--- title: 'Senior Security Compliance (GRC) Manager at Aisle' canonical: 'https://feeny.ai/job/senior-security-compliance-grc-manager-aisle-prague-qyc65c2ad6g0' type: 'job' last_seen: '2026-09-11' --- # Senior Security Compliance (GRC) Manager at Aisle - **Company:** Aisle - **Location:** Prague, Czech Republic - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-07-21 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/aisle/97a09433-9034-4266-acd3-1361219b4bce ## Job description Why Aisle? AISLE is building the AI that finds, fixes, and verifies software vulnerabilities autonomously - an end-to-end system that closes the gap between when a vulnerability appears and when it's safely patched. Vulnerabilities are the #1 root cause of cyber incidents, yet most organizations take weeks or months to remediate what attackers now exploit in days. We're ending that backlog. Our systems already find and fix vulnerabilities in the world's most heavily audited codebases - 375+ independently validated CVEs across projects like OpenSSL, curl, Linux, and Chromium - at machine speed and superhuman scale. AISLE runs entirely inside our customers' perimeter (cloud, on-prem, or fully air-gapped) and can run on our optimized models or theirs, so even the most sensitive organizations, including those operating critical infrastructure, stay in full control of their code and their models. Backed by world-class founders, advisors, and angel investors, we're defining a new category: sovereign, AI-native security. Our goal isn't to improve vulnerability management - it's to end the backlog and move toward a future where software defends itself. We’re a small, talent-dense team spread across Europe, the US and Canada. We value high ownership, high velocity, and low-ego collaboration. If you want to work with world-class minds in AI and security, thrive in fast-moving environments, and care about solving one of the toughest challenges in tech, Aisle is the place for you. ## What You’ll Be Doing - SDLC & Product Security Integration: Lead application security reviews and threat modeling for core products, microservices, and LLM/AI integrations. Translate security policies directly into concrete engineering controls within the CI/CD pipeline. - AI Governance & Safety Architecture: Translate AI Management Policies (including ISO 42001 mandates) into engineering guardrails. Implement AI observability, prompt-injection defenses, and risk controls for RAG architectures, multi-tenant AI agents, and third-party LLM connectors. - Infrastructure & Trust Boundaries: Partner with Infrastructure/DevOps teams to design and enforce zero-trust architecture, multi-tenant isolation, and automated cloud compliance controls (AWS/Azure/GCP). - Automated Compliance & Security Tooling: Build and deploy internal security agents and automation scripts to handle vulnerability triage, log analysis, continuous control testing, and automated evidence collection for audits. - Audit Ownership & Technical Representation: Serve as the principal technical counterpart for ISO 27001, SOC 2, and ISO 42001 audits. Interface with external auditors by presenting real-time architectural proof and automated control evidence. - Security Engineering Enablement: Mentor software engineers on secure coding practices, threat modeling, and secure AI usage. Create code patterns (clear contracts, typed interfaces) that make secure-by-default development effortless for engineering. - Incident & Threat Runbooks: Maintain technical runbooks for emerging threat vectors, including AI-specific scenarios (data exfiltration, model behavior drift, cross-tenant exposure, and cost-bomb attacks). ## Requirements - Professional Background: 5+ years combining GRC/Audit experience with hands-on exposure to Application Security, Security Engineering, or Cloud Infrastructure. - Technical Stack & Tooling: Familiarity with CI/CD security tools (SAST/DAST, dependency checkers), cloud infrastructure controls, script-level automation (Python, Bash, or Go), and automated GRC platforms (e.g., Vanta, Drata). - Architecture & Frameworks: Deep knowledge of mapping framework controls (SOC2, ISO 27001, ISO 42001, NIST, GDPR) directly to infrastructure configurations, network boundaries, and application code. - AI & LLM Security Literacy: Understanding of OWASP Top 10 for LLMs, threat modeling for RAG pipelines, and trust boundary definitions for autonomous AI agents. - Hands-on Execution: Ability to read code, analyze log streams, and discuss technical vulnerabilities with developers on their level. - Communication & Synthesis: Ability to bridge three worlds: explaining technical vulnerabilities to executive leadership, discussing API/code patterns with engineers, and satisfying external audit requirements. - Bonus Points: A background in Software Engineering, Cloud Architecture, or specialized certifications (e.g., CISSP, CCSP, OSCP, CISA). ## About Aisle ## Company Overview - **One-liner**: AISLE is an AI-native vulnerability management platform that autonomously discovers, fixes, and verifies software vulnerabilities at machine-superhuman speed. - **Entity Type**: Private (Angel-stage – raised an angel round in October 2025 from 6 undisclosed investors) - **Headquarters**: San Francisco, California, United States (also a major hub in Prague, Czech Republic) - **Founded**: 2024 - **Founders**: Ondrej Vlcek (CEO) and Stanislav Fort (Chief Scientist) ## Core Business - **Primary industry**: Computer and Network Security / Cybersecurity (vulnerability management) - **Target customers**: Enterprise organizations with complex, heavily audited codebases (B2B) - **Mission or purpose**: Build self-defending systems that secure the digital backbone of modern life — autonomously, intelligently, and at scale. The company’s measurable goal is **zero exploitable vulnerabilities**. ## Products & Services - **AISLE Snapshot**: On-premises, cloud, or fully air-gapped security scanner that delivers frontier-class detection in hours. It runs inside the customer’s perimeter (AWS, GCP, Azure, self-hosted) and provides a fast picture of code health. *Type: On-prem/cloud SaaS.* - **AISLE Enterprise**: Full-featured enterprise platform offering AI-native vulnerability management with flexible deployment, SSO, and compliance support. Includes collaborative remediation workflow. *Type: SaaS.* - **Autonomous Cyber Reasoning System**: End-to-end system that finds, fixes, and verifies vulnerabilities at scale — reducing mean time to remediation from 135 days (industry) to **4 days** in collaborative mode. *Type: AI/ML service.* ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company) - **Key Metric**: **225+ CVEs** discovered (highest of any AI security platform); **85% fix acceptance rate**; **95% noise reduction** vs. traditional AppSec tools; **10x cost-efficiency** vs. Mythos. - **Notable Investors/Partners**: Angel investors include **Jeff Dean** (Google), **Thomas Wolf** (Hugging Face), **Olivier Pomel** (Datadog), **Aparna Chennapragada** (Microsoft), **Ian Goodfellow** (DeepMind), **Dwarkesh Patel**. Advisors: Prof. **Surya Ganguli** (Stanford), **Aernout Reijmer** (ex-ASML CISO), **Bruce Schneier** (Harvard), **Jaya Baloo** (COO/CISO). - **Growth Signals**: Headcount of 48 employees (monthly growth +3.8%); operates in 6 countries (US, Czechia, Poland, Switzerland, UK, Canada); credited for surfacing 13 of 14 Open in one release. Recent angel round shows strong investor confidence. ## Competitive Advantages - **AI-native autonomy**: Unlike traditional AppSec tools, AISLE’s reasoning system finds, fixes, and verifies vulnerabilities without manual triage. - **Speed & accuracy**: 4-day MTTR vs. 135-day industry average; 95% noise reduction; 85% fix acceptance rate. - **Proven CVE output**: More CVEs discovered than any other AI security platform, validated independently. - **Flexible deployment**: Can run in air-gapped, on-prem, or public cloud environments, meeting strict compliance needs. ## Strategic Focus - **Zero exploitable vulnerabilities** as an achievable outcome, not just a slogan. - **Ending the vulnerability backlog** by closing the loop between detection and remediation. - **Expanding enterprise adoption** and building partnerships with security-conscious organizations. - **Continued investment in AI research** (Chief Scientist Stanislav Fort leads frontier reasoning work). ## Why Work Here - **Remote-friendly culture**: Hubs in San Francisco and Prague, plus remote colleagues in the UK, Netherlands, Canada, and Switzerland. Open to extraordinary people anywhere. - **Meaningful equity**: Every employee is an owner and shares in the company’s success. - **Generous time off**: Real emphasis on recharging; unlimited PTO culture. - **Comprehensive benefits**: Medical, dental, mental health coverage; competitive compensation. - **Early-stage impact**: Small team (48 people) means every hire shapes the product and direction; direct access to founders and top-tier advisors (Jeff Dean, Bruce Schneier, etc.). - **Values-driven**: Six core values — Thoughtful, Honest, Resilient, Inclusive, Visionary, Empathetic — guide daily work. - **Open roles**: Currently hiring a Security Engineer; also accepts “Wild Card” applications for exceptional candidates. ## Sources 1. [aisle.com](https://aisle.com/) – product overview and enterprise features 2. [aisle.com/careers](https://aisle.com/careers) – values, benefits, and remote policy 3. [aisle.com/about-us](https://aisle.com/about-us) – founders, story, investors, advisors 4. [linkedin.com/company/aisleinc](https://www.linkedin.com/company/aisleinc) – headcount, funding, offices, tech stack ## Other roles at Aisle - [Technical Account Manager — EMEA](https://feeny.ai/job/technical-account-manager-emea-aisle-europe-qf7tm7cgf2p0) — Europe - [Enterprise Sales Development Representative](https://feeny.ai/job/enterprise-sales-development-representative-aisle-united-states-fvx0rv2gjmjm) — United States - [Forward Deployed Engineer – Vulnerability Management & Security](https://feeny.ai/job/forward-deployed-engineer-vulnerability-management-security-aisle-europe-p6rng83b7bhd) — Europe - [Program Manager](https://feeny.ai/job/program-manager-aisle-prague-ym7z44ay2xgy) — Prague, Czech Republic - [Cloud Platform & Infrastructure Engineer](https://feeny.ai/job/cloud-platform-infrastructure-engineer-aisle-prague-9njwccafrpa5) — Prague, Czech Republic - [Head of Marketing](https://feeny.ai/job/head-of-marketing-aisle-united-states-egey8vx9ajme) — United States - [Fullstack Engineer](https://feeny.ai/job/fullstack-engineer-aisle-prague-x48htq846f9f) — Prague, Czech Republic - [Python Core Engineer](https://feeny.ai/job/python-core-engineer-aisle-prague-9wdts2s8y84p) — Prague, Czech Republic - [Wild Card](https://feeny.ai/job/wild-card-aisle-europe-t7wf81d70s32) — Europe