Security GRC Specialist

South San Francisco, CA · Toronto, Canada · South San Francisco · TorontoPosted Jul 30, 2026

About Phylo

Phylo is an applied research lab building agentic intelligence to accelerate biomedical discovery. Spun out of Stanford’s Biomni project, our team brings together researchers, engineers, and scientists across AI and biology. We are backed by a $13.5 million seed round led by a16z, Menlo Ventures, and Anthropic.

About the Role

We’re hiring a hands-on Security & Compliance Lead to build and scale Phylo’s security, privacy, and compliance program. You’ll own our compliance roadmap, lead audits and customer reviews, and work closely with engineering to turn requirements into practical controls.

What You’ll Do

  • Own Phylo’s security and compliance roadmap.

  • Lead SOC 2, ISO 27001 and GDPR readiness, audits, evidence collection, and remediation.

  • Build HIPAA-ready processes for workloads involving protected health information.

  • Assess and plan for FedRAMP, NIST, privacy, and life-sciences requirements where applicable.

  • Partner with engineers to implement scalable controls across cloud infrastructure, applications, and AI systems.

  • Lead customer questionnaires, RFPs, due diligence, and security conversations.

  • Run risk assessments and drive remediation across systems, vendors, and processes.

  • Maintain lightweight policies, customer-facing security documentation, and compliance reporting.

  • Automate evidence collection, monitoring, and other compliance workflows.

What We’re Looking For

  • 5+ years in security GRC, compliance, or a security engineering-adjacent role.

  • Experience leading SOC 2, ISO 27001, HIPAA, FedRAMP, or similar programs.

  • Strong understanding of cloud and application security.

  • Ability to translate regulatory requirements into technical controls.

  • Experience supporting audits and enterprise customer security reviews.

  • Strong cross-functional communication and program ownership.

  • A pragmatic, hands-on approach suited to an early-stage company.

Nice to Have

  • Experience building a security program from an early stage.

  • Background in healthcare, life sciences, enterprise AI, or cloud infrastructure.

  • Experience with HIPAA, FedRAMP, NIST SP 800-53, HITRUST, or GDPR.

  • Familiarity with AI governance frameworks such as NIST AI RMF or ISO 42001.

  • Experience automating GRC and compliance workflows.

Why Phylo?

You’ll shape the security foundation for technology designed to accelerate biomedical discovery. This is an opportunity to work alongside exceptional researchers and engineers, influence product and infrastructure decisions, and build a high-impact program from the ground up.

Why Join Us?

  • Competitive salary and equity share in building the future of biomedical discovery

  • Full medical, dental, and vision coverage, including free therapy sessions and eyewear stipend

  • 401(k) to help you build long-term financial security (US only)

  • Unlimited PTO to recharge when you need it (US only)

  • Lunch and snacks when you're in the office

  • Regular team offsites and company events

  • A culture of excellence and speed - we move fast, think big, and support each other every step of the way

  • Your work will directly impact our mission to 100X biomedical discoveries through AI

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free