GRC Analyst

Fireworks AI

San Mateo (CA)

On-site

USD 120,000 - 160,000

Full time

22 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fireworks AI is seeking a GRC Analyst to join our security and compliance team in a fast-paced SaaS environment. You’ll mature our program across SOC 2, HIPAA, ISO standards, GDPR, and more, supporting audits, managing risk, and partnering with engineering and operations to keep controls effective as we scale.

From day one you’ll engage in user access reviews, awareness training, third‑party risk management, and carrying authority into audits, with clear room to grow into leadership and strategy

Qualifications

  • 3–5 years of experience in GRC, IT audit, information security, or closely related field.
  • Working knowledge of major security frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA.
  • Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC).
  • Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes).
  • Hands-on experience administering security awareness or phishing simulation platforms (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar).
  • Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated.
  • Strong written communication; translate control requirements and security concepts for engineers, customers, and non-technical employees.
  • Detail-oriented and organized; manage multiple audits, campaigns, and deadlines.
  • Collaborative mindset; work across teams rather than gatekeeping.

Responsibilities

  • Support day-to-day GRC operations including user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage of policy and control exceptions.
  • Support the risk management program: perform risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
  • Support third-party risk management: run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across critical vendors.
  • Execute internal audits using established test procedures to test control effectiveness, and coordinate evidence and remediation for external audits.
  • Help maintain continuous control monitoring and evidence automation, administer the GRC platform, and keep audit readiness year-round.
  • Build relationships with cross-functional partners across engineering, IT, operations, legal, and sales; avoid gatekeeping.
  • Partner with control owners to understand their responsibilities, prepare for audits, and operationalize controls rather than treating compliance as a checkbox.
  • Help keep the policy library current; review updates to security policies, standards, and procedures to stay practical and aligned.
  • Turn program data into insights and translate findings into metrics for leadership.
  • Take on additional GRC projects as the program evolves; priorities shift as the team grows.

Skills

GRC experience
IT audit
Security frameworks
Policy writing
Risk assessment

Tools

Anecdotes
Vanta
Drata
Secureframe
OneTrust
ServiceNow GRC

Job description

About Us

Fireworks is the platform for specialized intelligence, enabling companies to build, train, and serve AI models tailored to their own data, workflows, and products. Founded by the team behind PyTorch and backed by AMD, Atreides, Benchmark Capital, Index Ventures, Lightspeed, NVIDIA, Sequoia Capital, and TCV, Fireworks powers production AI with hundreds of state-of-the-art open models across text, image, embedding, audio, and multimodal workloads. Today, Fireworks is a Series D company valued at $17.5 billion, bringing together an ambitious, collaborative team that's building the future of enterprise AI.

Fireworks is the platform for specialized intelligence, enabling companies to build, train, and serve AI models tailored to their own data, workflows, and products. Founded by the team behind PyTorch and backed by AMD, Atreides, Benchmark Capital, Index Ventures, Lightspeed, NVIDIA, Sequoia Capital, and TCV, Fireworks powers production AI with hundreds of state-of-the-art open models across text, image, embedding, audio, and multimodal workloads. Today, Fireworks is a Series D company valued at $17.5 billion, bringing together an ambitious, collaborative team that's building the future of enterprise AI.

About The Role

We're looking for a GRC Analyst to join our security and compliance team. You'll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale. From day one you'll get hands‑on with core operational areas of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third‑party risk management, with clear room to grow into broader ownership, audit leadership, and program strategy over time. This is a great fit for someone with solid working experience in security or compliance who's looking to build hands‑on ownership and deepen their skill set in a fast‑moving SaaS environment.

What You'll Do
  • Support day‑to‑day GRC operations including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage of policy and control exceptions.
  • Support the risk management program help perform annual and ad‑hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
  • Support third‑party risk management run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors.
  • Execute internal audits using established test procedures to test control effectiveness, and support external audit cycles by coordinating evidence, control owners, and remediation.
  • Help maintain continuous control monitoring and evidence automation support administration of our GRC platform, keep automated control tests and evidence healthy, and help maintain audit readiness year‑round rather than point‑in‑time.
  • Build relationships with cross‑functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping.
  • Partner with control owners to help them understand their control responsibilities and expectations, prepare for audits, and operationalize controls rather than treat compliance as a checkbox.
  • Help keep the policy library current support reviews and updates to security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under.
  • Turn program data into insights help translate access review, awareness, and risk findings into insights and metrics that flag high‑risk users, teams, or behaviors, and support reporting to leadership.
  • Take on additional GRC projects as the program evolves; we're a growing team and priorities shift.
How The Role Will Grow
  • Greater ownership of core programs move from supporting established processes to owning entire workstreams (user access reviews, security awareness, third‑party risk) end‑to‑end.
  • Audit leadership progress from executing established test procedures to helping design new ones, scoping audits, and coordinating auditors directly.
  • Program and control maturity contribute to control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale.
  • Growing influence as you build expertise, you'll have opportunities to mentor newer team members and represent GRC in cross‑functional projects.
What We're Looking For
  • 3-5 years of experience in GRC, IT audit, information security, or a closely related field
  • Working knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA
  • Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)
  • Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)
  • Hands‑on experience administering a security awareness or phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar)
  • Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated
  • Strong written communication; you can translate control requirements and security concepts into language engineers, customers, and non‑technical employees understand
  • Detail‑oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines
  • A collaborative mindset; you enjoy working across teams rather than gatekeeping
Why Fireworks?
  • Solve Hard Problems: Tackle challenges at the forefront of AI infrastructure, from low‑latency inference to scalable model serving.
  • Build What’s Next: Work with bleeding‑edge technology that impacts how businesses and developers harness AI globally.
  • Ownership & Impact: Join a fast‑growing, passionate team where your work directly shapes the future of AI—no bureaucracy, just results.
  • Learn from the Best: Collaborate with world‑class engineers and AI researchers who thrive on curiosity and innovation.

Fireworks AI is an equal‑opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all innovators.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

MTS, Security
MTS, Security

Fireworks • San Mateo (CA)

On-site
USD 150,000 - 210,000
Security Operations Lead
Security Operations Lead

Fireworks AI • San Mateo (CA)

On-site
USD 180,000 - 230,000
Security Operations Lead
Security Operations Lead

Fireworks AI • New York (NY)

On-site
USD 150,000 - 230,000
Member of Technical Staff, Enterprise Foundations
Member of Technical Staff, Enterprise Foundations

Fireworks • New York (NY)

On-site
USD 180,000 - 240,000
Strategic Projects Lead
Strategic Projects Lead

Fireworks AI • New York (NY)

On-site
USD 110,000 - 180,000
Member of Technical Staff- Full Stack
Member of Technical Staff- Full Stack

Fireworks • San Mateo (CA)

On-site
USD 180,000 - 240,000
GRC Analyst — Shape Enterprise AI Security & Compliance
GRC Analyst — Shape Enterprise AI Security & Compliance

Fireworks AI • San Mateo (CA)

On-site
USD 120,000 - 160,000
Member of Technical Staff
Member of Technical Staff

Fireworks AI • New York (NY)

On-site
USD 170,000 - 260,000
Member of Technical Staff, Software Engineer
Member of Technical Staff, Software Engineer

Fireworks • San Mateo (CA)

On-site
USD 175,000 - 220,000
Equity
Competitive salary
Benefits package
Social and Community Manager
Social and Community Manager

Fireworks AI • San Mateo (CA)

On-site
USD 140,000 - 160,000
Equity options
Comprehensive benefits package