Senior Security Compliance (GRC) Manager

aisle· Security
Apply Now ↗
📍 Prague, Czech RepublicFullTime

About this role

Why Aisle?

Aisle is redefining how enterprises secure their software with an AI agent for autonomous vulnerability remediation. Vulnerabilities are the #1 root cause of cyber incidents, yet most organizations take weeks or months to patch what attackers exploit in days. We’re changing that.

Our mission is to protect democratic societies from the most sophisticated cyberattacks. We do that by giving organizations - including those operating critical infrastructure - the power to harden their systems and resolve security issues at superhuman speed and scale. Backed by world-class founders and advisors, we’re creating a new category in cybersecurity at the intersection of AI, automation, and enterprise resilience.

We’re a small, talent-dense team spread across the US, Europe, and Israel. We value high ownership, high velocity, and low-ego collaboration. If you want to work with world-class minds in AI and security, thrive in fast-moving environments, and care about solving one of the toughest challenges in tech, Aisle is the place for you.

What You’ll Be Doing

  • SDLC & Product Security Integration: Lead application security reviews and threat modeling for core products, microservices, and LLM/AI integrations. Translate security policies directly into concrete engineering controls within the CI/CD pipeline.

  • AI Governance & Safety Architecture: Translate AI Management Policies (including ISO 42001 mandates) into engineering guardrails. Implement AI observability, prompt-injection defenses, and risk controls for RAG architectures, multi-tenant AI agents, and third-party LLM connectors.

  • Infrastructure & Trust Boundaries: Partner with Infrastructure/DevOps teams to design and enforce zero-trust architecture, multi-tenant isolation, and automated cloud compliance controls (AWS/Azure/GCP).

  • Automated Compliance & Security Tooling: Build and deploy internal security agents and automation scripts to handle vulnerability triage, log analysis, continuous control testing, and automated evidence collection for audits.

  • Audit Ownership & Technical Representation: Serve as the principal technical counterpart for ISO 27001, SOC 2, and ISO 42001 audits. Interface with external auditors by presenting real-time architectural proof and automated control evidence.

  • Security Engineering Enablement: Mentor software engineers on secure coding practices, threat modeling, and secure AI usage. Create code patterns (clear contracts, typed interfaces) that make secure-by-default development effortless for engineering.

  • Incident & Threat Runbooks: Maintain technical runbooks for emerging threat vectors, including AI-specific scenarios (data exfiltration, model behavior drift, cross-tenant exposure, and cost-bomb attacks).

Requirements

  • Professional Background: 5+ years combining GRC/Audit experience with hands-on exposure to Application Security, Security Engineering, or Cloud Infrastructure.

  • Technical Stack & Tooling: Familiarity with CI/CD security tools (SAST/DAST, dependency checkers), cloud infrastructure controls, script-level automation (Python, Bash, or Go), and automated GRC platforms (e.g., Vanta, Drata).

  • Architecture & Frameworks: Deep knowledge of mapping framework controls (SOC2, ISO 27001, ISO 42001, NIST, GDPR) directly to infrastructure configurations, network boundaries, and application code.

  • AI & LLM Security Literacy: Understanding of OWASP Top 10 for LLMs, threat modeling for RAG pipelines, and trust boundary definitions for autonomous AI agents.

  • Hands-on Execution: Ability to read code, analyze log streams, and discuss technical vulnerabilities with developers on their level.

  • Communication & Synthesis: Ability to bridge three worlds: explaining technical vulnerabilities to executive leadership, discussing API/code patterns with engineers, and satisfying external audit requirements.

  • Bonus Points: A background in Software Engineering, Cloud Architecture, or specialized certifications (e.g., CISSP, CCSP, OSCP, CISA).

Frequently Asked Questions

Is the salary disclosed for the Senior Security Compliance (GRC) Manager position at aisle?
The salary for this Senior Security Compliance (GRC) Manager role at aisle is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Senior Security Compliance (GRC) Manager position at aisle located?
This Senior Security Compliance (GRC) Manager role at aisle is based in Prague, Czech Republic. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Senior Security Compliance (GRC) Manager role at aisle full-time or part-time?
This is listed as a FullTime position. It is posted as a Senior Security Compliance (GRC) Manager role in the Security department at aisle.
Which team or department does the Senior Security Compliance (GRC) Manager at aisle belong to?
This Senior Security Compliance (GRC) Manager position is part of the Security department at aisle. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Senior Security Compliance (GRC) Manager position at aisle?
Click the "Apply Now" button on this page. You will be redirected to aisle's official application portal hosted on ashby where you can submit your application directly.
When was the Senior Security Compliance (GRC) Manager job at aisle posted?
This Senior Security Compliance (GRC) Manager position at aisle was posted on Jul 21, 2026. Apply as soon as possible — early applications are often reviewed first.
Senior Security Compliance (GRC) Manager
aisle
Apply for this role ↗

You'll be redirected to aisle's official application page on Ashby ATS.