OpenAI’s charter calls on us to ensure the benefits of AI are distributed broadly and safely. Our Health AI team focuses on expanding access to high-quality medical expertise and aims to set a high standard for deploying AI responsibly in high-stakes domains. Improving health will be one of the defining impacts of AGI. Today, millions of people lack access to reliable medical information, and clinicians around the world face increasing time and resource constraints. We are building AI systems that support patients, clinicians, and health workers, while meeting the highest standards for safety, reliability, and privacy. We are seeking full stack software engineers to help build and scale products used by consumers and care providers globally. You will work closely with product, design, and research teams to ship real systems in a fast-moving, high-impact environment. In this role, you will: Design and build scalable fullstack systems for consumer and enterprise health. Own end-to-end feature development—from early design and implementation through deployment, monitoring, and iteration. Build and maintain data pipelines and services that meet strict privacy, security, and compliance requirements (e.g., HIPAA). Collaborate closely with researchers and safety teams to integrate reliability, evaluation, and guardrails into production systems. Debug, optimize, and harden systems to support high availability, performance, and global scale. Take ownership of ambiguous problems and drive them to practical, high-quality solutions. You might thrive in this role if you: Are deeply motivated by improving health outcomes and expanding access to medical expertise. Are a strong engineer who enjoys building durable, well-designed systems. Have 5+ years of experience writing maintainable, production-quality code. Can operate with high agency—owning problems end-to-end with minimal supervision. Enjoy working in fast-moving, cross-functional teams with engineers, product managers, desi
Jobs in United States
Information Security Compliance Manager in San Francisco
15 active opportunities · Updated September 2026
Showing
15 jobs
Explore current information security compliance manager jobs in San Francisco. Filter by work mode, employment type, experience, department, date posted and distance.
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The Role: Positioned in the first line of defense (1LOD) and reporting to the Head of Business Controls, this experienced executive will act as the Business Controls Lead for SoFi’s Technology and Cybersecurity organizations. This includes comprehensive coverage of Engineering, Information Security, Infrastructure, and Data across the full SoFi Legal structure: SoFi Inc., SoFi Bank, Galileo, Technisys, and SoFi Hong Kong. The Business Controls Lead will act as the direct advisor to the Chief Technology Officer (CTO), Chief Information Security Officer (CISO), and their senior leadership teams. You will lead a team of experienced IT risk & controls team charged with promoting risk awareness and ensure the overall effectiveness of risk and compliance management program implementation and execution across the 1LOD. This role provides support, advisory services, and enables strategic alignment directly to department heads to accelerate and ensure quality execution. You will be responsible for supporting and driving consistent 1LOD adherence to critical programs, such as building and maintaining risk and control self-assessments (RCSAs); identification and evaluation of control effectiveness through control testing; 1LOD risk reporting; and supporting audits and regulatory exams. You will monitor the first l
About the Team The Industrial Security team enables OpenAI’s classified and national security work by building secure, compliant programs that support government customers and protect sensitive information. Within Industrial Security, the Personnel Security function ensures employees have the clearances, accesses, briefings, and government approvals required to support classified programs. We work closely with employees, program teams, government customers, and partners across Security, People, Recruiting, Legal, IT, and Facilities to make complex security processes accurate, timely, and understandable. About the Role As a Personnel Security Specialist, you will own the day-to-day personnel security operations that allow OpenAI employees to support classified government work. You will manage clearance and access requests, maintain government-system records, coordinate visits and briefings, support onboarding and offboarding, and guide employees through sensitive security requirements with discretion and care. We’re looking for a hands-on security professional who can independently manage a high-volume operational queue, keep cases and records organized, recognize when issues require escalation, and improve the processes behind the work. This role offers the opportunity to help build a modern personnel security function that supports important national security programs while delivering a thoughtful, responsive employee experience. This role is based in San Francisco, CA, or Washington, DC. We use a hybrid work model of three days in the office per week and offer relocation assistance to new employees. Additional onsite presence and occasional travel may be required based on classified program and government customer needs. In this role, you will: Own the daily personnel security workload from intake through completion, including clearance verification, access nominations, visit requests, onboarding, offboarding, briefings, and reporting actions. Process and track pe
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. You will: Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute with
Who Are We? Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster. The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman. P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment. The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale. The Opportunity We are looking for a Principal Offensive Security Engineer who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operat
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The Role: SoFi's Cyber Defense organization is looking for an Offensive Security Lead to mature and grow our Penetration Testing and Red Team functions. This is a hands-on leadership role for someone who has spent years both doing the work and building the program around it — someone equally comfortable running a red team engagement against a critical banking platform and designing the operating model that lets a small team of offensive operators keep pace with a fast-growing fintech. A defining part of this role is modernizing how the team scales. We're looking for a leader who has already built and implemented AI-assisted penetration testing and red teaming programs — using AI tooling to accelerate reconnaissance, exploit development, attack-path analysis, and reporting — and who can bring that experience to bear on the program. You'll own the strategy, staffing, tooling, and execution quality of both disciplines, report into Cyber Defense leadership, and act as a trusted advisor to engineering, product, and risk partners across the company. What You’ll Do: Lead and unify Penetration Testing and Red Team into a single, cohesive Offensive Security function — shared standards, shared tradecraft, shared reporting, distinct missions. Set and execute the offensive security roadmap, aligning testing scope
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. About The role As a Vulnerability Management Engineer, you will support the identification, assessment, prioritization, and remediation of vulnerabilities across applications and infrastructure. Working under the guidance of senior team members, you will assist in understanding how vulnerable dependencies enter an application, identifying remediation options, and engaging with engineering teams to track fixes. You will contribute to the maintenance of internal vulnerability-management tools, such as scripts, documentation, and reporting. The ideal candidate will have a desire to grow their AppSec expertise, will be eager to learn about modern security tooling and automation, and will be comfortable using AI tools like Claude to assist with documentation, investigation, and scripting tasks while following company security and data-handling requirements. What you’ll do Perform regular vulnerability assessments using different tools. Regularly drive remediation and reporting of cataloged vulnerabilities. Assess discovered vulnerabilities and properly prioritize their scope, impact and necessary response actions. Conduct security reviews of our products and production infrastructure. Contribute to vulnerability management, application security and/or offensive/red-team operations. Engage in security audit
ABOUT BASETEN Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F , led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to to ship AI products. THE ROLE As the Head of IT at Baseten, you will build, scale, and secure our internal technology function to support our rapid growth. Reporting to our Chief Information Security Officer, you will lead and mentor a team of 5+ IT engineers, leading the charge to transition Baseten from startup-era IT to a highly automated, enterprise-ready IT organization. You will take full ownership of corporate IT infrastructure, Helpdesk operations, corporate identity management, device lifecycles, and vendor procurement. As we scale to support the world’s most dynamic AI companies, you will ensure our internal systems scale seamlessly with our headcount, providing a secure, frictionless, and world-class technology experience for all Baseten employees. RESPONSIBILITIES Team Leadership: Manage, mentor, and grow a team of IT engineers, fostering a high-performance culture focused on technical excellence and end-user satisfaction. Helpdesk Operational Excellence: Build a fast-response support function by establishing clear response SLAs, tracking employee satisfaction metrics, and formalizing on-call and incident response processes. Zero-Touch Automation: Architect and implement automated employee onboarding, offboarding, and role-based access changes through deep integrations across HRIS, MDM, and IAM systems. SaaS Management & Procurement: Establish comprehensive SaaS management processes to eliminate shadow IT, automate access w
About the team The Intelligence and Investigations team seeks to rapidly identify and mitigate abuse and strategic risks to ensure a safe online ecosystem in close collaboration with our internal and external partners. Our efforts contribute to OpenAI's overarching goal of developing AI that benefits humanity. This role focuses specifically on AI Safety: understanding and mitigating risks created or amplified by increasingly capable AI systems. It is not a cybersecurity, information security, or corporate security role. The Strategic Intelligence & Analysis (SIA) team provides safety intelligence for OpenAI’s products by monitoring, analyzing, and forecasting real-world abuse, geopolitical risks, and strategic threats. Our work informs AI safety mitigations, product decisions, and partnerships, ensuring OpenAI’s tools are deployed responsibly across critical sectors. About the role We are looking for a Frontier AI Risks Lead to help us understand potential harms and misuse of AI in a time of rapid, sustained change. We seek to understand how developments in AI could intersect with misuse and abuse, accelerating existing harm areas and creating novel risks. We seek to scan available signals and use strategic foresight methodologies to enable proactive detection and mitigation of frontier AI risks. This is an AI safety role focused on frontier and systemic risks, including model misalignment, recursive self-improvement (RSI), multi-agent interaction, loss of control, runaway agents, and related emerging failure modes. In this role, you will help provide a strategic-level perspective on a range of frontier AI safety areas, producing actionable understanding of issues relevant to OpenAI’s platforms, systems, and broader mission. Utilizing mixed quantitative and qualitative methodologies, you will spot early warning signs, pull threads on potentially concerning behavior, and turn weak signals into clear, prioritized risk calls. You will focus on upstream ecosystem sc
About the Team The Corporate Security team ensures the physical safety and security of the organization's assets, operations, and personnel. We are committed to maintaining a secure environment that enables our team to focus on advancing artificial intelligence in a responsible manner. About the Role As a Protective Intelligence & Threat Analyst, you will identify, assess, and communicate physical security threats affecting OpenAI, its personnel, executives, operations, and assets. You will leverage open-source intelligence, social media, investigative tools, and other information sources to assess violent or disruptive threats, geopolitical developments, and emerging risks relevant to the company. The role will support a broad range of Protective Intelligence activities, including persons of interest investigations, behavioral threat assessment, executive and individual risk assessments, event and travel security assessments, and time-sensitive intelligence support to Corporate Security and cross-functional partners. You will turn complex and often incomplete information into clear assessments and actionable recommendations that help inform security and protective decisions. We are seeking candidates with intelligence experience, particularly in protective intelligence, threat investigations, or behavioral threat assessment. Successful candidates will understand the intelligence cycle, OSINT investigative techniques, corporate physical security, risk management, and threat assessment, and will be comfortable operating independently in a fast-moving environment involving sensitive and occasionally high-profile matters. This role could be based in San Francisco, CA, or may be a remote role for the right candidate. We use a hybrid work model of 3 days in the office per week. Relocation offered for those outside of the Bay Area. In this role, you will: Identify and investigate potential physical threats to OpenAI, its executives, employees, facilities, operations,
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Secure Manufacturing & Stealth (SMS) team protects OpenAI’s most sensitive product, manufacturing, launch, and partnership work from theft, leakage, espionage, and unauthorized disclosure. We operate across physical, digital, human, and third-party domains, building practical protections that allow teams to move quickly while preserving strict need-to-know controls. About the Role We are seeking a senior Secure Manufacturing & Stealth Partner to serve as the dedicated SMS owner for Marketing. This person will build trusted relationships across Marketing, understand launches and sensitive information flows, identify secrecy risks early, and embed practical controls into planning, creative production, events, agencies, vendors, media, and executive communications. The role owns the Marketing relationship while coordinating shared SMS capabilities when investigative, prototype-handling, regional, or other specialist support is needed. In this role you will: Serve as the primary SMS Partner and trusted adviser to Marketing, building a deep understanding of its priorities, planning cycles, launches, events, external partners, and sensitive information flows. Identify secrecy and information-exposure risks early, then translate SMS requirements into practical controls that protect sensitive work without unnecessarily slowing execution. Build, document, and socialize durable operating mechanisms for compartmentalization, need-to-know access, agencies and vendors, sensitive creative production, events, demonstrations, launch preparation, codenames, watermarking, and password controls. Assess and approve Marketing systems and information workflows, identify gaps or duplication, establish secure handling requirements, and advise AI-native Marketing initiatives on permissions, data governance, and operational tracking. Coordinate
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The role We are seeking a Director of Digital Employee Experience to lead the strategy and execution of a modern, intuitive, and measurable digital workplace experience for our employees. This leader will own the strategy and technology experience for how employees access the tools, information, services, and support they need to do their best work. The ideal candidate is a systems thinker and cross-functional operator who can connect business needs, employee insights, technology capabilities, service design, and change management. This role will partner closely with IT, People/HR, Security, Workplace, Communications, and business leaders to simplify employee journeys, increase technology adoption, and reduce friction across the digital workplace. What you’ll do Develop and own the employee digital experience vision, strategy, roadmap, and operating model. Drive SoFi’s “Make Work Easier” strategy by identifying and reducing friction across the digital employee experience, making it simpler for employees to find information, access support, and get work done. Map and improve priority employee journeys, including onboarding, internal mobility, hardware/software access, IT and HR support, knowledge discovery, collaboration, and hybrid work experiences. Partner with service owners across IT, HR, Facilities, Sec
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! Member of Technical Staff, Search Why this role? We are looking for talented individuals to help us develop state-of-the-art models for information retrieval as part of our Search team. This group is working on a range of tasks including training our embedding and reranker models. You'll have the opportunity to revolutionise people's search experience by contributing to building an intelligent, efficient and precise search system and you would have a lot of opportunity to try new things out, innovate, and productionize your ideas. Your work will specifically focus on advancing semantic search techniques to improve accuracy and efficiency, involving working with a wide range of novel technologies and collaborating with other teams to integrate your work into our search infrastructure. We're looking for someone who is passionate about search and has a strong background in information retrieval. Candidates should have experience working with a wide range of technologies and have worked collaboratively with other teams in the past. As a Member of Technical Staff on this team, you will: Design, train and improve upon cutting-edge sea
About the Team OpenAI’s Governance team helps shape how the company responsibly develops and deploys increasingly capable AI. We bring together technical evidence, policy, and operational perspectives to help the company address emerging risks, resolve difficult questions, and make well-supported decisions. Our work includes shaping and improving governance practices, supporting effective oversight, developing clear assessments and recommendations, and ensuring that decisions lead to action. We work closely with research, safety, security, legal, and product teams to identify gaps, reconcile different views, and improve our approach as capabilities and circumstances change. About the Role We are looking for a curious, high-agency Research Program Manager who can reason from first principles, make sense of incomplete or conflicting information, and move difficult work forward. You will help shape the substance of governance reviews, connect ideas and evidence across teams, and develop recommendations that are both well-founded and practical. The work requires someone who can use established approaches where they fit, recognize when circumstances call for a different approach, and update their thinking as new evidence emerges. You should bring sound judgment, a willingness to experiment and learn, and the program-management discipline to turn good analysis into action. Depending on your experience and the team’s needs, your work may focus on safety advisory and board-level oversight, deployment governance, or standards and strategic partner commitments. In this role, you will: Bring together technical, policy, and operational inputs to develop coherent assessments, recommendations, and decision materials for governance bodies and senior leaders. Work through emerging or ambiguous questions, test assumptions, identify gaps or conflicting evidence, and help determine what additional analysis or decisions are needed. Engage critically with research, evaluations, safeguar
About the Team: We are a small and fast-moving partnerships team that shapes and executes OpenAI’s most important collaborations. Your mission is to identify, structure, and scale partnerships that expand how businesses adopt and benefit from OpenAI. You will work across priority sectors, including legal, professional services, information services, and other B2B categories, while maintaining the flexibility to pursue the highest-impact opportunities as the market evolves. About the Role: You are a senior business development and partnerships leader with strong judgment, high ownership, and a track record of originating and closing complex partnerships. You can move from market strategy and executive engagement through deal development, launch, and growth. You combine strategic thinking, commercial discipline, and hands-on execution, and you can create clarity and momentum across multiple internal and external stakeholders. Key Responsibilities: Develop a portfolio strategy for high-impact B2B partnerships. Identify and prioritize partners based on customer reach, differentiated data or workflows, distribution, strategic value, and growth potential. Originate, structure, negotiate, and launch complex product and commercial partnerships. Build joint value propositions and business plans spanning integration, distribution, go-to-market, and customer adoption. Lead executive relationships and establish durable cross-functional partnership governance. Coordinate product, engineering, sales, marketing, legal, finance, security, policy, and operations to deliver partnership outcomes. Translate partner and market insight into product strategy and new partnership models. Track adoption, pipeline, revenue impact, strategic milestones, and partner performance, and communicate progress and risks clearly. Qualifications: 10+ years of experience in strategic partnerships, business development, enterprise technology, or platform ecosystems. Proven experience personally originatin
Other cities to consider
More places hiring for this role
Get new information security compliance manager jobs in San Francisco, United States by email
Daily job updates · Unsubscribe anytime