远程工作雷达

GRC项目经理,审计与控制

GRC Program Manager, Audit & Controls

开发工程未标注地域
公司Openai
薪资$216,000 - $252,000
工作地点San Francisco
地域资格未标注地域
时区要求无特别要求
用工类型FullTime
发布时间2026-08-06
数据来源Ashby
前往企业招聘页投递 →

关于团队

OpenAI 的治理、风险与合规团队帮助确保安全和隐私在我们的产品和系统实际运行方式中得到落实。保证运营与安全、工程、基础设施、产品、隐私和法律团队合作,使控制措施可证明,风险决策明确,并将审计准备作为良好设计系统的自然结果。

关于该职位

我们正在招聘一位技术导向、注重产品的 GRC 构建者,能够负责重要的审计工作,同时改进其背后的控制和证据系统。您将构建一个可复用的通用控制框架,使用 Codex 自动化保证工作,验证不断变化的系统范围,并将重复的审计摩擦转化为可衡量的改进。我们寻找一位能够质疑继承的假设、创造性地解决新问题、与工程师紧密合作,并通过改进底层系统让下一次审计更容易的人。

您将负责:

- 从范围定义到证据审查、现场工作、整改和结束,主导外部、内部、客户和认证审计工作。

- 构建一个通用控制框架,连接风险、控制意图、实施、负责人、系统、环境、证据和适用框架。

- 验证实际范围和所有权,而不是假设去年的控制、产品边界或证据仍然准确。

- 使用 Codex 构建和测试证据检查、控制映射、请求分类、负责人工作流、监控和整改报告。

- 与工程师合作,涉及云架构、身份、日志、数据流、软件变更、漏洞和控制有效性。

- 设计可维护的、权限感知的工具,保留源出处、人工审核和证据完整性。

- 通过可衡量的工作流改进,减少控制负责人重复的请求和操作负担。

- 定义路线图、决策权、里程碑、成功指标和清晰的跨职能升级流程。

我们寻找具备以下条件的人:

- 直接负责有意义的审计、安全、客户保证或监管成果。

- 具备控制设计、证据、测试、操作有效性和整改的实际知识。

- 在云系统、身份、日志、API、数据流和系统边界方面具备技术熟练度。

- 能够使用 Codex 或类似的 AI 辅助开发工具构建、运行、检查和测试一个可行的解决方案。

- 具有使用代码、SQL、API 和结构化数据的经验

查看英文原文

About the Team

OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems.

About the Role

We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system.

You’ll be responsible for:

- Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout.

- Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks.

- Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate.

- Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting.

- Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness.

- Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity.

- Reduce repeated requests and operational burden for control owners through measurable workflow improvements.

- Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations.

We’re looking for someone with:

- Direct ownership of meaningful audit, security, customer-assurance, or regulatory outcomes.

- Practical knowledge of control design, evidence, testing, operating effectiveness, and remediation.

- Technical fluency across cloud systems, identity, logging, APIs, data flows, and system boundaries.

- Ability to use Codex or comparable AI-assisted development tools to build, run, inspect, and test a working solution.

- Experience using code, SQL, APIs, structured data, automation, or data workflows to solve an operational problem.

- Ability to design reusable cross-framework controls without erasing framework-specific test and evidence requirements.

- First-principles curiosity, creative problem solving, intellectual humility, and the ability to update when facts change.

- Product and program judgment: define the user, scope, milestones, ownership, adoption, and measurable outcome.

- Clear, constructive partnership with Security, Engineering, Infrastructure, Product, Privacy, Legal, and audit teams.

- Frameworks such as SOC 2, ISO 27001/27017, PCI DSS, NIST, or FedRAMP are helpful; a specific degree, certification, or prior access to internal OpenAI tools is not required.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement https://cdn.openai.com/policies/eeo-policy-statement.pdf.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241.

OpenAI Global Applicant Privacy Policy https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

学习产品经理

OpenaiSan Francisco$293,000 - $385,000FullTime21 天前
AI职能支持全球可投(据职位描述推断)

← 返回全部职位