Senior GRC Specialist
San Mateo, United States · On-site · Full-time
- Posted 2w ago
- From Fireworks AI’s careers page
- Location
- San Mateo, United States
- Work mode
- On-site
- Type
- Full-time
- Level
- Senior
- Experience
- 5+ years
- Department
- Engineering
Opens the listing on jobs.ashbyhq.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
About the role
We're looking for a GRC Specialist to join our security and compliance team. You'll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale. From day one you'll own operational cornerstones of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with room to grow into broader audit and program leadership over time. This is a great fit for someone with a foundation in security or compliance who's ready to take ownership of meaningful work in a fast-moving SaaS environment.
What you'll do
-
Own day-to-day GRC operations - including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage and enforcement of policy and control exceptions.
-
Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
-
Manage third-party risk - run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors.
-
Design and execute targeted internal audits to test control effectiveness, and facilitate or support external audit cycles by coordinating evidence, control owners, and remediation.
-
Own continuous control monitoring and evidence automation - administer our GRC platform, keep automated control tests and evidence healthy, and maintain audit readiness year-round rather than point-in-time.
-
Build and foster relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping.
-
Partner with control owners to educate them on their control responsibilities, ownership, and expectations; prepare them for audits; and help them operationalize controls rather than treat compliance as a checkbox.
-
Keep the policy library current - review and update security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under.
-
Turn program data into action - translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, report to leadership, and drive targeted interventions.
-
Take on additional GRC projects as the program evolves; we're a growing team and priorities shift.
What we're looking for
-
5-7 years of experience in GRC, IT audit, information security, or a closely related field
-
Working knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA
-
Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)
-
Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)
-
Hands-on experience administering a security awareness or phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar)
-
Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated
-
Strong written communication; you can translate control requirements and security concepts into language engineers, customers, and non-technical employees understand
-
Detail-oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines
-
A collaborative mindset; you enjoy working across teams rather than gatekeeping
Skills they ask for
Pick one to see other roles that ask for it.
About Fireworks AI
AI inference and model serving platformFireworks AI provides infrastructure for deploying and serving AI models and specialized intelligence.
See all 43 roles at Fireworks AIMore roles at Fireworks AI
See all 43- Privacy Program EngineerUnited States · RemoteEngineering · RemoteUnited States1d
- Member of Technical Staff, GrowthSan Mateo · Senior · HybridEngineering · Senior · HybridSan Mateo, United States2d
- Head of Process & Controls - Finance and OperationsSan Mateo · Director · HybridDirector · HybridSan Mateo, United States3d
- Office Manager, New YorkNew York · HybridAdministrative & Clerical Support · HybridNew York, United States3d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.