Verified current Job

Senior Security Compliance (GRC) Manager

Why Aisle? AISLE is building the AI that finds, fixes, and verifies software vulnerabilities autonomously - an end-to-end system that closes the gap between when a vulnerability appears and when it's safely patched. Vulnerabilitie...

Job Full source details
Aisle Careers Prague, Czech Republic Source published Jul 21, 2026 Verified 10 hours ago
✓ 92% verification score · Source: Aisle Careers · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
Senior Security Compliance (GRC) Manager at Aisle Careers
EmploymentFull Time
DepartmentSecurity

Overview

Why Aisle? AISLE is building the AI that finds, fixes, and verifies software vulnerabilities autonomously - an end-to-end system that closes the gap between when a vulnerability appears and when it's safely patched. Vulnerabilities are the #1 root cause of cyber incidents, yet most organizations take weeks or months to remediate what attackers now exploit in days. We're ending that backlog. Our systems already find and fix vulnerabilities in the world's most heavily audited codebases - 375+ independently validated CVEs across projects like OpenSSL, curl, Linux, and Chromium - at machine speed and superhuman scale. AISLE runs entirely inside our customers' perimeter (cloud, on-prem, or fully air-gapped) and can run on our optimized models or theirs, so even the most sensitive organizations, including those operating critical infrastructure, stay in full control of their code and their mod

Full job description

Description

Full Job Description

Why Aisle?

AISLE is building the AI that finds, fixes, and verifies software vulnerabilities autonomously - an end-to-end system that closes the gap between when a vulnerability appears and when it's safely patched. Vulnerabilities are the #1 root cause of cyber incidents, yet most organizations take weeks or months to remediate what attackers now exploit in days. We're ending that backlog.

Our systems already find and fix vulnerabilities in the world's most heavily audited codebases - 375+ independently validated CVEs across projects like OpenSSL, curl, Linux, and Chromium - at machine speed and superhuman scale. AISLE runs entirely inside our customers' perimeter (cloud, on-prem, or fully air-gapped) and can run on our optimized models or theirs, so even the most sensitive organizations, including those operating critical infrastructure, stay in full control of their code and their models.

Backed by world-class founders, advisors, and angel investors, we're defining a new category: sovereign, AI-native security. Our goal isn't to improve vulnerability management - it's to end the backlog and move toward a future where software defends itself.

We’re a small, talent-dense team spread across Europe, the US and Canada. We value high ownership, high velocity, and low-ego collaboration. If you want to work with world-class minds in AI and security, thrive in fast-moving environments, and care about solving one of the toughest challenges in tech, Aisle is the place for you.

What You’ll Be Doing

  • SDLC & Product Security Integration: Lead application security reviews and threat modeling for core products, microservices, and LLM/AI integrations. Translate security policies directly into concrete engineering controls within the CI/CD pipeline.

  • AI Governance & Safety Architecture: Translate AI Management Policies (including ISO 42001 mandates) into engineering guardrails. Implement AI observability, prompt-injection defenses, and risk controls for RAG architectures, multi-tenant AI agents, and third-party LLM connectors.

  • Infrastructure & Trust Boundaries: Partner with Infrastructure/DevOps teams to design and enforce zero-trust architecture, multi-tenant isolation, and automated cloud compliance controls (AWS/Azure/GCP).

  • Automated Compliance & Security Tooling: Build and deploy internal security agents and automation scripts to handle vulnerability triage, log analysis, continuous control testing, and automated evidence collection for audits.

  • Audit Ownership & Technical Representation: Serve as the principal technical counterpart for ISO 27001, SOC 2, and ISO 42001 audits. Interface with external auditors by presenting real-time architectural proof and automated control evidence.

  • Security Engineering Enablement: Mentor software engineers on secure coding practices, threat modeling, and secure AI usage. Create code patterns (clear contracts, typed interfaces) that make secure-by-default development effortless for engineering.

  • Incident & Threat Runbooks: Maintain technical runbooks for emerging threat vectors, including AI-specific scenarios (data exfiltration, model behavior drift, cross-tenant exposure, and cost-bomb attacks).

Requirements

  • Professional Background: 5+ years combining GRC/Audit experience with hands-on exposure to Application Security, Security Engineering, or Cloud Infrastructure.

  • Technical Stack & Tooling: Familiarity with CI/CD security tools (SAST/DAST, dependency checkers), cloud infrastructure controls, script-level automation (Python, Bash, or Go), and automated GRC platforms (e.g., Vanta, Drata).

  • Architecture & Frameworks: Deep knowledge of mapping framework controls (SOC2, ISO 27001, ISO 42001, NIST, GDPR) directly to infrastructure configurations, network boundaries, and application code.

  • AI & LLM Security Literacy: Understanding of OWASP Top 10 for LLMs, threat modeling for RAG pipelines, and trust boundary definitions for autonomous AI agents.

  • Hands-on Execution: Ability to read code, analyze log streams, and discuss technical vulnerabilities with developers on their level.

  • Communication & Synthesis: Ability to bridge three worlds: explaining technical vulnerabilities to executive leadership, discussing API/code patterns with engineers, and satisfying external audit requirements.

  • Bonus Points: A background in Software Engineering, Cloud Architecture, or specialized certifications (e.g., CISSP, CCSP, OSCP, CISA).

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

Discovered directly from the employer’s public Ashby Job Postings API. The complete public role content and compensation metadata were normalized into safe candidate-facing sections. Complete structured details were extracted from the public authoritative source while preserving the original application link.

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Aisle Careers ↗

Browse current Job and Scholarship listings from Aisle Careers →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books