GRC Analyst

Fireworks AI

San Mateo (CA)

On-site

USD 110,000 - 170,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Fireworks AI is seeking a GRC Analyst to mature our security and compliance program across SOC 2, HIPAA, ISO 27001/27701/42001, GDPR, and other frameworks. You will support audits, manage risk, and partner with engineering and operations to keep controls effective as we scale.

From day one you’ll engage in user access reviews, security awareness, and third‑party risk management, with opportunities to grow into broader ownership, audit leadership, and program strategy over time.

Qualifications

  • 3–5 years of experience in GRC, IT audit, information security, or a closely related field.
  • Experience conducting risk assessments and maintaining risk registers.
  • Familiarity with major security and privacy frameworks (SOC 2, ISO 27001/27701/42001, HIPAA, GDPR, NIST CSF).
  • Ability to coordinate audits and work with cross-functional teams to implement controls.

Responsibilities

  • Support day-to-day GRC operations: user access reviews, certifications, security awareness, phishing/deepfake simulations, JML tracking, and policy/control exception triage.
  • Assist risk management: perform annual and ad-hoc risk assessments, maintain risk register, remediate with risk owners, track issues to closure.
  • Lead third-party risk assessments and ongoing monitoring of critical vendors and subprocessors.
  • Coordinate internal audits and support external audit cycles with evidence collection and remediation.
  • Maintain continuous control monitoring and evidence automation, ensuring audit readiness year-round.
  • Collaborate with engineering, IT, operations, legal, and sales to integrate controls and avoid gatekeeping.
  • Help keep policy library current with updates to security policies, standards, and procedures.

Skills

Cloud platforms
AWS
GCP
Azure
IAM concepts
RBAC
least privilege
Segregation of duties
JML processes
Security awareness
KnowBe4
Hoxhunt
Proofpoint
SOC 2
ISO 27001
ISO 27701
ISO 42001
HIPAA
GDPR
NIST CSF
CCPAA
cross-functional collaboration
security & compliance

Tools

Anecdotes
Vanta
Drata
Secureframe
OneTrust
ServiceNow GRC

Job description

  • We’re looking for a GRC Analyst to join our security and compliance team
  • You’ll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale
  • From day one you’ll get hands-on with core operational areas of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with clear room to grow into broader ownership, audit leadership, and program strategy over time
  • This is a great fit for someone with solid working experience in security or compliance who’s looking to build hands-on ownership and deepen their skill set in a fast-moving SaaS environment
  • Support day-to-day GRC operations including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage of policy and control exceptions
  • Support the risk management program help perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure
  • Support third-party risk management run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors
  • Execute internal audits using established test procedures to test control effectiveness, and support external audit cycles by coordinating evidence, control owners, and remediation
  • Help maintain continuous control monitoring and evidence automation support administration of our GRC platform, keep automated control tests and evidence healthy, and help maintain audit readiness year-round rather than point-in-time
  • Build relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping
  • Partner with control owners to help them understand their control responsibilities and expectations, prepare for audits, and operationalize controls rather than treat compliance as a checkbox
  • Help keep the policy library current support reviews and updates to security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under
  • Turn program data into insights help translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, and support reporting to leadership
  • Take on additional GRC projects as the program evolves; we’re a growing team and priorities shift
  • As you build context on our environment and program, you’ll take on broader ownership and move toward more senior scope:
  • Greater ownership of core programs move from supporting established processes to owning entire workstreams (user access reviews, security awareness, third-party risk) end-to-end
  • Audit leadership progress from executing established test procedures to helping design new ones, scoping audits, and coordinating auditors directly
  • Program and control maturity contribute to control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale
  • Growing influence as you build expertise, you’ll have opportunities to mentor newer team members and represent GRC in cross-functional projects

Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operatedExperience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)Hands-on experience administering a security awareness or phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar)Strong written communication; you can translate control requirements and security concepts into language engineers, customers, and non-technical employees understand3-5 years of experience in GRC, IT audit, information security, or a closely related fieldWorking knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPAA collaborative mindset; you enjoy working across teams rather than gatekeepingExperience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)Detail-oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Assurance Engineer
Senior Security Assurance Engineer

6sense • New York (NY)

On-site
USD 150,000 - 190,000
Health & Wellness
HUB Working Model
WeWork Access
+3
Security Compliance Analyst
Security Compliance Analyst

Harbinger Motors • Garden Grove (CA)

On-site
USD 110,000 - 160,000
Stock options
Flexible PTO
Health coverage
+2
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
GRC Analyst
GRC Analyst

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 80,000 - 130,000
Governance, Risk, and Compliance Analyst
Governance, Risk, and Compliance Analyst

YipitData • United States

On-site
USD 70,000 - 110,000
Flexible work hours
Flexible vacation
Generous 401K match
+4
Senior Security Analyst
Senior Security Analyst

Valon Mortgage • United States

Hybrid
USD 120,000 - 160,000
Remote options
Health insurance
Parental leave
+1
GRC Compliance Auditor
GRC Compliance Auditor

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
GRC Compliance Auditor
GRC Compliance Auditor

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 90,000 - 140,000
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
GRC Analyst / Product Owner
GRC Analyst / Product Owner

Allen Recruitment • California (MO)

On-site
USD 110,000 - 150,000