1,434,312open jobs
83,785companies
217,826added this week
Browse all
Salary
≈ $97k – $191k per year (Estimated)
Location
In office (New York, San Francisco)
Seniority
Middle · 3+ years exp
Visa
Sponsorship offered in the posting · H-1B filings in 12 months: 35
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 9, 2026. First seen by Alion on Oct 9, 2026. Reflection AI scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Reflection AI is a company founded in 2024 by former Google DeepMind researchers who worked on AlphaGo and large language models. It builds autonomous coding agents and has committed to releasing frontier open-weight models as an American counterweight to Chinese open model releases. The company raised a very large round in 2025 to fund training at frontier scale.

Our Mission

Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all.

Role summary

Reflection AI's Compliance and AI Governance function spans six pillars: AI Governance, Data Governance, Trade Compliance, Privacy Operationalization, Government Contracting Compliance, and Corporate Compliance. The team builds the policies, controls, and operating rhythms that let the company move fast while staying defensible with regulators, customers, and partners. This role sits at the intersection of compliance and engineering, partnering most closely on technical controls required by Security frameworks, AI Governance frameworks, Privacy, and Data Governance pillars to translate policy requirements into technical controls that scale.

We're looking for a Governance, Risk, & Compliance engineer who wants to work on compliance as a product problem rather than a paperwork problem. You'll build and maintain the technical infrastructure (tooling, pipelines, automated controls, evidence collection) that lets the compliance program operate at engineering scale instead of through manual review. A core part of the job is keeping our security framework compliance (SOC 2, ISO 27001, NIST) running on automated evidence rather than manual screenshotting, and building out the technical side of our Trade Compliance, Privacy, Data Governance, and TPRM program. You'll be the technical translator between compliance requirements and the engineering and security teams that have to implement them.

What You'll Do

  • Design and build automated controls and monitoring that satisfy security framework requirements (SOC 2, ISO 27001, NIST 800-53/800-171, CMMC): access reviews, data minimization, model/data lineage, continuous evidence collection

  • Partner with Engineering, Security, and IT to implement technical requirements arising from security frameworks, deemed export controls, and privacy regulations

  • Build and maintain internal tooling that supports compliance workflows (intake forms, screening checks, reporting dashboards, GRC platform integrations such as Vanta)

  • Translate regulatory and policy requirements into concrete technical specifications engineering teams can implement

  • Support technical due diligence for inbound customer security questionnaires, audits, and outbound vendor assessments

  • Maintain integrations between compliance/GRC systems and source-of-truth systems (identity, data infrastructure, model pipelines)

  • Help scope and support technical environment separations or system boundaries required for regulatory compliance (e.g., subsidiary or enclave environments)

What We're Looking For

  • 3-6 years of software engineering, security engineering, or DevOps/infrastructure experience

  • Hands-on experience supporting at least one security framework (SOC 2, ISO 27001, or NIST) as an engineer, not just as a subject

  • Comfortable writing production-quality code (Python, or similar) and working with APIs/integrations

  • Experience translating non-technical requirements (policy, regulatory, contractual) into technical implementation

  • Familiarity with cloud infrastructure and identity/access management concepts

  • Strong collaboration skills; able to work effectively with compliance, legal, and engineering stakeholders who don't share a common vocabulary

  • Experience building or maintaining GRC tooling, TPRM/vendor risk platforms, or compliance automation (e.g., Vanta or similar)

  • Familiarity with one or more relevant frameworks: CMMC, NIST 800-171/800-53, SOC 2, ISO 27001, GDPR/CCPA technical requirements

  • Experience with data governance or data lineage tooling, especially in ML/AI pipelines

  • Background supporting a government contracting or regulated environment

What We Offer:

We believe that to make intelligence open and accessible to all, you need to start at the foundation. Joining Reflection means building from the ground up as part of a talent-dense team. You will help define our future as a company, and help define the future of open foundational models.

We want you to do the most impactful work of your career with the confidence that you and the people you care about most are supported.

  • Top-tier compensation: Salary and equity structured to recognize and retain our talent globally.

  • Stock options: Everyone who joins and contributes to Reflection's success gets to share in the upside through stock options.

  • Health & wellness: Comprehensive medical, dental, vision, and life, with an annual wellness allowance.

  • Meals: Lunch and dinner are provided in the office daily.

  • Life & family: 22 weeks paid parental leave for all new birthing and non-birthing parents, including adoptive and surrogate journeys.

  • Vacation days: Unlimited paid time off in the U.S. and 30 days in the U.K.

  • Sponsorship support: We sponsor visas to help exceptional talent join our team and support long-term immigration pathways where applicable.

  • Team building: We have regular off-sites, happy hours, and team celebrations.

Export Control Notice: This position may require access to technology or source code subject to the U.S. Export Administration Regulations. Any offer of employment for this role may be conditioned on the Company's ability to provide the candidate with access to such technology or source code in compliance with applicable U.S. export control laws, which may require the Company to seek government authorization.

Candidate and Employee Privacy Notice: We collect and process personal data about applicants for the purposes described in our Candidate and Employee Privacy Notice

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,434,312 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
New York
$131k – $136k per year • In office • Full-Time • 3+ years exp • PhD • New York
DevOps
GCP
Azure
AWS
IAM
Windows
VPN
Cybersecurity
ISO 27001
DLP
Apply
$177k – $266k per year • Hybrid • San Diego
SQL
Databases
Snowflake
Amazon Redshift
Analytics
Tableau
Apply
≈ $97k – $193k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Chicago • Austin • Denver
Python
PowerShell
DevOps
Rest API
Cybersecurity
Zscaler
Microsoft Defender
MITRE ATT&CK
NIST CSF
Zero Trust
Defense in Depth
SIEM
Apply
≈ $82k – $161k per year (Estimated) • In office • Full-Time • 4+ years exp • Denver
Apply
$119k – $152k per year • Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • Los Angeles
SQL
DevOps
IAM
Unix
Cybersecurity
CyberArk
Zero Trust
BeyondTrust
LDAP
Apply
Group Account Director 10 hours ago
$160k – $280k per year • Hybrid • Full-Time • New York • Richmond
Apply
$68k – $78k per year • Hybrid • Full-Time • 2+ years exp • PhD • New York
Management
Outlook
Agile
Apply
Copy Supervisor 10 hours ago
$100k – $125k per year • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • New York
Apply
Copy Supervisor 10 hours ago
$100k – $120k per year • Hybrid • Full-Time • Bachelor's Degree • New York
Apply
$68k – $86k per year • Equity • In office • Full-Time • Bachelor's Degree • New York
Apply
See all jobs
This is one of many
1,434,312 more open roles from verified company boards, updated every day.