Security GRC Specialist

phylo· Technical Staff
Apply Now ↗
🌍 Remote📍 South San Francisco📍 Toronto (hybrid)FullTime

About this role

About Phylo

Phylo is an applied research lab building agentic intelligence to accelerate discovery for every biomedical scientist. We believe AI agents will fundamentally transform how biomedical research is done. Our fast-growing team brings together researchers and engineers across AI and biology, commercializing the Biomni platform.

Our growing team brings together world class researchers and engineers across AI and biology. Backed by a $13.5M seed round led by a16z, Menlo Ventures and Anthropic, and advised by Nobel Prize laureate and pioneering biologists, Phylo is building the next generation of AI systems for the life sciences.

 

About the Role

We’re hiring a hands-on Security & Compliance Lead to build and scale Phylo’s security, privacy, and compliance program. You’ll own our compliance roadmap, lead audits and customer reviews, and work closely with engineering to turn requirements into practical controls.

What you’ll do as a Security GRC Specialist at Phylo:

  • Own Phylo’s security and compliance roadmap.

  • Lead SOC 2, ISO 27001 and GDPR readiness, audits, evidence collection, and remediation.

  • Build HIPAA-ready processes for workloads involving protected health information.

  • Assess and plan for FedRAMP, NIST, privacy, and life-sciences requirements where applicable.

  • Partner with engineers to implement scalable controls across cloud infrastructure, applications, and AI systems.

  • Lead customer questionnaires, RFPs, due diligence, and security conversations.

  • Run risk assessments and drive remediation across systems, vendors, and processes.

  • Maintain lightweight policies, customer-facing security documentation, and compliance reporting.

  • Automate evidence collection, monitoring, and other compliance workflows.

What We're Looking For:

  • 5+ years in security GRC, compliance, or a security engineering-adjacent role.

  • Experience leading SOC 2, ISO 27001, HIPAA, FedRAMP, or similar programs.

  • Strong understanding of cloud and application security.

  • Ability to translate regulatory requirements into technical controls.

  • Experience supporting audits and enterprise customer security reviews.

  • Strong cross-functional communication and program ownership.

  • A pragmatic, hands-on approach suited to an early-stage company.

Nice to Haves:

  • Experience building a security program from an early stage.

  • Background in healthcare, life sciences, enterprise AI, or cloud infrastructure.

  • Experience with HIPAA, FedRAMP, NIST SP 800-53, HITRUST, or GDPR.

  • Familiarity with AI governance frameworks such as NIST AI RMF or ISO 42001.

  • Experience automating GRC and compliance workflows.

Why Join Us?

  • Competitive salary and equity share in building the future of biomedical discovery

  • Full medical, dental, and vision coverage, including free therapy sessions and eyewear stipend

  • 401(k) to help you build long-term financial security (US only)

  • Unlimited PTO to recharge when you need it (US only)

  • Lunch and snacks when you're in the office

  • Regular team offsites and company events

  • A culture of excellence and speed - we move fast, think big, and support each other every step of the way

  • Your work will directly impact our mission to 100X biomedical discoveries through AI

Frequently Asked Questions

Is the salary disclosed for the Security GRC Specialist position at phylo?
The salary for this Security GRC Specialist role at phylo is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Is the Security GRC Specialist job at phylo remote?
Yes, this Security GRC Specialist position at phylo is remote, with team members based in South San Francisco, Toronto (hybrid). You can work from home or anywhere in the supported regions.
Is the Security GRC Specialist role at phylo full-time or part-time?
This is listed as a FullTime position. It is posted as a Security GRC Specialist role in the Technical Staff department at phylo.
Which team or department does the Security GRC Specialist at phylo belong to?
This Security GRC Specialist position is part of the Technical Staff department at phylo. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Security GRC Specialist position at phylo?
Click the "Apply Now" button on this page. You will be redirected to phylo's official application portal hosted on ashby where you can submit your application directly.
When was the Security GRC Specialist job at phylo posted?
This Security GRC Specialist position at phylo was posted on Jul 30, 2026. Apply as soon as possible — early applications are often reviewed first.
Security GRC Specialist
phylo
Apply for this role ↗

You'll be redirected to phylo's official application page on Ashby ATS.