About the Team The Privacy Engineering team builds secure, reliable systems that help OpenAI meet its legal obligations while protecting user data. We partner closely with Legal and Engineering teams across OpenAI to support lawful data access requests and other critical legal workflows. Our work turns complex, high-stakes processes into auditable and dependable technical systems with clear human oversight and strong privacy and security controls. About the Role We’re looking for a full-stack Software Engineer to build the internal tools and data pipelines that power lawful data access request workflows and Legal Operations. You will work across product and data systems to make authorized retrieval and case handling accurate, efficient, and auditable. This role is well suited to someone who enjoys translating ambiguous operational requirements into durable systems, cares deeply about sensitive-data handling, and wants to improve both technical reliability and the day-to-day experience of the people operating these workflows. This role is based in San Francisco, CA, with two additional locations under consideration: London, UK, and Dublin, Ireland. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Design, build, and operate backend systems and workflow tooling for the full lifecycle of lawful data access requests, from intake and scoping through authorized retrieval, review, preparation, and audit. Build reliable data pipelines and interfaces across products and data stores so authorized teams can locate and handle the right records accurately and reproducibly. Implement least-privilege access, approval gates, provenance, audit trails, data minimization, and safe failure modes for sensitive workflows. Partner with Legal and Legal Operations to translate legal and operational requirements into clear technical designs and intuitive operator experiences. Identify responsible automation o
Jobs in United States
Security Grc Analyst in San Francisco
248 active opportunities · Updated September 2026
Showing
15 jobs
Explore current security grc analyst jobs in San Francisco. Filter by work mode, employment type, experience, department, date posted and distance.
Typical salary
$123.7K – $123.7K/yr
Based on 1 salary observations
About the Team OpenAI’s Cyber team works to make frontier AI a decisive advantage for defenders. The Cyber Blue Team is an operator-led group focused on turning real defensive problems into better models, useful products, safe Codex workflows, and integrations with the security tools defenders already use. Our ambition is simple: Raise attacker cost. Lower defender toil. Prove it by defending OpenAI; scale it through the ecosystem. We are not setting out to build another SIEM or autonomous SOC. We want to build the AI reasoning and workflow layer that helps security teams investigate threats, create and validate detections, improve their controls, and respond with greater speed and confidence. About the Role We are looking for a Product Manager to help build a new generation of AI-powered cyber defense products. You will work closely with security practitioners, researchers, engineers, designers, internal security teams, customers, and technology partners to turn emerging model capabilities into products that solve meaningful defensive problems. This is an early-stage product role. The work will span product discovery, prototyping, evaluation, development, launch, and iteration. You will help the team identify where AI can create the most value for defenders and translate those opportunities into clear, usable, and trustworthy product experiences. Initial areas of focus may include: Detection engineering and detection-content development Threat hunting and investigation Security validation and control testing AI-agent and MCP runtime defense Integrations with security platforms and enterprise workflows Safe, governed assistance for incident response The specific roadmap will continue to evolve based on model progress, practitioner needs, internal learnings, and customer feedback. In This Role, You Will Work with security practitioners to understand high-value defensive workflows, recurring pain points, and opportunities for AI to materially improve outcomes. Help sh
About the Team Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Identity Infrastructure Engineering team sits at the core of this effort, designing and building the identity and access management solutions that protect model weights, customer data, and critical systems across multiple cloud environments. The team partners across OpenAI, including Applied Engineering, Research, IT, Security, Infrastructure, and Engineering, to provide secure and scalable platforms for identity, access management, permissioning, orchestration, and safe AI research. About the Role We’re looking for an engineering leader to lead Identity Infrastructure Engineering, the team building the systems that govern and scale access across OpenAI’s research, engineering, and internal platforms. This role sits at the center of cloud infrastructure, identity, software engineering, and security-critical operations. You’ll lead engineers building control planes, policy systems, workload and agent authorization patterns, infrastructure-as-code, and operational foundations that help OpenAI move quickly while keeping access reliable, auditable, least-privileged, and safe under failure. The ideal candidate has led teams responsible for large-scale, mission-critical infrastructure. They can go deep into code and architecture when needed, while giving engineers and technical leads the clarity and ownership to do their best work. They set technical direction, grow strong teams, make durable architecture decisions, and turn ambiguous 0-to-1 problems into platforms OpenAI can trust and build on for years. In this role, you will: Build and lead a high-performing Identity Infrastructure team, going deep enough technically to set direction while empowering the team to own delivery. Define the strategy for identity platform as the policy plane for access across people, agents, workloads, services, clouds, and internal systems. Scale Acc
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Threat Intelligence team protects OpenAI’s technology, people, research, and infrastructure by proactively identifying and disrupting adversaries who seek to compromise our systems or misuse our models. We investigate sophisticated threats, build tooling to scale and augment analysis, and deliver intelligence that shapes security strategy and equips leadership with timely, risk-aware insights. We combine technical depth, investigative rigor, and strong cross-functional partnerships to uncover threats and drive impact across OpenAI’s security and research organizations. About the Role As a Technical Threat Investigator at OpenAI, you will help protect the company from sophisticated adversaries targeting OpenAI and the broader ecosystem, as well as those attempting to misuse our models in support of cyber operations. This is a deeply investigative role. You will independently conduct complex, end-to-end investigations into capable threat actors to understand their behavior, infrastructure, emerging techniques, and how AI is integrated into their workflows. You’ll use these insights to proactively identify malicious activity and drive detection, disruption, enforcement, and safety improvements across the company. You’ll translate your investigative findings into durable solutions that scale impact. You’ll build and own lightweight tooling, automate where it matters, and create AI-assisted workflows to make investigations faster, more repeatable, and more effective over time. In this role, you will: Conduct deep, end-to-end investigations into sophisticated threat actors interacting with OpenAI’s models, products, and broader ecosystem. Think like an adversary — model attacker behavior, anticipate misuse patterns, and proactively hunt for, identify, and disrupt malicious activity. Leverage internal telemetry, OSINT, vendor data, a
About the Team The Privacy Engineering team builds the systems and technical foundations that govern how user data is understood, retained, accessed, and used across OpenAI. We partner with Product, Data, Infrastructure, Security, and Legal to translate policy and trust commitments into durable architecture and enforceable controls. Our work spans data inventory and mapping, classification and lineage, retention and deletion, access governance, purpose and usage controls, auditability, and lifecycle automation. We aim to make policy-aligned data handling the default while giving teams clear, reliable primitives for building and operating products at scale. About the Role We are looking for an experienced Software Engineer to drive the architecture and execution of user data governance across OpenAI. You will define technical direction, build shared platforms and controls, and lead cross-functional programs that make data flows discoverable, policies enforceable, and ownership explicit. This role is well suited to a senior engineer who can move between deep systems design and organization-wide influence, turn ambiguous requirements into pragmatic roadmaps, and operate high-trust systems end to end. This position is based in San Francisco. Relocation assistance is available. In this role, you will: Set the technical strategy and architecture for user data governance across data mapping, classification, lineage, retention, deletion, access, and permitted usage. Design and build shared services, APIs, metadata systems, and policy-enforcement mechanisms that make governance controls consistent, scalable, and auditable. Establish reliable inventories of user data, system ownership, data flows, and policy applicability across products, infrastructure, analytics, and research systems. Partner with Product, Data, Infrastructure, Security, and Legal leaders to define decision rights, translate requirements into controls, and drive adoption across teams. Own governance systems
About the Team The Privacy Engineering Team at OpenAI is committed to integrating privacy as a foundational element in OpenAI's mission of advancing Artificial General Intelligence (AGI). Our focus is on all OpenAI products and systems handling user data, striving to uphold the highest standards of data privacy and security. We build essential production services, develop novel privacy-preserving techniques, and equip cross-functional engineering and research partners with the necessary tools to ensure responsible data use. Our approach to prioritizing responsible data use is integral to OpenAI's mission of safely introducing AGI that offers widespread benefits. About the Role As a part of the Privacy Engineering Team, you will work on the frontlines of safeguarding user data while ensuring the usability and efficiency of our AI systems. You will help us understand and implement the latest research in privacy-enhancing technologies such as differential privacy, federated learning, and data memorization. Moreover, you will focus on investigating the interaction between privacy and machine learning, developing innovative techniques to improve data anonymization, and preventing model inversion and membership inference attacks. This position is located in San Francisco. Relocation assistance is available. In this role, you will: Design and prototype privacy-preserving machine-learning algorithms (e.g., differential privacy, secure aggregation, federated learning) that can be deployed at OpenAI scale. Measure and strengthen model robustness against privacy attacks such as membership inference, model inversion, and data memorization leaks—balancing utility with provable guarantees. Develop internal libraries, evaluation suites, and documentation that make cutting-edge privacy techniques accessible to engineering and research teams. Lead deep-dive investigations into the privacy–performance trade-offs of large models, publishing insights that inform model-training and prod
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. About The role As a Vulnerability Management Engineer, you will support the identification, assessment, prioritization, and remediation of vulnerabilities across applications and infrastructure. Working under the guidance of senior team members, you will assist in understanding how vulnerable dependencies enter an application, identifying remediation options, and engaging with engineering teams to track fixes. You will contribute to the maintenance of internal vulnerability-management tools, such as scripts, documentation, and reporting. The ideal candidate will have a desire to grow their AppSec expertise, will be eager to learn about modern security tooling and automation, and will be comfortable using AI tools like Claude to assist with documentation, investigation, and scripting tasks while following company security and data-handling requirements. What you’ll do Perform regular vulnerability assessments using different tools. Regularly drive remediation and reporting of cataloged vulnerabilities. Assess discovered vulnerabilities and properly prioritize their scope, impact and necessary response actions. Conduct security reviews of our products and production infrastructure. Contribute to vulnerability management, application security and/or offensive/red-team operations. Engage in security audit
About the Team The Corporate Security team ensures the physical safety and security of the organization's assets, operations, and personnel. We are committed to maintaining a secure environment that enables our team to focus on advancing artificial intelligence in a responsible manner. About the Role As a Protective Intelligence & Threat Analyst, you will identify, assess, and communicate physical security threats affecting OpenAI, its personnel, executives, operations, and assets. You will leverage open-source intelligence, social media, investigative tools, and other information sources to assess violent or disruptive threats, geopolitical developments, and emerging risks relevant to the company. The role will support a broad range of Protective Intelligence activities, including persons of interest investigations, behavioral threat assessment, executive and individual risk assessments, event and travel security assessments, and time-sensitive intelligence support to Corporate Security and cross-functional partners. You will turn complex and often incomplete information into clear assessments and actionable recommendations that help inform security and protective decisions. We are seeking candidates with intelligence experience, particularly in protective intelligence, threat investigations, or behavioral threat assessment. Successful candidates will understand the intelligence cycle, OSINT investigative techniques, corporate physical security, risk management, and threat assessment, and will be comfortable operating independently in a fast-moving environment involving sensitive and occasionally high-profile matters. This role could be based in San Francisco, CA, or may be a remote role for the right candidate. We use a hybrid work model of 3 days in the office per week. Relocation offered for those outside of the Bay Area. In this role, you will: Identify and investigate potential physical threats to OpenAI, its executives, employees, facilities, operations,
From $130K/yr
About Flexport: At Flexport, we believe global trade can move the human race forward. That’s why it’s our mission to make global commerce so easy there will be more of it. We’re shaping the future of a $10T industry with solutions powered by innovative technology and exceptional people. Today, companies of all sizes—from emerging brands to Fortune 500s—use Flexport technology to move more than $19B of merchandise across 112 countries a year. The recent global supply chain crisis has put Flexport center stage as we continue to play a pivotal role in how goods move around the world. We are proud to have the support of the best investors in the game who believe in our mission, solutions and people. Ready to tackle global challenges that impact business, society, and the environment? Come join us. The Opportunity: Flexport IT is looking for a Senior Systems Engineer (Identity & Access) . In this role, you will design, implement, and administer our Identity and Access Management (IAM) solutions to ensure secure, efficient user lifecycle management. While you are our resident Okta expert, you are also a high-level IT generalist. You will oversee our broader SaaS ecosystem (Google Workspace, Slack, Jira) and endpoint management infrastructure (Jamf, Intune). Your expertise will drive automation, protect sensitive data, mitigate security risks, and maintain compliance in a heavily regulated industry. You will continually strive towards automation of toil. If you are still manually doing the same operational tasks 18 months from now, something has gone wrong. Flexport’s book of business is growing fast, but the promise of technology is that we can grow our business faster than our headcount. The automation you build will be a key factor in that effort. You Will IAM Architecture: Design, implement, and maintain the end-to-end lifecycle of Identity and Access Management platforms. Okta & Directory Trust: Administer Okta, directory services, Multi-Fact
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Identity Infrastructure Engineering team sits at the core of this effort, designing and building the identity and access management solutions that protect our model weights, customer data, and critical systems across multiple cloud environments. We partner with teams across OpenAI—Applied Engineering, Research, IT, and Security—to provide a secure and scalable platform for permissioning, orchestration, and innovative AI research. About the Role We’re looking for a Staff+ Software Engineer to help build and evolve the identity infrastructure that supports OpenAI’s research, engineering, and internal platforms. This role sits at the intersection of cloud infrastructure, identity systems, and software engineering. You’ll work across production systems, infrastructure-as-code, cloud control planes, identity providers, and operational infrastructure to build secure, scalable, and reliable systems used broadly across the company. The ideal candidate has experience building and operating large-scale, mission-critical systems with strong reliability and security requirements, and is comfortable writing production code, designing distributed systems, and driving ambiguous projects from 0 to 1 while building the operational rigor needed to run critical infrastructure over time. In this role, you will: Lead the architecture, development, and operation of identity infrastructure that spans cloud platforms, internal systems, and critical engineering services. Design and evolve systems for authentication, authorization, access governance, auditability, and policy enforcement with a strong focus on reliability, scalability, and secure-by-default design. Build foundational infrastructure and platform capabilities that are broadly used across engineering, research, and security teams. Improve the reliability, observability, performance, and op
About the Team The IT and Security organization builds the systems, data foundations, and automation that help OpenAI operate securely and reliably at scale. We support critical domains across identity, access, infrastructure security, enterprise systems, and internal productivity. As OpenAI grows, audit readiness and control assurance increasingly depend on reliable data: accurate system inventories, access populations, change records, configuration state, exception signals, and evidence generated directly from source systems. Our goal is to move beyond manual evidence collection and build scalable data products, automated validation, and continuous control monitoring that make security and IT controls measurable, repeatable, and defensible. About the Role We are looking for an IT Controls Data Engineer to build the data infrastructure that powers audit readiness, IT controls, evidence automation, and continuous control monitoring. In this role, you will design and maintain the pipelines, datasets, models, validation logic, dashboards, and evidence exports that make IT controls measurable, repeatable, and defensible. You will work across Security, IT, Infrastructure, Engineering, Finance Risk Management, and auditors to turn complex system behavior into reliable control data products. This is a technical builder role. The ideal candidate is strong in data engineering and analytics engineering, comfortable working with enterprise and security system data, and able to explain data lineage, source-system behavior, and control logic clearly to technical and audit stakeholders. You’ll be responsible for Building reliable data pipelines, models, and datasets for IT controls, including access, identity, configuration, change, ticketing, exception, and evidence data. Creating data quality, lineage, reconciliation, and completeness checks that make control data defensible for SOX and other audit use cases. Designing automated evidence generation workflows that produce compl
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! Why this role? Cohere is in a unique and exciting position to grow our go-to-market teams globally! We are expanding our Talent Team and are looking for a creative, high-performing Talent Attraction and Employer Brand Specialist to help us build a world-class employer brand that attracts top frontier AI talent. In this role, you will shape how Cohere is perceived by the global AI community and drive strategic recruitment marketing initiatives that position us as the destination for ambitious researchers and engineers. Please Note: We have offices in Toronto, San Francisco, and London but embrace being remote-first! As a Talent Attraction and Employer Brand Specialist, you will: Develop and execute comprehensive brand strategy that defines and promotes Cohere's identity, culture, and technical leadership to target talent groups Run multi-channel recruitment marketing campaigns across social media, job boards, and search engines to reach priority candidates Create compelling content including job descriptions, employee success stories, and optimized career site landing pages Optimize and maintain our career site experience while t
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! Why this role? Cohere is in a unique and exciting position to grow our go-to-market teams globally! We are expanding our Talent Team and are looking for a dedicated Early Careers & Interns Specialist to help us build a world-class pipeline of future AI talent. In this role, you will design and execute comprehensive early careers programs that attract, develop, and retain top student and recent graduate talent, positioning Cohere as the premier destination for ambitious early-career professionals in AI. As an Early Careers & Interns Specialist, you will: Design and implement strategic early talent programs with clear goals for intern and graduate pipelines Align with early careers frameworks with Cohere's global growth plans and talent needs Story tell the comprehensive learning objectives and core projects for each intern cohort Build and maintain partnerships with top universities and colleges to source high-potential candidates Develop targeted employer branding strategies specifically for student markets Represent Cohere at career fairs and host on-campus recruitment events Partner with the People team to execute seam
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! Why this role? Cohere is in a unique and exciting position to grow our go-to-market teams globally! We are expanding our Talent Team and are looking for creative, high-performing talent sourcers who are eager to take on a new challenge as we are in the early stages of building the Talent Acquisition function. In this role, you will master a new domain of sourcing, source world-class business talent, and influence the scaling of a high-growth Canadian tech company. If you consider yourself resilient, collaborative, influential, and a lifelong learner with an established network, we’d love to hear from you! Please Note: We have offices in Toronto, San Francisco, and London but embrace being remote-first! As a Talent Sourcer, you will: Build, own, and nurture a strong pipeline of world-class business talent across Sales, Finance, Revenue, Marketing & Communications, and Operations Deliver a world-class recruiting experience that reflects Cohere's premium brand Partner with hiring managers and talent partners to find and engage passive talent through creative sourcing methods Maintain deep market intelligence on business talent
Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As Cohere scales its enterprise AI platform and accelerates its position as a leader in sovereign AI solutions, we need a strategic Corporate Development leader to drive high-impact partnerships, M&A, and long-term business development. This role will focus on expanding Cohere’s ecosystem through strategic alliances, channel relationships, and targeted acquisitions that support our growth in regulated industries, government sectors, and global markets. Key Responsibilities M&A Strategy: Evaluate and execute acquisitions or investments in complementary technologies that strengthen our core platform, particularly in compute infrastructure, specialized AI capabilities, and regulatory compliance tools Lead due diligence processes with cross-functional teams to ensure technical integration feasibility and strategic alignment Manage post-merger integration to maximize value realization and revenue synergies Market Expansion: Support entry into new verticals and geographies through targeted collaborations with industry leaders and government partners Develop market entry strategies that address regulatory requirements and sover
Higher-paying openings
Jobs with higher listed pay
Related career options
Similar roles with stronger pay
Demand 35/100 · 7 jobs
$4.6M – $4.6M/yr
Salary →Demand 46/100 · 8 jobs
$345K – $345K/yr
Salary →Demand 73/100 · 93 jobs
$294.5K – $294.5K/yr
Salary →Demand 51/100 · 22 jobs
$292.5K – $292.5K/yr
Salary →Demand 45/100 · 9 jobs
$255.7K – $255.7K/yr
Salary →Demand 77/100 · 123 jobs
$242.1K – $242.1K/yr
Salary →Other cities to consider
More places hiring for this role
Get new security grc analyst jobs in San Francisco, United States by email
Daily job updates · Unsubscribe anytime