Senior GRC Specialist

Fireworks AI
San Mateo
Workplace: OnsiteFull timeUSD 200,000 - 220,000 annuallyFunction: Solutions Engineering & Sales EngineeringExperience: 5-7 yearsSkills: ["Detail-oriented","Organized","Strong communication","Collaborative"]

Own day-to-day GRC operations for an enterprise AI SaaS, maturing compliance across SOC 2, HIPAA, ISO 27001/27701/42001, and GDPR. Run risk assessments and maintain the risk register, manage third-party risk, and design targeted internal audits. Administer the GRC platform for continuous control monitoring and evidence automation, while translating program findings into actionable insights for engineering, IT, operations, legal, and sales.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Fireworks AI
Fireworks AI
1 month ago

Senior GRC Specialist

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live
Reposted: similar role first listed 1 month ago

Job Summary

Own day-to-day GRC operations for an enterprise AI SaaS, maturing compliance across SOC 2, HIPAA, ISO 27001/27701/42001, and GDPR. Run risk assessments and maintain the risk register, manage third-party risk, and design targeted internal audits. Administer the GRC platform for continuous control monitoring and evidence automation, while translating program findings into actionable insights for engineering, IT, operations, legal, and sales.
Location: San Mateo
Workplace: Onsite
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Own day-to-day GRC operations including user access reviews/certifications, security awareness and phishing/deepfake simulations, JML tracking, and exception triage/enforcement.
  • •Run the risk management program by conducting risk assessments, maintaining the risk register, partnering on remediation, and tracking issues to closure.
  • •Manage third-party risk through vendor/subprocessor risk assessments, ongoing monitoring, and remediation tracking.
  • •Design and execute internal audits to test control effectiveness and support external audit cycles by coordinating evidence, control owners, and remediation.
  • •Administer the GRC platform for continuous control monitoring and evidence automation to maintain audit readiness year-round.

Pay and Benefits

Salary: USD 200,000 - 220,000 annually
Equity and Bonus:Equity

Key Requirements

  • •5-7 years of experience in GRC, IT audit, information security, or a closely related field.
  • •Working knowledge of security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA.
  • •Experience with GRC platforms including Anecdotes, Vanta, Drata, Secureframe, OneTrust, and ServiceNow GRC.
  • •Experience running user access reviews and understanding IAM concepts such as RBAC, least privilege, segregation of duties, and JML processes.
  • •Hands-on experience with a security awareness/phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar).
Experience:5-7 yearsSaaSGRCIT auditInformation security
Skills:Detail-orientedOrganizedStrong communicationCollaborative
Tech Stack:SOC 2HIPAAISO 27001ISO 27701ISO 42001GDPRCCPANIST CSFGRC platformsAnecdotesVantaDrataSecureframeOneTrustServiceNow GRCAdaptive SecurityKnowBe4HoxhuntProofpointRBAC

Company Brief

Fireworks AI
Develops AI-driven tools to generate and optimize visual marketing content for brands and creators, automating production of short-form videos and multimedia assets for social platforms to improve engagement and scale creative workflows.
Industry: SaaS
Website