OpenAI logo

OpenAI

GRC Program Manager, Product Lifecycle Assurance

Hybrid

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · San Francisco

Employer listed it 3 weeks ago · Added 5 days ago

Been open since 3 weeks ago, still being checked, but it has been live a while.

Salary

$216,000 to $240,000

Location

Hybrid · San Francisco

Timezone

Not stated

Contract

Full-time

Experience

Mid

Category

Software

Published by the employer

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around San Francisco, New York City, Seattle, Washington, DC, Hybrid, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "San Francisco, New York City, Seattle, Washington, DC, Hybrid"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About the Team

Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. We are technical in what we build but operational in how we do our work, and we partner deeply with Product, Security, Legal, Privacy, GTM, and Field Security to help OpenAI move quickly while maintaining trust with customers, auditors, regulators, and the public.

About the Role

We are looking for an experienced Product Lifecycle Assurance IC to help scale OpenAI’s GRC function across our product stack to ensure products address customer and regulatory compliance requirements at launch and regressions are detected promptly and corrected.

You will partner closely with Product, Security, Legal, and Privacy teams to make sure OpenAI can move quickly while maintaining our security, privacy and compliance claims and giving customers, auditors, and regulators assurance about how OpenAI handles user data. You are responsible for product assurance end-to-end from inception to post-launch (continuous) monitoring. You leverage existing workflows, reviews, and data and enhance, augment and build the components needed to create an end-to-end product assurance program.

This role is not about supporting SOC or ISO audits; it's a highly cross-functional and deeply technical operations role to ensure that OAI products meet the compliance bar at launch, regressions are prevented and detected, and our compliance state can be evidenced. This role also helps ensure that our product launch governance program operates effectively across key safety, privacy, legal and security stakeholders and lessons-learned from incidents and regressions are used to improve the program.

You or in partnership with engineering teams, build key controls in our infrastructure stack, developer workflows and launch tooling to provide developers with guardrails, perform CI/CD conformance checks, and surface launches that need GRC guidance. You ensure that teams have the information needed to design and launch safety and meet them where they are. You exercise sound judgement in making high-stakes decisions related to product launch risk and controls.

You are comfortable working in high velocity, low friction development environments. Your work goes across team boundaries and you assist and enable other teams to realize product assurance objectives. You should be comfortable with complex (Kubernetes) system architectures and dataflows, working with engineering teams to understand what could go wrong and where and how controls should be applied. You should be comfortable working with Privacy engineering and Data Science to understand data maps and database schemas and leverage existing processes and controls to further product assurance goals.

We’re looking for people who bring:

Strong technical product lifecycle assurance and security and privacy compliance experience working in high velocity, low friction development environments.

Experience building technical controls, metrics, monitoring tools, CI/CD tooling, high-fidelity risk signals and dashboards to meet product assurance goals

Ability to run an end-to-end, cross-functional, product assurance program applying judgement where what type of process or controls should be in place to meet a high assurance bar

Capacity to shift product assurance to the left in the product development cycle with just-in-time controls, guidance, guardrails and responsible friction for developers

Low ego outcome oriented mindset to achieve the product assurance goal required for OAI’s mission

Strong technical cross-functional leadership and don’t work in a vacuum - they influence, align and direct partner teams to achieve product assurance goals.

Exercise sound judgement in making high-stakes decisions related to product launch risk and controls.

You’ll be responsible for:

The end-to-end effective operation of OAI’s product assurance program from product development to post-launch (continuous) monitoring

Owning the GRC product assurance program, providing governance over Safety, Deployment, Security, Legal reviews to ensure we effectively surface product risk and design scalable mitigations

Driving cross-function collaboration and accountability in all aspects of the product assurance program

Building controls and low-friction, scalable processes in our infrastructure stack, developer workflows and launch tooling to ensure effective product assurance

Ensuring that teams have the guidance needed to design and launch safety and meet them where they are

Ensuring compliance, security and privacy claims and maps to verifiable controls

Recognizing how the product lifecycle assurance program fits into the large organizational objectives and when to build and when to influence and maintain strong partnerships with partner teams and influence roadmaps to further assurance goals

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at OpenAI, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$216,000 to $240,000 · You'll be taken to the employer's careers page.