GRC项目经理, 美国政府合规
GRC Program Manager, US Government Compliance
关于团队
治理、风险与合规(GRC)是OpenAI安全业务的基础,确保实现任务目标。我们热衷于为模糊的安全需求构建创新解决方案,并将新技术交付给关键客户。GRC团队提供安全和工程专业知识,以确保客户的最严格和关键的需求得到满足。我们在构建技术时是技术导向的,但在工作方式上是务实的,致力于获得、扩展和维护关键系统的授权运营(ATO),同时培养协作和注重执行的文化。
关于职位
我们的技术支撑着世界上一些最重要和有影响力的工作,包括我们在公共部门的战略性和高影响力客户。作为GRC项目经理,您将在实现美国政府(USG)的ATO和合规框架(包括但不限于FedRAMP和国防部(DoW))方面发挥关键作用,为OpenAI产品以及在高度监管和安全环境中部署的系统提供特定机构的ATO。您将与工程师、内部利益相关者和外部评估人员密切合作,设计、记录并实施符合严格合规要求的安全控制措施。您的创造力和注重执行的方法对于应对复杂挑战并保持利益相关者的信任至关重要。
我们寻找具备以下条件的人:
- 在政府或受监管行业,在高度受限环境中,有获得和维护FedRAMP ATO和特定机构ATO的丰富经验。
- 深入理解美国政府安全框架和政策(例如NIST、RMF、FedRAMP)。
- 能够向不同受众(包括工程师和非技术人员)传达技术概念。
- 优秀的技术项目管理能力,能够多任务处理并在压力下交付大型复杂项目。
该职位位于华盛顿特区。我们采用每周3天在办公室的混合办公模式,并为新员工提供搬迁协助。
在此职位中,您将:
- 在受限环境中,为FedRAMP及多个政府客户推动ATO流程,且在最小监督下进行。
- 与工程团队合作,解读安全需求并实施平衡合规与运营需求的控制措施。
- 创建清晰、简洁和技术性的文档,支持安全控制的实施和审计。
查看英文原文
About the Team
Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture.
About the Role
Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government (USG) ATOs and compliance frameworks, including but not limited to FedRAMP and Department of War (DoW),for OpenAI products and support agency-specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders.
We’re looking for people who bring:
- Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors.
- A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP).
- Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders.
- Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure.
This role is based in Washington, DC. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.
In this role, you will:
- Drive the ATO process for FedRAMP and across multiple government clients in restricted environments with minimal oversight.
- Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.
- Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.
- Act as a subject matter expert during audits and assessments, representing the organization with credibility and expertise.
- Continuously refine processes to improve the efficiency and quality of compliance efforts.
You might thrive in this role if you:
- An active US security clearance.
- 5+ years of compliance experience in positions involving information security, data security, or infrastructure or network security.
- Familiarity with deployment models, including to cloud platforms (Azure, AWS) and the underlying infrastructure primitives (Kubernetes, Terraform).
- Strong familiarity with core security concepts and technologies, such as authentication, encryption, vulnerability management, and audit logging.
- The ability to work collaboratively and effectively in a cross-functional team environment.
- Thrive in dynamic environments and can navigate ambiguity with ease.
About OpenAI
OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.
We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.
For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement https://cdn.openai.com/policies/eeo-policy-statement.pdf.
Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.
To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form https://form.asana.com/?d=57018692298241&k=5MqR40fZd7jlxVUh5J-UeA. No response will be provided to inquiries unrelated to job posting compliance.
We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link https://form.asana.com/?k=bQ7w9h3iexRlicUdWRiwvg&d=57018692298241.
OpenAI Global Applicant Privacy Policy https://cdn.openai.com/policies/global-employee-and-contractor-privacy-policy.pdf
At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.