About the job
About Quartermaster AI:
At Quartermaster AI, we envision the ocean as a resource that is both secure and sustainably managed for everyone. Utilizing advanced AI and robotics, we are pioneering capabilities that were previously unattainable. Our innovative open-ocean systems empower vessels to sense, compute, and communicate, thus enhancing maritime domain awareness for those who need it most.
We are constructing the essential infrastructure relied upon by national security and maritime sectors, and we are in search of a security and compliance leader to establish the trust frameworks vital for our success.
The Role:
This is more than a compliance checklist role. As the GRC Manager at Quartermaster AI, you will take ownership of and operationalize our governance, risk, and compliance program, which supports our collaborations with the Department of Defense and other federal partners. You will develop compliance infrastructure from the ground up, converting complex regulatory frameworks into scalable, automation-first processes that empower our engineering teams to operate swiftly while ensuring security is not compromised.
You will report directly to the security leadership and function as the primary authority on all aspects of information security governance, regulatory compliance, and organizational risk posture. This foundational role carries significant influence over Quartermaster AI's growth and operational strategies.
Key Responsibilities:
Design and manage the enterprise GRC program, creating policies, standards, and procedures in line with NIST SP 800-171, CMMC 2.0, and other relevant federal frameworks.
Lead the CMMC Level 2 certification process from start to finish, including gap analysis, remediation strategies, System Security Plan (SSP) development, and coordination with third-party assessors (C3PAOs).
Establish and maintain a comprehensive risk management framework, conducting regular risk assessments and presenting risk posture and mitigation strategies to executive leadership.
Implement continuous monitoring capabilities and compliance automation to ensure ongoing adherence to NIST 800-171 controls across all 14 security families.
Act as the main contact for all regulatory audits, government compliance evaluations, and customer security inquiries.
Work collaboratively with Engineering, Product, and Operations teams to seamlessly integrate security and compliance requirements into development workflows.
Develop and sustain the Plan of Action & Milestones (POA&M) process to track compliance and remediation efforts.

