×
Register Here to Apply for Jobs or Post Jobs. X

GRC Analyst

Job in San Mateo, San Mateo County, California, 94409, USA
Listing for: Fireworks AI
Full Time position
Listed on 2026-08-27
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below

About Us

Fireworks is the platform for specialized intelligence, enabling companies to build, train, and serve AI models tailored to their own data, workflows, and products. Founded by the team behind PyTorch and backed by AMD, Atreides, Benchmark Capital, Index Ventures, Lightspeed, NVIDIA, Sequoia Capital, and TCV, Fireworks powers production AI with hundreds of state-of-the-art open models across text, image, embedding, audio, and multimodal workloads.

Today, Fireworks is a Series D company valued at $17.5 billion, bringing together an ambitious, collaborative team that's building the future of enterprise AI.

Fireworks is the platform for specialized intelligence, enabling companies to build, train, and serve AI models tailored to their own data, workflows, and products. Founded by the team behind PyTorch and backed by AMD, Atreides, Benchmark Capital, Index Ventures, Lightspeed, NVIDIA, Sequoia Capital, and TCV, Fireworks powers production AI with hundreds of state-of-the-art open models across text, image, embedding, audio, and multimodal workloads.

Today, Fireworks is a Series D company valued at $17.5 billion, bringing together an ambitious, collaborative team that's building the future of enterprise AI.

About

The Role

We're looking for a GRC Analyst to join our security and compliance team. You'll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale. From day one you'll get hands‑on with core operational areas of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third‑party risk management, with clear room to grow into broader ownership, audit leadership, and program strategy over time.

This is a great fit for someone with solid working experience in security or compliance who's looking to build hands‑on ownership and deepen their skill set in a fast‑moving SaaS environment.

What You'll Do
  • Support day‑to‑day GRC operations including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage of policy and control exceptions.
  • Support the risk management program help perform annual and ad‑hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
  • Support third‑party risk management run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors.
  • Execute internal audits using established test procedures to test control effectiveness, and support external audit cycles by coordinating evidence, control owners, and remediation.
  • Help maintain continuous control monitoring and evidence automation support administration of our GRC platform, keep automated control tests and evidence healthy, and help maintain audit readiness year‑round rather than point‑in‑time.
  • Build relationships with cross‑functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping.
  • Partner with control owners to help them understand their control responsibilities and expectations, prepare for audits, and operationalize controls rather than treat compliance as a checkbox.
  • Help keep the policy library current support reviews and updates to security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under.
  • Turn program data into insights help translate access review, awareness, and risk findings into insights and metrics that flag high‑risk users, teams, or behaviors, and support reporting to leadership.
  • Take on additional GRC projects as the program evolves; we're a growing team and priorities shift.
How

The Role Will Grow
  • Greater ownership of core programs move from supporting established processes to owning entire work streams (user access reviews, security awareness, third‑party risk) end‑to‑end.
  • Audit leadership progress from executing…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary