GRC Analyst

Fireworks AI
San Mateo
Workplace: OnsiteFull timeUSD 160,000 - 170,000 annuallyFunction: Legal, Risk & ComplianceExperience: 3-5 yearsSkills: ["Written communication","Detail-oriented","Organized","Collaborative mindset","Cross-functional partnership"]

Join the security and compliance team to mature Fireworks’ GRC program across SOC 2, HIPAA, ISO 27001/27701/42001, and GDPR. Support day-to-day GRC operations including user access reviews, security awareness and phishing/deepfake simulations, third-party risk management, and internal/external audit execution. Help maintain continuous control monitoring and evidence automation in a GRC platform, translate findings into insights for leadership, and grow into broader ownership over key workstreams.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Fireworks AI
Fireworks AI
3 days ago

GRC Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Join the security and compliance team to mature Fireworks’ GRC program across SOC 2, HIPAA, ISO 27001/27701/42001, and GDPR. Support day-to-day GRC operations including user access reviews, security awareness and phishing/deepfake simulations, third-party risk management, and internal/external audit execution. Help maintain continuous control monitoring and evidence automation in a GRC platform, translate findings into insights for leadership, and grow into broader ownership over key workstreams.
Location: San Mateo
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Support day-to-day GRC operations including user access reviews and certifications, security awareness/phishing/deepfake simulation facilitation, JML tracking, and triage of policy/control exceptions.
  • •Support the risk management program by performing annual and ad-hoc risk assessments, maintaining the risk register, partnering on remediation, and tracking issues to closure.
  • •Run third-party risk management by conducting vendor and subprocessor risk assessments, performing ongoing monitoring, and tracking remediation across critical vendors.
  • •Execute internal audits and support external audit cycles by coordinating evidence, control owners, and remediation.
  • •Maintain continuous control monitoring and evidence automation in the GRC platform, keep automated tests and evidence healthy, support year-round audit readiness, and translate program data into leadership insights.

Pay and Benefits

Salary: USD 160,000 - 170,000 annually

Key Requirements

  • •3-5 years of experience in GRC, IT audit, information security, or a closely related field.
  • •Working knowledge of security and privacy frameworks including SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA.
  • •Experience with GRC platforms such as Anecdotes, Vanta, Drata, Secureframe, OneTrust, or ServiceNow GRC.
  • •Experience running user access reviews and understanding identity and access management concepts (RBAC, least privilege, segregation of duties, JML).
  • •Hands-on experience administering a security awareness or phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar).
Experience:3-5 yearsSaaSEnterprise AIGRC
Skills:Written communicationDetail-orientedOrganizedCollaborative mindsetCross-functional partnership
Tech Stack:SOC 2HIPAAISO 27001ISO 27701ISO 42001GDPRNIST CSFCCPAAnecdotesVantaDrataSecureframeOneTrustServiceNow GRCAdaptive SecurityKnowBe4HoxhuntProofpointAWSGCP

Company Brief

Fireworks AI
Develops AI-driven tools to generate and optimize visual marketing content for brands and creators, automating production of short-form videos and multimedia assets for social platforms to improve engagement and scale creative workflows.
Industry: SaaS
Website