Higgsfield AI Logo

Higgsfield AI

Lead GRC Engineer

Posted One Month Ago
Remote or Hybrid
Hiring Remotely in CA
Senior level
Remote or Hybrid
Hiring Remotely in CA
Senior level
Build and automate technical security, privacy, and compliance controls across cloud, identity, HR, source control, CI/CD, and SaaS systems. Develop continuous monitoring, dashboards, alerts, release gates, evidence collection, control testing, and exception management. Design AI-assisted GRC workflows and support AI assurance initiatives. Collaborate with Security, Engineering, Privacy, Legal, auditors, and customer security teams in a fast-moving 0-to-1 environment.
The summary above was generated by AI

Why work at Higgsfield AI?
Higgsfield AI is the fastest-scaling generative AI company in history, hitting $500M in annual revenue run rate, 25M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands.
We're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.
About the role:

We’re looking for a Lead GRC Engineer to build the technical foundation of our security and compliance program as Higgsfield scales.

This is not a traditional GRC role focused primarily on policies, audits, and evidence collection. We’re looking for a builder who can translate security, privacy, and compliance requirements into technical, automated, and continuously monitored controls.

You’ll work closely with Security, Engineering, Privacy, Legal, and other teams to design controls that work for Higgsfield today while building the infrastructure we’ll need several years from now.

What You’ll DoBuild Controls & Compliance Infrastructure
  • Translate security, privacy, and compliance requirements into technical controls, automated checks, and enforcement mechanisms.

  • Build pipelines and integrations that aggregate control, asset, identity, and system data across cloud infrastructure, IdP, HRIS, source control, CI/CD, and SaaS applications.

  • Turn that data into automated control checks, live monitoring, dashboards, alerts, and audit-ready evidence.

  • Build preventative controls and release gates that identify or block security and privacy issues before they reach production.

  • Design controls that remain effective as our employees, locations, vendors, systems, infrastructure, and products rapidly change.

Automate Evidence & Continuous Assurance
  • Build a unified controls approach where evidence can be collected once and mapped across multiple frameworks and requirements.

  • Automate evidence collection, control testing, monitoring, and exception management rather than relying on point-in-time reviews.

  • Integrate with systems and controls already owned by Security, Engineering, IT, and other teams rather than creating parallel processes.

  • Continuously test whether controls are actually working and detect when they regress or drift.

  • Instrument control effectiveness so security and GRC stakeholders can understand risk posture from live data rather than periodic assessments.

Build AI-Native GRC Workflows
  • Design agentic and AI-assisted workflows for evidence analysis, control testing, monitoring, and audit-response preparation.

  • Apply strong judgment around what can be delegated to AI, what requires human review, and how both should be evidenced.

  • Help build the technical evidence base for AI-related certifications and assurance, including areas such as agent activity, evaluations, tool restrictions, and failure modes.

  • Partner with Product and Engineering as AI assurance standards and customer expectations continue to evolve.

Requirements:

  • 6+ years spanning security, GRC, software engineering, automation engineering, or related technical roles.

  • Demonstrated experience translating framework, regulatory, or policy requirements into technical implementations.

  • Hands-on experience personally building or automating security and compliance controls.

  • Production-grade scripting or programming experience, such as Python, including working with APIs and integrations.

  • Strong understanding of frameworks such as SOC 2 and ISO 27001 and what constitutes credible control evidence.

  • Ability to distinguish between a control that technically exists and one that is actually effective, enforced, and continuously monitored.

  • Experience building in rapidly changing or 0→1 environments without relying on mature infrastructure or large teams.

  • Strong judgment around automation, risk, exceptions, enforcement, and engineering velocity.

  • Ability to communicate technical controls and evidence clearly to auditors, customer security teams, engineers, and nontechnical stakeholders.

Compensation & Benefits

  • We offer a competitive and thoughtfully structured compensation package designed to align with impact, experience, and long-term growth.

  • Base Salary: The anticipated salary range for this role is $220,000 - $280,000, depending on experience, skills, scope, and location.

• Bonus: This role is Bonus eligible and may participate in the Company's discretionary annual bonus program.

  • Equity: In addition to cash compensation, employees are eligible to participate in the company’s stock option program and share in Higgsfield’s long-term growth.

  • Benefits: We offer a comprehensive benefits package designed to support employees professionally and personally, including medical, dental, and vision insurance, a competitive 401(k) retirement plan with company matching, and additional benefits and perks.

  • The opportunity to work on ambitious AI products alongside a highly experienced, fast-moving, and international team.

  • Significant ownership, direct impact, and opportunities for professional growth as the company scales.

This is a hybrid role based in the San Francisco Bay Area. Team members are expected to work from our San Francisco office three full days per week, with the remaining days worked remotely and are expected to be available during agreed working hours and to maintain sufficient overlap with the relevant team’s time zone. We value in-person collaboration, active communication, responsiveness, and close partnership across teams.

Higgsfield AI is an equal opportunity employer. We are committed to building a diverse and inclusive team and do not discriminate on the basis of race, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic.

Similar Jobs

Yesterday
Remote or Hybrid
Québec, QC, CAN
Mid level
Mid level
Cloud • Information Technology • Security • Software • Cybersecurity
Drive new business for Cloudflare’s Enterprise services across Eastern Canada. Develop territory plans, identify target accounts, build sales pipelines, present technical value propositions, negotiate contracts, achieve revenue targets, maintain strategic customer and partner relationships, and engage stakeholders from technical teams through senior executives.
Top Skills: Cloud SolutionsCloudflareComputer NetworkingCybersecurityIaasInternet InfrastructurePaasSaaS
Yesterday
In-Office or Remote
Canada
Senior level
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads health technology assessment, value, and evidence strategy for Pfizer’s genitourinary oncology portfolio. Manages HEOR, real-world evidence, economic models, global value dossiers, registries, and evidence dissemination to support reimbursement and patient access. Partners with global, regional, country, and cross-functional oncology teams, oversees vendors and project teams, and communicates findings through publications and conferences.
Yesterday
In-Office or Remote
Senior level
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Leads business systems analysis and data engineering support for military sustainment digital services. The role gathers and documents requirements, maps workflows, defines reporting and data needs, supports ETL/ELT, SQL analysis, integrations, dashboards, testing, governance, and implementation readiness. It partners with government, program, supplier, operational, product, and technical stakeholders to improve readiness and operational performance, while mentoring junior analysts and maintaining requirements, process, data, and delivery documentation.
Top Skills: AgileAmazon RedshiftAPIsAWSAzure SynapseConfluenceData ModelingDatabricksEtl/EltGitJIRALookerMiddlewarePower BIQlikSnowflakeSplunkSQLTableau

What you need to know about the Montreal Tech Scene

With roots dating back to 1642, Montreal is often recognized for its French-inspired architecture and cobblestone streets lined with traditional shops and cafés. But what truly sets the city apart is how it blends its rich tradition with a modern edge, reflected in its evolving skyline and fast-growing tech industry. According to economic promotion agency Montréal International, the city ranks among the top in North America to invest in artificial intelligence, making it le spot idéal for job seekers who want the best of both worlds.

Key Facts About Montreal Tech

  • Number of Tech Workers: 255,000+ (2024, Tourisme Montréal)
  • Major Tech Employers: SAP, Google, Microsoft, Cisco
  • Key Industries: Artificial intelligence, machine learning, cybersecurity, cloud computing, web development
  • Funding Landscape: $1.47 billion in venture capital funding in 2024 (BetaKit)
  • Notable Investors: CIBC Innovation Banking, BDC Capital, Investissement Québec, Fonds de solidarité FTQ
  • Research Centers and Universities: McGill University, Université de Montréal, Concordia University, Mila Quebec, ÉTS Montréal

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account