GRC Analyst

Fluidstack

San Francisco (CA)

On-site

USD 218,000 - 269,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Equity
Health, dental, and vision insurance
Generous PTO
Retirement plan

Job summary

Fluidstack is seeking a Security Compliance Lead in San Francisco to own end-to-end controls across SOC 2 Type II, ISO 27001, NIST 800-53, and FedRAMP, building a scalable program for global sites.

You will collaborate with engineering and operations to gather evidence, manage audit readiness, and close findings with external auditors, while aligning policy with evolving regulatory requirements.

Qualifications

  • Experience leading controls and pulling evidence against one or more security frameworks (SOC 2, ISO 27001, NIST 800-53, or FedRAMP).
  • Proven ability to own a compliance documentation set, policies, procedures, and narratives and keep them current.
  • Experience defending controls in front of auditors and closing findings without escalation.
  • Ability to drive evidence collection from busy engineers and owners across the organization on time.

Responsibilities

  • Run end-to-end SOC 2 Type II, ISO 27001, NIST 800-53, or FedRAMP initiatives and audit preparation.
  • Own policy and procedure sets; maintain review cycles as the program grows.
  • Coordinate control operations, access reviews, evidence refreshes, and attestations with system owners.
  • Lead POA&M management and closure with external auditors and assessors.
  • Scale the program to new sites and teams, mapping systems to existing controls for consistent coverage.

Skills

SOC 2
ISO 27001
NIST 800-53
FedRAMP
Audit management
Policy writing
Evidence collection
Cross-functional collaboration

Tools

Vanta

Job description

About Fluidstack

We exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we’ve ever built – but only if models are aligned with what humanity actually wants. There are groups building AI who don’t share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.

We are singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them – with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization‑scale infrastructure for AI.

How We Operate
  • Extreme ownership. Full autonomy. Own things end to end often taking on scope outside your core role without being asked to get things done.
  • Velocity. We drive everything forward as fast as possible.
  • First principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.
  • Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.
The Security Team
Examples of key problems the team is working on
  • You’re securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and we’re standing up the compute to hold them faster than anyone ever has. A breach isn’t a leak, it’s the frontier walking out the door.
  • Build the entire security program from scratch. Most leaders inherit someone else’s system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents.
  • Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small.
Role Scope
  • Run the day‑to‑day compliance program end to end across SOC 2 Type II, ISO 27001, NIST 800‑53, and FedRAMP Moderate equivalency: continuous evidence collection, control monitoring, and audit readiness held on GRC platforms (Vanta) and the tooling we build in‑house.
  • Own the policy and procedure set: draft, maintain, and run the review cycle so documentation keeps pace with the controls as the program grows.
  • Run recurring control operations on cadence, access reviews, control owner attestations, and evidence refreshes, chasing system owners and employees across the org directly to get them done on time.
  • Drive audit and assessment cycles with external auditors and assessors and manage the POA&M to closure, tracking each finding to a named owner and milestone so nothing ages past its deadline.
  • Bring each new site and team into the compliance program as we scale, mapping their systems to existing controls so coverage stays consistent instead of fragmenting facility by facility.
What We’re Looking For
  • You’ve operated controls and pulled evidence against at least one major framework (SOC 2, ISO 27001, NIST 800‑53, or FedRAMP) through a real audit, not just read the policy.
  • You’ve owned a compliance documentation set, policies, procedures, and control narratives, and kept it current as the environment changed underneath you.
  • You’ve sat across from an auditor or assessor, defended how a control runs in practice, and closed findings without escalating every question upward.
  • You get evidence and adherence out of busy engineers, system owners, and employees across the org, on time, without a manager pushing you to do it.
  • You catch a stale control, an expired access grant, or a coverage gap before an assessor does, because you watch the portfolio continuously, not once a quarter.
  • You translate a control requirement into the exact artifact that proves it, and you keep that mapping tight across overlapping frameworks instead of collecting the same evidence twice.
  • Bonus: FedRAMP Moderate equivalency or NIST 800‑53 evidence work. GRC platforms (Vanta) or comparable continuous‑compliance tooling. Cloud, GPU, or data center environments. Mapping controls across SOC 2, ISO 27001, and NIST in parallel.
Salary & Benefits
  • Competitive total compensation package (salary + equity).
  • Retirement or pension plan, in line with local norms.
  • Health, dental, and vision insurance.
  • Generous PTO policy, in line with local norms.

Compensation Range: $218K - $269K

We are committed to pay equity and transparency.

Fluidstack is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Fluidstack will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Manager
Incident Response Manager

Fluidstack • Seattle (WA)

On-site
USD 182,000 - 224,000
Equity
Health insurance
Generous PTO
Incident Response Manager
Incident Response Manager

Fluidstack • San Francisco (CA)

On-site
USD 180,000 - 240,000
Health, dental, and vision insurance
Retirement plan
Generous PTO
Security Deployment Lead, Deployment
Security Deployment Lead, Deployment

Fluidstack • Indiana (PA)

On-site
USD 185,000 - 221,000
Equity compensation
Incident Response Manager
Incident Response Manager

Fluidstack • Austin (TX)

On-site
USD 218,000 - 269,000
Equity
Retirement plan
Health, dental, vision
+1
Principal Incident Responder
Principal Incident Responder

Fluidstack • Austin (TX)

On-site
USD 330,000 - 380,000
Principal Incident Responder
Principal Incident Responder

Fluidstack • New York (NY)

On-site
USD 330,000 - 380,000
Software Engineer, Cloud Infrastructure
Software Engineer, Cloud Infrastructure

Fluidstack • Seattle (WA)

On-site
USD 175,000 - 300,000
Health, dental, and vision insurance
Retirement or pension plan
Generous PTO policy
Software Engineer, Cloud Infrastructure
Software Engineer, Cloud Infrastructure

Fluidstack • New York (NY)

On-site
USD 175,000 - 300,000
Health, dental, and vision insurance
Retirement or pension plan
Generous PTO policy
Software Engineer, Cloud Infrastructure
Software Engineer, Cloud Infrastructure

Fluidstack • San Francisco (CA)

On-site
USD 175,000 - 300,000
Health, dental, and vision insurance
Generous PTO policy
Retirement or pension plan
Distributed Systems Engineer
Distributed Systems Engineer

Fluidstack • San Francisco (CA)

On-site
USD 175,000 - 300,000
Health, dental, and vision insurance
Retirement or pension plan
Generous PTO policy