Senior GRC Specialist

Fireworks AI

San Mateo (CA)

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Fireworks AI is seeking a GRC Specialist to mature our compliance program across SOC 2, HIPAA, ISO standards, GDPR, and more. You’ll own user access reviews, risk assessments, third‑party risk, and internal audits while partnering with engineering and operations to keep controls effective as we scale.

You’ll build relationships across teams, drive audit readiness year‑round, and grow into broader program leadership as the company scales its security posture.

Qualifications

  • 5–7 years of experience in GRC, IT audit, or information security.
  • Working knowledge of SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA.
  • Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC).
  • Experience running IAM concepts (RBAC, least privilege, segregation of duties, JML).
  • Hands-on security awareness platform experience (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint).
  • Comfort with cloud environments (AWS, GCP, Azure).
  • Strong written communication and ability to translate security concepts for diverse audiences.
  • Detail-oriented, organized, and collaborative across teams

Responsibilities

  • Own day-to-day GRC operations – user access reviews, certifications, security awareness, phishing simulations, JML tracking, and policy exceptions.
  • Run the risk management program – annual/ad-hoc risk assessments, risk register, remediation, and issue closure.
  • Manage third‑party risk – vendor/subprocessor risk assessments and ongoing monitoring.
  • Design and execute internal audits to test controls and support external audits with evidence and remediation.
  • Own continuous control monitoring and evidence automation via the GRC platform.
  • Build cross-functional relationships with engineering, IT, operations, legal, and sales.
  • Educate control owners on responsibilities and expectations; prepare for audits.
  • Keep the policy library current with practical, aligned standards and procedures.
  • Translate findings into actionable metrics for leadership and targeted interventions.
  • Take on additional GRC projects as the program grows; priorities shift.
  • End-to-end audit leadership – scope, auditor coordination, and drive cycles to completion.
  • Lead control maturity and automation to raise program efficiency.
  • Mentor teammates and influence cross-functional projects.

Skills

GRC experience
Security frameworks
Audit coordination
IAM concepts
Security awareness

Tools

Anecdotes
Vanta
Drata
Secureframe
OneTrust
ServiceNow GRC

Job description

About Us

Fireworks is the platform for specialized intelligence, enabling companies to build, train, and serve AI models tailored to their own data, workflows, and products. Founded by the team behind PyTorch and backed by AMD, Atreides, Benchmark Capital, Index Ventures, Lightspeed, NVIDIA, Sequoia Capital, and TCV, Fireworks powers production AI with hundreds of state‑of‑the‑art open models across text, image, embedding, audio, and multimodal workloads. Today, Fireworks is a Series D company valued at $17.5 billion, bringing together an ambitious, collaborative team that's building the future of enterprise AI.


About The Role

We're looking for a GRC Specialist to join our security and compliance team. You'll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale. From day one you'll own operational cornerstones of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with room to grow into broader audit and program leadership over time. This is a great fit for someone with a foundation in security or compliance who's ready to take ownership of meaningful work in a fast-moving SaaS environment.


What You’ll Do


  • Own day-to-day GRC operations - including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage and enforcement of policy and control exceptions.

  • Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.

  • Manage third-party risk - run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors.

  • Design and execute targeted internal audits to test control effectiveness, and facilitate or support external audit cycles by coordinating evidence, control owners, and remediation.

  • Own continuous control monitoring and evidence automation - administer our GRC platform, keep automated control tests and evidence healthy, and maintain audit readiness year-round rather than point-in-time.

  • Build and foster relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping.

  • Partner with control owners to educate them on their control responsibilities, ownership, and expectations; prepare them for audits; and help them operationalize controls rather than treat compliance as a checkbox.

  • Keep the policy library current - review and update security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under.

  • Turn program data into action - translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, report to leadership, and drive targeted interventions.

  • Take on additional GRC projects as the program evolves; we’re a growing team and priorities shift.


How The Role Will Grow


  • End-to-end audit leadership - move from supporting audits to owning them: scoping, auditor coordination, and driving the cycle to completion across frameworks.

  • Program and control maturity - lead control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale.

  • Leadership and influence - mentor newer team members, represent GRC in cross-functional projects, and help shape the direction of the program.


What We’re Looking For


  • 5-7 years of experience in GRC, IT audit, information security, or a closely related field

  • Working knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA

  • Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)

  • Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)

  • Hands‑on experience administering a security awareness or phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar)

  • Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated

  • Strong written communication; you can translate control requirements and security concepts into language engineers, customers, and non-technical employees understand

  • Detail-oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines

  • A collaborative mindset; you enjoy working across teams rather than gatekeeping


Why Fireworks?


  • Solve Hard Problems: Tackle challenges at the forefront of AI infrastructure, from low-latency inference to scalable model serving.

  • Build What’s Next: Work with bleeding‑edge technology that impacts how businesses and developers harness AI globally.

  • Ownership & Impact: Join a fast-growing, passionate team where your work directly shapes the future of AI—no bureaucracy, just results.

  • Learn from the Best: Collaborate with world‑class engineers and AI researchers who thrive on curiosity and innovation.


Fireworks AI is an equal‑opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all innovators.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Specialist
Senior GRC Specialist

Fireworks AI • United States

On-site
USD 110,000 - 150,000
Senior GRC Specialist
Senior GRC Specialist

Fireworks AI • New York (NY)

On-site
USD 120,000 - 165,000
Member of Technical Staff, Enterprise Foundations
Member of Technical Staff, Enterprise Foundations

Fireworks AI • New York (NY)

On-site
USD 180,000 - 260,000
MTS, Security
MTS, Security

Fireworks • San Mateo (CA)

On-site
USD 150,000 - 210,000
Security Operations Lead
Security Operations Lead

Fireworks AI • San Mateo (CA)

On-site
USD 180,000 - 230,000
Member of Technical Staff- Full Stack
Member of Technical Staff- Full Stack

Fireworks • San Mateo (CA)

On-site
USD 180,000 - 240,000
Member of Technical Staff, Enterprise Foundations
Member of Technical Staff, Enterprise Foundations

Fireworks • New York (NY)

On-site
USD 180,000 - 240,000
Security Operations Lead
Security Operations Lead

Fireworks AI • New York (NY)

On-site
USD 150,000 - 230,000
Strategic Projects Lead
Strategic Projects Lead

Fireworks AI • New York (NY)

On-site
USD 110,000 - 180,000
Member of Technical Staff, New Grad (BS/MS)
Member of Technical Staff, New Grad (BS/MS)

Fireworks AI • New York (NY)

On-site
USD 95,000 - 130,000