Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Jasper is the marketing agents platform, built to help enterprises orchestrate AI agents that execute marketing work at scale. Purpose-built for marketing teams, Jasper enables faster, more consistent execution across campaigns, personalization, localization, and complianceāwhile maintaining enterprise-grade control and governance.
As a Senior GRC Lead at Jasper, you will own our Governance, Risk, and Compliance program end-to-endābuilding a program that scales with our AI-native products. You will step in to rebuild and maintain momentum on audits, risk management, and vendor security, partnering closely with Security, Legal, and Engineering to keep Jasper compliant and trustworthy as we grow.
Day-to-day, you will work alongside the Security team, while collaborating cross-functionally with Legal, GTM, People, and Engineering to embed compliance requirements into how the company builds and operates. You will serve as the subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagementsāmaking trust a competitive advantage for Jasper.
This fully remote role reports to the Director, Security and is open to candidates located anywhere in the continental US.
What you will do at Jasper
- Own and drive Jasperās compliance audits (SOC 2, ISO 27001, and similar frameworks) from readiness through certification, with a path toward ISO 42001.
- Support GDPR and broader privacy compliance alongside the Legal team, without owning the legal interpretation of requirements.
- Rationalize overlapping requirements across frameworks to reduce compliance burden and create a single source of truth for control ownership.
- Serve as the subject-matter expert on control mapping during customer and external audits, RFPs, and enterprise sales engagements.
- Respond to customer security questionnaires and support the sales and legal teams during due diligence.
- Maintain and continuously improve the risk register, including risk identification, scoring, and remediation tracking.
- Manage vendor and third-party risk assessments and the vendor security review process.
- Own policy managementādrafting, reviewing, and keeping security and compliance policies current.
- Partner cross-functionally with Security, Legal, Product, Engineering, etc to embed compliance and governance requirements into how the company builds and operates.
- Automate compliance workflows, including artifact collection for external audits, internal security compliance reviews, and continuous monitoring tasks.
- Drive, improve, and help implement AI governance across the company and product.
What you will bring to Jasper
- AI fluency ā a working understanding of core AI concepts (LLMs, agents, copilots, tokens, credits, context windows, RAG, data governance, etc.), applied in the context of governance, risk, and compliance for AI-native products.
- 8+ years of experience in Governance, Risk & Compliance, ideally at a SaaS company.
- Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001, NIST CSF, and at least one regulatory framework (GDPR, CCPA, HIPAA, or equivalent).
- Expertise in modern cloud-native web application development practices and related security best practices, especially in the context of GCP and frontier AI platforms.
- Experience with GRC tooling (e.g., Vanta, Drata, OneTrust, or similar).
- Experience managing a risk register and vendor risk program.
- Strong cross-functional communication ā comfortable working with Security, Legal, Product, and Engineering, and able to translate technical issues for non-technical teams.
- Experience using AI agents, tools, and platforms to automate workflows and build tools, with sound judgment in applying AI responsibly to improve efficiency and impact.
- Prior experience at a startup or fast-growing SaaS company.
- CISA, CISSP, CRISC, or similar certification.
- Experience scoping or pursuing ISO 42001 or other AI governance frameworks.
- Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python ā you donāt need to be a software engineer, but you should be fluent enough to use AI platforms to modify and run scripts, build automations, and ship small tools end-to-end.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Jasper
Explore Top Companies in this Space
Jasper
View Company ProfileJasper is an enterprise-grade, AI-powered marketing and content creation platform built for modern marketing teams and agencies. The company provides a comprehensive suite of AI tools and specialized agents that help businesses automate and scale the production of blog posts, social media campaigns, ad copy, emails, and website content. A core differentiator of Jasper is its focus on enterprise trust, security, and advanced brand control; its "Brand Voice" feature ensures that all AI-generated content adheres to a company's specific tone, style, and brand guidelines. By offering customizable workflows, campaign planning tools, and robust team collaboration features, Jasper enables organizations to execute go-to-market strategies faster and more efficiently while maintaining high-quality, on-brand messaging.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
