
About Domino Data Lab
At Domino, we build solutions that help the largest, highly regulated organizations adopt AI to accelerate mission-critical use cases. Our platform integrates a streamlined model and app development environment, advanced model, agent, and app hosting capabilities, and novel governance capabilities providing regulator-ready AI at scale. Our customers — like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA, and the US Navy — use our software to solve critical challenges across medicine, financial markets, and defense. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake, and other leading investors, we operate with the spirit of a startup.
What We Are Building
The Quality & Compliance team at Domino is:
- Building the assurance layer: Enabling highly regulated organizations to put Domino at the center of their AI work across pharma, finance, and government.
- Running a multi-framework program: Managing SOC 2, ISO 9001, ISO 27001, and CMMC under one roof across info security, quality management, and federal compliance.
- Operating lean and non-bureaucratic: Focusing on clear, actionable SOPs and policies that teams actually follow.
- Driving revenue impact: Handling high-volume security questionnaires and change control inquiries to directly support sales outcomes.
- Scaling GRC operations: Transitioning to structured operations with tooling, reusable answer libraries, and reliable operational rhythms.
Your Impact
- First 90 Days: Take over inbound security and quality questionnaires using our answer library and response tooling. Manage the master audit and compliance activities schedule.
- By 6 Months: Own day-to-day QMS operations, training assignments and content, and records for change orders, suppliers, and computer systems. Maintain clear GRC program status in Jira and Confluence.
- By 12 Months: Review control statements across SOC 2, ISO 9001, ISO 27001, and CMMC to ensure evidence matches claims. Keep SOPs up to date and measurably improve questionnaire turnaround times.
What We Look For
- 2–5 years of hands-on experience in GRC, compliance operations, quality assurance, or audit support.
- Direct experience responding to security or quality questionnaires at volume and managing answer libraries or response tooling.
- End-to-end involvement in at least one audit or certification cycle (SOC 2, ISO 9001, ISO 27001, CMMC, or equivalent), including evidence collection and finding follow-ups.
- Experience as an administrator or power user of an eQMS, GRC platform, or compliance system of record.
- Strong technical writing skills to turn vague requirements into clear SOPs and precise customer answers.
- Fluency in Jira and Confluence with strong maintenance discipline.
- Practical experience using agentic AI tools and frameworks (custom skills, prompt-driven workflows) while maintaining human verification.
- Meticulous attention to detail, calendar discipline, and sound judgment regarding when to escalate or consult SMEs.
- Low-ego, collaborative approach across Security, Engineering, Legal, People, and Sales.
Nice to Have
- Experience in regulated life sciences, medical device, or pharmaceutical environments (GxP, 21 CFR Part 11, computer system validation, or supplier qualification).
Our Values
- Growth Mindset: Digging into problems to find opportunities for success.
- Truth & Authenticity: Seeking and speaking the truth while bringing your whole self to work.
- Continuous Improvement: Viewing everything as a work in progress with room to improve.
- Teaching & Learning: Supporting continuous learning to equip team members for success.
- Diversity & Inclusion: Building a diverse team across all backgrounds, genders, ethnicities, abilities, and sexual orientations.
Timezone overlap
UTC+8–+12
Open to
APAC
Sign in to track applications and earn points.