Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
 GRC Program Manager, Public Sector image - Rise Careers
Job details

GRC Program Manager, Public Sector - job 1 of 2

About the Team

Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture. 

About the Role

Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving FedRAMP ATOs for OpenAI products and support agency specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders.

We’re looking for people who bring:

  • Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors.

  • A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP).

  • Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders.

  • Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure.

This role can be based in San Francisco, CA, Seattle, WA, New York City, NY or Washington, DC. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.

In this role, you will:

  • Drive the ATO process for FedRAMP and across multiple government clients in restricted environments with minimal oversight.

  • Collaborate with engineering teams to interpret security requirements and implement controls that balance compliance with operational needs.

  • Create clear, concise, and technically accurate documentation, including System Security Plans (SSPs), risk assessments, and architecture diagrams.

  • Act as a subject matter expert during audits and assessments, representing the organization with credibility and expertise.

  • Continuously refine processes to improve the efficiency and quality of compliance efforts.

You might thrive in this role if you:

  • An active US security clearance.

  • 5+ years of compliance experience in positions involving information security, data security, or infrastructure or network security. 

  • Familiarity with deployment models, including to cloud platforms (Azure, AWS) and the underlying infrastructure primitives (Kubernetes, Terraform).

  • Strong familiarity with core security concepts and technologies, such as authentication, encryption, vulnerability management, and audit logging.

  • The ability to work collaboratively and effectively in a cross-functional team environment.

  • Thrive in dynamic environments and can navigate ambiguity with ease. 

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. 

We are an equal opportunity employer and do not discriminate on the basis of race, religion, national origin, gender, sexual orientation, age, veteran status, disability or any other legally protected status. 

OpenAI Affirmative Action and Equal Employment Opportunity Policy Statement

For US Based Candidates: Pursuant to the San Francisco Fair Chance Ordinance, we will consider qualified applicants with arrest and conviction records.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

OpenAI Glassdoor Company Review
4.2 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
OpenAI DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of OpenAI
OpenAI CEO photo
Sam Altman
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About GRC Program Manager, Public Sector, OpenAI

Are you ready to take on a pivotal role as a GRC Program Manager in the heart of Washington with OpenAI? Our Governance, Risk, and Compliance (GRC) team is where creativity meets operational excellence as we address the most challenging security requirements for our public sector clients. In this role, you will be instrumental in achieving FedRAMP Authorizations to Operate (ATOs) for our innovative products, collaborating closely with engineers and stakeholders to ensure compliance with the highest security and regulatory standards. Your ability to adapt and refine processes will help streamline our compliance efforts while building trust with our clients. We are looking for someone with a strong background in security frameworks like NIST and a proven ability to communicate complex technical concepts to a wide range of audiences. Known for your exceptional program management skills, you will juggle multiple priorities and deliver under pressure, all while maintaining a collaborative and thriving work culture. You'll enjoy the flexibility of our hybrid work model and the opportunity for relocation assistance if you're joining us from outside the area. At OpenAI, we are dedicated to advancing the responsible deployment of artificial intelligence, and we want you to be a part of this exciting journey. Together, we can tackle some of the most important challenges worldwide, making a real impact in the public sector. Your expertise can be instrumental in achieving and maintaining compliance in a mission-driven environment, making this not just a job but a commitment to changing the future for the better.

Frequently Asked Questions (FAQs) for GRC Program Manager, Public Sector Role at OpenAI
What are the main responsibilities of a GRC Program Manager at OpenAI?

As a GRC Program Manager at OpenAI, your primary responsibilities will include driving the ATO process for FedRAMP and working with various government clients. You'll collaborate with engineering teams to develop and implement security controls that ensure compliance while balancing operational needs. Additionally, you'll create essential technical documentation and represent the organization as a subject matter expert during audits.

Join Rise to see the full answer
What qualifications are needed for a GRC Program Manager position at OpenAI?

To be a successful GRC Program Manager at OpenAI, you should have over 5 years of compliance experience, particularly in information security. A deep understanding of USG security frameworks like NIST and FedRAMP is crucial, along with prior experience in achieving and maintaining ATOs in highly regulated environments. Excellent communication and multitasking skills will also be essential.

Join Rise to see the full answer
Can I work remotely as a GRC Program Manager at OpenAI?

Yes! OpenAI operates with a hybrid work model, allowing GRC Program Managers to enjoy the flexibility of working from home three days a week. This setup helps promote a balanced work-life while still fostering collaboration in office settings.

Join Rise to see the full answer
What does the onboarding process look like for a GRC Program Manager at OpenAI?

The onboarding process for the GRC Program Manager role at OpenAI includes a comprehensive introduction to the team and our operational processes. You'll receive support and training to navigate the compliance landscape effectively, ensuring you have the tools necessary to succeed in your role from day one.

Join Rise to see the full answer
What skills will help me thrive as a GRC Program Manager at OpenAI?

A successful GRC Program Manager at OpenAI will benefit from strong technical program management skills, knowledge of security principles, and experience with cloud platforms like AWS or Azure. Moreover, agility in navigating dynamic and ambiguous environments while fostering teamwork will be key to achieving success.

Join Rise to see the full answer
Common Interview Questions for GRC Program Manager, Public Sector
How do you approach developing security controls that satisfy compliance requirements?

When developing security controls to meet compliance requirements, I first conduct a thorough analysis of the specific regulations and the organization’s operational needs. I collaborate closely with engineering teams to ensure the controls are technically feasible and documented clearly. Effective communication with both technical and non-technical stakeholders is vital to ensure everyone understands the implications and necessity of these controls.

Join Rise to see the full answer
Can you describe your experience with obtaining FedRAMP ATOs?

I have extensive experience in obtaining FedRAMP ATOs, during which I've navigated the auditing processes and coordinated with both internal and external assessors. I ensure all necessary documentation, including System Security Plans and risk assessments, are complete and accurately reflect the security posture of our systems. I focus on building relationships with stakeholders to facilitate a smooth ATO process.

Join Rise to see the full answer
What is your methodology for collaborating with cross-functional teams?

My methodology revolves around open communication and a clearly defined project structure. I establish regular check-ins and status updates to ensure everyone is aligned. I encourage feedback and foster an environment where team members can voice concerns or ideas. This collaborative approach not only enhances productivity but also builds trust and engagement among team members.

Join Rise to see the full answer
Discuss a challenge you faced in GRC and how you overcame it.

One significant challenge was navigating complex regulatory shifts that impacted compliance timelines. To overcome this, I spearheaded an initiative that involved reassessing our current security policies and aligning them with the new regulations. I collaborated with compliance experts, provided training to teams on the changes, and adjusted our documentation processes, which ultimately streamlined our compliance efforts and maintained stakeholder trust.

Join Rise to see the full answer
How do you keep up-to-date with security frameworks and compliance changes?

I prioritize ongoing education by subscribing to industry publications and attending relevant conferences and webinars. I also participate in networking groups focused on compliance and security, which provides insights into emerging trends and best practices. This keeps me well-informed and allows me to adapt our strategies in response to any changes in the landscape.

Join Rise to see the full answer
What role does documentation play in your compliance efforts?

Documentation is crucial in compliance efforts, as it serves as the foundation for audits and assessments. I ensure that all documents—such as risk assessments, security plans, and compliance reports—are not only thorough and accurate but also user-friendly. Clear documentation helps facilitate better understanding among teams and external assessors, and it supports operational effectiveness.

Join Rise to see the full answer
What experience do you have with cloud environments and security?

I have worked extensively within cloud environments, particularly AWS and Azure, where I focused on implementing security controls that align with compliance requirements. My experience includes managing infrastructure as code, utilizing services like Kubernetes, and ensuring robust security practices around authentication, encryption, and auditing. This technical background enables me to effectively support compliance efforts and address security challenges.

Join Rise to see the full answer
Why is effective communication essential for a GRC Program Manager?

Effective communication is vital for a GRC Program Manager to bridge the gap between technical and non-technical stakeholders. Clear communication ensures that security requirements and compliance needs are understood and addressed at all levels of the organization, ultimately facilitating smoother compliance processes and fostering a culture of security awareness across teams.

Join Rise to see the full answer
How do you measure the effectiveness of your GRC initiatives?

I measure the effectiveness of GRC initiatives through a combination of quantitative and qualitative metrics. Key performance indicators, such as successful ATOs achieved, audit scores, and compliance breaches, provide valuable data. Additionally, stakeholder feedback and team engagement levels help assess how well initiatives are being received and their impact on operational efficiency.

Join Rise to see the full answer
Describe a time when you had to present to a non-technical audience about security issues.

When presenting to a non-technical audience about security issues, I focus on simplifying complex concepts into relatable terms. I prepared a presentation that highlighted potential risks using analogies and real-world cases to illustrate the impacts of these threats. This approach helped the audience grasp the significance of security measures without getting lost in technical jargon, fostering a deeper understanding and support for our initiatives.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Feedback Forward
Collaboration over Competition
Growth & Learning

Join OpenAI as an Account Director to shape business strategies that leverage advanced AI technologies for Mid Market & Enterprise clients.

Photo of the Rise User
Posted 7 days ago
Inclusive & Diverse
Feedback Forward
Collaboration over Competition
Growth & Learning

As an Account Director at OpenAI, you'll drive success for top startups by leveraging our advanced AI models and fostering critical partnerships.

Photo of the Rise User
ServiceNow Remote Remote, West Palm Beach, Florida, United States
Posted 8 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity

As a Principal Solution Architect at ServiceNow, you will play a pivotal role in empowering organizations with innovative AI-enhanced Workflow solutions.

Photo of the Rise User

Take ownership of IT strategy in a fast-scaling European tech company focused on transforming frontline work.

Photo of the Rise User
Posted 8 days ago

Stride, Inc. is on the lookout for a Solution Architect who will leverage their expertise in technology and communication to deliver effective solutions.

Posted 13 hours ago

Join the National Internet Observatory as a Virtualization Systems Engineer to play a pivotal role in managing their private-cloud infrastructure.

Join our team as a 3rd Line Desktop Support Engineer in the Defence sector, providing expert technical support and infrastructure management.

Photo of the Rise User
Posted 8 hours ago

An exciting opportunity for a seasoned MS Fabric Architect to drive data architecture initiatives in a hybrid working environment.

Photo of the Rise User
Posted 10 days ago

Join Oak Street Health as a Medical Scribe to support primary care providers and improve healthcare delivery for Medicare patients.

Photo of the Rise User

Join UChicago Medicine as an IAM Analyst to enhance security and optimize systems in a hybrid work environment.

OpenAI is a US based, private research laboratory that aims to develop and direct AI. It is one of the leading Artifical Intellgence organizations and has developed several large AI language models including ChatGPT.

818 jobs
MATCH
VIEW MATCH
BADGES
Badge ChangemakerBadge Future MakerBadge InnovatorBadge Future UnicornBadge Rapid Growth
CULTURE VALUES
Inclusive & Diverse
Feedback Forward
Collaboration over Competition
Growth & Learning
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 23, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
C
Someone from OH, Akron just viewed Phlebotomy Technician - Outpatient at CCF
Photo of the Rise User
Someone from OH, Solon just viewed Graphic Designer at Applause
Photo of the Rise User
Someone from OH, North Canton just viewed NodeJs developer at BlackStone eIT
Photo of the Rise User
Someone from OH, North Canton just viewed Software Development Engineer - Recent Grads Welcome at Sonos
Photo of the Rise User
16 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry and Word Processing at MoxieIT
Photo of the Rise User
Someone from OH, Dayton just viewed Content Developer - Intern at Big Ideas Learning
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Lead at Bounteous
Photo of the Rise User
Someone from OH, Pickerington just viewed Industry Lead - High Tech (Salesforce) at Thunder
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Success Manager, US SLED at Dataminr