# Security GRC Lead at Mercor

- Company: Mercor
- What the company does: Mercor is organizing human intelligence to power the AI economy. We are powering frontier research, AI benchmarks, and AI agent training at scale for the top AI labs and enterprises. Backed by General Catalyst and Menlo.
- Company website: https://mercor.com/
- Type: Startups
- Level: Senior
- Location: San Francisco
- Work setup: On-site
- Pay: $350K to $425K base salary per year (USD)
- Posted: 2026-09-09
- Apply by: 2026-10-24
- Apply: https://jobs.ashbyhq.com/mercor/3ecb8ca3-2145-4f52-88ea-17d64817a03a
- Page: https://www.1752.vc/careers/jobs/mercor-security-grc-lead/

## About the role

You'll be the first GRC hire at a company that processes some of the most sensitive data on earth: training data, evals, and human-feedback pipelines for the frontier AI labs, plus payments and KYC for 300K+ experts.

## What they're looking for

- 7+ years in security GRC, compliance engineering, or audit, with at least 2 years owning a SOC 2 Type 2 program end-to-end at a company under audit by enterprise customers
- You've shipped at least one ISO 27001 certification from kickoff to issued certificate, including Stage 1 and Stage 2 with a real registrar
- Fluent in Vanta (or Drata, Secureframe, Sprinto) at the integration and admin level, not just the reviewer UI - you've configured connectors, written custom tests, debugged broken evidence
- You translate cloud-security language to auditor language and back without losing precision - you can read a Wiz finding, a Panther rule, an IAM policy, and say what control it maps to
- You write controls as code or query evidence with SQL when the platform falls short - Python, SQL, or shell, whatever it takes
- You know the difference between "we don't have a control for that" and "we have a compensating control" and you don't fabricate the second one

Tags: Security
