What the work involves
A foundational AI lab is training a model to produce the artifacts a GRC function actually ships: Word policies, Excel control matrices, PowerPoint board updates. You will sit on both sides of that loop. Some shifts you author a gold-standard reference — a Type II readiness memo, a Trust Services Criteria mapping, a CAIQ-style vendor response — with the working notes and framework citations that explain why each control was scoped in. Other shifts you take a model output and mark it: where the control language is hand-wavy, where a CC6.x mapping is plausible but wrong, where a risk register mixes inherent and residual ratings, where a board slide overstates assurance the evidence doesn't support.
Grading is written, not a star rating. The lab wants a paragraph an auditor would recognize: what failed, against which clause or criterion, and what the corrected artifact looks like. Spreadsheet tasks carry real weight here — formula integrity, heat-map logic, and consistency between a risk score and its stated likelihood/impact inputs are recurring failure modes the model needs taught.
What the platform screens for
- Named framework ownership. SOC 2, ISO 27001, or NIST — held end to end, not observed from an adjacent seat. Expect follow-ups on scoping decisions, evidence collection, and how you handled an exception or a finding.
- Artifact craft. Whether you have personally built the control matrix, not just reviewed one someone else assembled.
- Calibrated judgment. Can you separate a stylistic quibble from a defect that would fail an audit, and say so in writing without hedging.
- Voice screen composure. An AI interviewer asks the questions and probes inconsistencies; specifics beat polish.
Logistics
Fully remote, asynchronous, no fixed hours. Five to twenty hours weekly, more available for contributors whose grading stays consistent with reviewer consensus. Tasks arrive in batches through the platform's workspace; you self-select and submit on your own clock. Pay is observed at $90/hour and is not guaranteed — rates can vary by task type and calibration history.