Recently posted · Greenhouse · alphasense✓ Direct employer / ATS application
Senior Risk & Governance Engineer
Alphasense
Role details
What you’ll be doing
About AlphaSense: The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content. The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us! About the Role AlphaSense's GRC function is making a deliberate investment in automation and engineering, and we need a Senior GRC Engineer to lead that charge. You will design and build the technical automation that powers our compliance testing, evidence collection, risk monitoring, and GRC platform integrations—and you will own the governance architecture for how AI and agentic systems are built and deployed at AlphaSense. You sit at the intersection of security engineering and compliance operations. You are not just AI-curious; you are AI-native in practice: you use LLMs and agents for real substantive work—analysis, drafting, automation, code, investigation—and you apply rigorous judgment about where AI creates leverage, where it introduces risk, and where a human must remain in the loop. The goal is continuous compliance infrastructure that generates its own proof, not a compliance team that sprints to collect evidence before each audit cycle.The conventional GRC playbook was not built for a company like AlphaSense—and we are not following it. We are building a GRC engineering function that we believe represents what the entire industry will eventually need to become: automated, AI-native, and architected like a product rather than operated like a process. The frameworks are still catching up. The tooling is still maturing. We are doing the work now that others will reference later. If you want to build something that sets the standard—not follow one—this is the role. Key Responsibilities Compliance Automation Engineering Design, build, and maintain automated compliance testing pipelines that continuously validate control adherence across cloud infrastructure, SaaS platforms, and internal systems. Replace point-in-time manual evidence collection with always-on automated checks. Pull evidence directly from APIs—cloud audit logs, identity systems, configuration posture, secrets management—without relying on screenshots or control owner self-attestation. GRC Platform Engineering & Integration Own the technical configuration and integration of the GRC platform (Drata or equivalent). Build custom API integrations, automated evidence connectors, and workflow automation that reduce manual control owner burden and keep evidence artifacts current. Know where the platform solves the problem and where custom code is the better answer. AI-Native GRC Workflows Develop and deploy AI-assisted workflows for evidence summarization, control narrative drafting, risk analysis, vendor questionnaire triage, and policy gap detection. Build with LLMs and agentic frameworks as a professional standard—not an experiment. Apply domain-specific judgment: know where AI helps, where it hurts, and where sensitive data, attacker-controlled inputs, or privileged access require a human in the loop. AI & Agentic Systems Governance Own the governance framework for AlphaSense's AI and agentic systems. Define the policies, control sets, and compliance posture that govern how agents are built and deployed—and build ahead of the compliance frameworks that are still catching up. Anticipate new policy requirements, adapt existing controls, and ensure the governance architecture is ready before auditors ask about it. Policy as Code & Control Architecture Build the policy program as code: policies in version control, peer-reviewed, with requirements exp