Security specialist, GRC (UK)
full-time
junior
Posted 1 month ago
About this role
🚀 ABOUT WRITER
WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving it's possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER's end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company's data and fueled by WRITER's enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Austin, Chicago, and London, our team thinks big and moves fast, and we're looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
📐 ABOUT THE ROLE
This is your chance to shape AI governance from the ground up at one of the fastest-growing companies in enterprise AI. As a security specialist, GRC at WRITER, you'll be building the frameworks that ensure our AI platform earns and keeps the trust of the world's most demanding enterprises. You're not just checking boxes—you're creating the compliance infrastructure that enables WRITER to scale safely and securely while moving at the speed of innovation.
The opportunity here is extraordinary: you'll work at the intersection of AI, security, and business enablement, helping define what governance looks like for enterprise AI systems that didn't exist a few years ago. You'll lead audit engagements for SOC 2, ISO 27001, and other critical certifications, respond to customer security assessments that directly impact major deals, and build the policies and controls that protect both our AI models and the sensitive data flowing through them. You'll translate complex regulatory requirements into practical, business-aligned security controls while partnering with Engineering, Legal, Product, and Sales to ensure WRITER can sell into highly regulated industries without compromising our velocity.
This role is hybrid from our London office, reporting to the head of security.
🦸🏻♀️ WHAT YOU'LL DO
- Own and drive WRITER's security compliance program end-to-end including managing SOC 2 Type II audits, ISO Triad (27001/27701/42001) certification, and expanding our compliance coverage to meet emerging customer requirements in regulated industries like financial services and healthcare
- Lead customer assurance efforts by responding to security questionnaires, DDQs, and RFPs from enterprise customers, maintaining our trust portal with up-to-date security documentation, and partnering with Sales to remove security blockers that could delay major deals
- Build and maintain WRITER's security governance framework including creating and updating security policies, access control standards, vendor risk procedures, incident response plans, and AI-specific governance documentation that addresses model training, data handling, and responsible AI deployment
- Conduct continuous control monitoring and evidence collection by implementing automated compliance workflows, tracking remediation activities across teams, performing control testing, and ensuring we maintain audit-ready documentation throughout the year instead of scrambling before audits
- Drive risk assessments and third-party vendor security reviews by evaluating supplier controls, identifying and quantifying security risks across our AI platform and infrastructure, and working cross-functionally to prioritize and track remediation efforts
- Partner with Engineering and Product teams to embed compliance into the development lifecycle by reviewing architecture decisions for security and privacy implications, ensuring secure-by-design principles are followed for new AI features, and translating regulatory requirements into technical controls that developers can actually implement
- Serve as the primary point of contact for external auditors and assessors, coordinating evidence collection, scheduling interviews, addressing findings, and ensuring audit processes run smoothly while minimizing disruption to the broader team
⭐️ WHAT YOU NEED
- 2+ years of hands-on experience in GRC, security compliance, or audit roles within fast-paced tech companies or startups—you understand how to build compliance programs that enable growth rather than slow it down
- Deep working knowledge of security frameworks and certifications including SOC 2 Type II, ISO 27001, GDPR, CCPA, and familiarity with emerging AI governance requirements—you've led audits from planning through certification and can speak confidently about control requirements
- Strong technical literacy that allows you to evaluate cloud security architectures, understand API sec
Similar Jobs
Related searches:
Hybrid Jobs
Junior Jobs
Hybrid Junior Jobs
Junior AI Agents & RAGJunior Healthcare AIJunior Generative AIJunior Machine LearningJunior NLP & Language AI
AI Jobs in London
AI Agents & RAG in LondonHealthcare AI in LondonGenerative AI in LondonMachine Learning in LondonNLP & Language AI in London
generative-aihealthcarellmagents