Fireworks AI
Senior GRC Specialist
San Mateo, CA · Senior
Sponsorship not specifiedDetected 16 days ago
AWSGCPAzureCloud PlatformsPyTorchLLMsComplianceAuditingHIPAALeadershipCommunicationInternal Audit
About the role
- We're looking for a GRC Specialist to join our security and compliance team.
- You'll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale.
- This is a great fit for someone with a foundation in security or compliance who's ready to take ownership of meaningful work in a fast-moving SaaS environment.
Responsibilities
- Own day-to-day GRC operations - including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage and enforcement of policy and control exceptions.
- Manage third-party risk - run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors.
- Design and execute targeted internal audits to test control effectiveness, and facilitate or support external audit cycles by coordinating evidence, control owners, and remediation.
- Own continuous control monitoring and evidence automation - administer our GRC platform, keep automated control tests and evidence healthy, and maintain audit readiness year-round rather than point-in-time.
- Build and foster relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping.
- Partner with control owners to educate them on their control responsibilities, ownership, and expectations
- Turn program data into action - translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, report to leadership, and drive targeted interventions.
- Partner with control owners to educate them on their control responsibilities, ownership, and expectations; prepare them for audits; and help them operationalize controls rather than treat compliance as a checkbox.
- As you build context on our environment and program, you'll take on broader ownership across third-party risk, audit leadership, and program maturity:
- Program and control maturity - lead control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale.
Requirements
- 5-7 years of experience in GRC, IT audit, information security, or a closely related field
- Working knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA
- Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)
- Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)
- Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated
- Detail-oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines
- you enjoy working across teams rather than gatekeeping
Compensation
- Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
Company info
- At Fireworks, we're building the future of generative AI infrastructure.
- Our platform delivers the highest-quality models with the fastest and most scalable inference in the industry.
- We've been independently benchmarked as the leader in LLM inference speed and are driving cutting-edge innovation through projects like our own function calling and multimodal models.
- Fireworks is a Series C company valued at $4 billion and backed by top investors including Benchmark, Sequoia, Lightspeed, Index, and Evantic.
- We're an ambitious, collaborative team of builders, founded by veterans of Meta PyTorch and Google Vertex AI.
- About the role
- From day one you'll own operational cornerstones of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with room to grow into broader audit and program leadership over time.
- Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
- Keep the policy library current - review and update security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under.
- Take on additional GRC projects as the program evolves; we're a growing team and priorities shift.
- How the role will grow
- End-to-end audit leadership - move from supporting audits to owning them: scoping, auditor coordination, and driving the cycle to completion across frameworks.
- Leadership and influence - mentor newer team members, represent GRC in cross-functional projects, and help shape the direction of the program.
- What we're looking for
Apply directly at Fireworks AI →Create a free account for alerts like thisView Fireworks AI immigration profile
This listing is sourced directly from Fireworks AI's careers page and normalized into a canonical job model.