRC Program Manager jobs in Washington, D.C., straight to your inbox.
No spam · Unsubscribe anytime