Fireworks AI

Fireworks AI

Senior GRC Specialist

San Mateo, CA · Senior

Sponsorship not specifiedDetected 16 days ago
AWSGCPAzureCloud PlatformsPyTorchLLMsComplianceAuditingHIPAALeadershipCommunicationInternal Audit

About the role

  • We're looking for a GRC Specialist to join our security and compliance team.
  • You'll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale.
  • This is a great fit for someone with a foundation in security or compliance who's ready to take ownership of meaningful work in a fast-moving SaaS environment.

Responsibilities

  • Own day-to-day GRC operations - including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage and enforcement of policy and control exceptions.
  • Manage third-party risk - run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors.
  • Design and execute targeted internal audits to test control effectiveness, and facilitate or support external audit cycles by coordinating evidence, control owners, and remediation.
  • Own continuous control monitoring and evidence automation - administer our GRC platform, keep automated control tests and evidence healthy, and maintain audit readiness year-round rather than point-in-time.
  • Build and foster relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping.
  • Partner with control owners to educate them on their control responsibilities, ownership, and expectations
  • Turn program data into action - translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, report to leadership, and drive targeted interventions.
  • Partner with control owners to educate them on their control responsibilities, ownership, and expectations; prepare them for audits; and help them operationalize controls rather than treat compliance as a checkbox.
  • As you build context on our environment and program, you'll take on broader ownership across third-party risk, audit leadership, and program maturity:
  • Program and control maturity - lead control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale.

Requirements

  • 5-7 years of experience in GRC, IT audit, information security, or a closely related field
  • Working knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA
  • Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)
  • Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)
  • Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated
  • Detail-oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines
  • you enjoy working across teams rather than gatekeeping

Compensation

  • Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.

Company info

  • At Fireworks, we're building the future of generative AI infrastructure.
  • Our platform delivers the highest-quality models with the fastest and most scalable inference in the industry.
  • We've been independently benchmarked as the leader in LLM inference speed and are driving cutting-edge innovation through projects like our own function calling and multimodal models.
  • Fireworks is a Series C company valued at $4 billion and backed by top investors including Benchmark, Sequoia, Lightspeed, Index, and Evantic.
  • We're an ambitious, collaborative team of builders, founded by veterans of Meta PyTorch and Google Vertex AI.
  • About the role
  • From day one you'll own operational cornerstones of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with room to grow into broader audit and program leadership over time.
  • Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
  • Keep the policy library current - review and update security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under.
  • Take on additional GRC projects as the program evolves; we're a growing team and priorities shift.
  • How the role will grow
  • End-to-end audit leadership - move from supporting audits to owning them: scoping, auditor coordination, and driving the cycle to completion across frameworks.
  • Leadership and influence - mentor newer team members, represent GRC in cross-functional projects, and help shape the direction of the program.
  • What we're looking for

This listing is sourced directly from Fireworks AI's careers page and normalized into a canonical job model.