OpenAI6 дней назад
GRC Program Manager, Assurance Engineering & Control Systems
Зарплата не указана
Полная занятостьУдалёнка
Обязанности
- 01Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout.
- 02Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks.
- 03Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate.
- 04Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting.
- 05Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness.
- 06Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity.
- 07Reduce repeated requests and operational burden for control owners through measurable workflow improvements.
- 08Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations.
Требования
- 01Direct ownership of meaningful audit, security, customer-assurance, or regulatory outcomes.
- 02Practical knowledge of control design, evidence, testing, operating effectiveness, and remediation.
- 03Technical fluency across cloud systems, identity, logging, APIs, data flows, and system boundaries.
- 04Ability to use Codex or comparable AI-assisted development tools to build, run, inspect, and test a working solution.
- 05Experience using code, SQL, APIs, structured data, automation, or data workflows to solve an operational problem.
- 06Ability to design reusable cross-framework controls without erasing framework-specific test and evidence requirements.
- 07First-principles curiosity, creative problem solving, intellectual humility, and the ability to update when facts change.
- 08Product and program judgment: define the user, scope, milestones, ownership, adoption, and measurable outcome.
- 09Clear, constructive partnership with Security, Engineering, Infrastructure, Product, Privacy, Legal, and audit teams.
- 10Frameworks such as SOC 2, ISO 27001/27017, PCI DSS, NIST, or FedRAMP are helpful; a specific degree, certification, or prior access to internal OpenAI tools is not required.