GRC Analyst — Shape Enterprise AI Security & Compliance

Fireworks AI

San Mateo (CA)

On-site

USD 120,000 - 160,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fireworks AI is seeking a GRC Analyst to join our security and compliance team in a fast-paced SaaS environment. You’ll mature our program across SOC 2, HIPAA, ISO standards, GDPR, and more, supporting audits, managing risk, and partnering with engineering and operations to keep controls effective as we scale.

From day one you’ll engage in user access reviews, awareness training, third‑party risk management, and carrying authority into audits, with clear room to grow into leadership and strategy

Qualifications

  • 3–5 years of experience in GRC, IT audit, information security, or closely related field.
  • Working knowledge of major security frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA.
  • Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC).
  • Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes).
  • Hands-on experience administering security awareness or phishing simulation platforms (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar).
  • Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated.
  • Strong written communication; translate control requirements and security concepts for engineers, customers, and non-technical employees.
  • Detail-oriented and organized; manage multiple audits, campaigns, and deadlines.
  • Collaborative mindset; work across teams rather than gatekeeping.

Responsibilities

  • Support day-to-day GRC operations including user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage of policy and control exceptions.
  • Support the risk management program: perform risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
  • Support third-party risk management: run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across critical vendors.
  • Execute internal audits using established test procedures to test control effectiveness, and coordinate evidence and remediation for external audits.
  • Help maintain continuous control monitoring and evidence automation, administer the GRC platform, and keep audit readiness year-round.
  • Build relationships with cross-functional partners across engineering, IT, operations, legal, and sales; avoid gatekeeping.
  • Partner with control owners to understand their responsibilities, prepare for audits, and operationalize controls rather than treating compliance as a checkbox.
  • Help keep the policy library current; review updates to security policies, standards, and procedures to stay practical and aligned.
  • Turn program data into insights and translate findings into metrics for leadership.
  • Take on additional GRC projects as the program evolves; priorities shift as the team grows.

Skills

GRC experience
IT audit
Security frameworks
Policy writing
Risk assessment

Tools

Anecdotes
Vanta
Drata
Secureframe
OneTrust
ServiceNow GRC

Job description

Fireworks AI is seeking a GRC Analyst to join our security and compliance team in a fast-paced SaaS environment. You’ll mature our program across SOC 2, HIPAA, ISO standards, GDPR, and more, supporting audits, managing risk, and partnering with engineering and operations to keep controls effective as we scale.

From day one you’ll engage in user access reviews, awareness training, third‑party risk management, and carrying authority into audits, with clear room to grow into leadership and strategy

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst - Audit & Risk Lead for SaaS
GRC Analyst - Audit & Risk Lead for SaaS

Fireworks • San Mateo (CA)

On-site
USD 120,000 - 180,000
GRC Analyst
GRC Analyst

Fireworks • San Mateo (CA)

On-site
USD 120,000 - 180,000
GRC Analyst
GRC Analyst

Fireworks AI • San Mateo (CA)

On-site
USD 120,000 - 160,000
GRC Analyst | AI Security & Compliance
GRC Analyst | AI Security & Compliance

Zip • San Francisco (CA)

On-site
USD 95,000 - 150,000
Start-up equity
Health, vision & dental coverage
Catered meals
+5
GRC Security Analyst: Automate Compliance & Risk
GRC Security Analyst: Automate Compliance & Risk

Discord • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
Equity
Relocation assistance
GRC Analyst — Lead Security & Compliance at Scale
GRC Analyst — Lead Security & Compliance at Scale

Zip • United States

On-site
USD 95,000 - 150,000
Start-up equity
Health, vision & dental coverage
Catered meals
+7
GRC Analyst: Risk, Compliance & Security Awareness
GRC Analyst: Risk, Compliance & Security Awareness

Protective • United States

Remote
USD 70,000 - 77,000
Health insurance
Dental insurance
Vision insurance
+5
GRC Analyst — AI Security & Compliance (Onsite SF)
GRC Analyst — AI Security & Compliance (Onsite SF)

Icehouseventures • San Francisco (CA)

On-site
USD 135,000 - 165,000
Comprehensive health coverage
Flexible PTO
Equity package
GRC & AI Compliance Lead
GRC & AI Compliance Lead

Perplexity • California (MO)

On-site
USD 120,000 - 180,000
GRC & Privacy Analyst — AI-Driven Compliance
GRC & Privacy Analyst — AI-Driven Compliance

Thrive Global Holdings, Inc. • United States

Remote
USD 115,000 - 125,000
401(k) with company match
Health, dental, and vision benefits
Thrive Time