The Role
Core Responsibilities
- Design, document, and continuously improve compliance processes and frameworks to scale GRC operations across Commercial, IG, and USG environments.
- Serve as connective tissue across teams, translating regulatory requirements into actionable workflows and ensuring accountability at every stage of the compliance lifecycle.
- Coordinate across internal and external audit cycles (FedRAMP, SOC 2, ISO 27001, etc.), ensuring evidence collection, remediation tracking, and stakeholder communication stay on schedule.
- Keep broad and complete state of everything involving or related to your projects, including audit timelines, control implementation status, and continuous monitoring obligations. Pre-empt and resolve any issues that may steer projects off-course.
- Enhance cross-team collaboration across engineering, legal, and customer-facing teams to drive key GRC deliverables through the entire software development and compliance lifecycle.
- Synthesize concrete compliance goals from product and regulatory vision, mapping global strategy to granular team tasks and issues. This means triaging requests from the field to create maximum focus for the team, while escalating items that need immediate attention.
- Work with customer-facing engineering teams on adoption, roll out, and support of compliance-related product features and certifications.
What We Value
- Demonstrated success managing compliance programs for an enterprise software company, startup or other company.
- Experience with multiple GRC frameworks and standards, such as SOC 2, ISO 27001, IRAP or ENS. Experience in USG-specific frameworks is particularly valuable: FedRAMP, NIST 800-53, DoD CC SRG, FISMA, or CMMC.
- Excellent judgment and composure in high-pressure situations, including during active audits or compliance incidents.
- A creative approach to project management centered around lightweight frameworks that enable rapid iteration, while operating in harmony with a larger development and compliance organization.
- An ability to develop strong relationships with key internal stakeholders (including customer-facing teams), auditors, and regulators, with a high level of empathy for our end-users' needs.
- Meticulous attention to detail, including holding tightly to your team's compliance and product quality bar.
- A proven track record of building and scaling compliance processes from the ground up, particularly in USG-regulated environments.
- Experience with risk management methodologies, including maintaining risk registers, conducting risk assessments, and managing third-party or vendor risk programs.
What We Require
- This role requires that you work from the country listed on this job posting and that you are based within a commutable distance of your local Palantir office.
- Willingness and eligibility to obtain a U.S. security clearance preferred.
Salary
If you would like to understand more about how your personal data will be processed by Palantir, please see our .