Jobedly Post a Job

Senior GRC Specialist

Fireworks AI · San Mateo, CA
Full-timeG&AManufacturing$162,000–$218,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Senior Grc Specialist role

Senior Grc Specialist positions focus on delivering results in their domain. This page aggregates open Senior Grc Specialist roles and what employers typically expect.

About Us: Fireworks is the platform for specialized intelligence, enabling companies to build, train, and serve AI models tailored to their own data, workflows, and products. Founded by the team behind PyTorch and backed by AMD, Atreides, Benchmark Capital, Index Ventures, Lightspeed, NVIDIA, Sequoia Capital, and TCV, Fireworks powers production AI with hundreds of state-of-the-art open models across text, image, embedding, audio, and multimodal workloads. Today, Fireworks is a Series D company valued at $17.5 billion, bringing together an ambitious, collaborative team that's building the future of enterprise AI. About the role We're looking for a GRC Specialist to join our security and compliance team. You'll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale. From day one you'll own operational cornerstones of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with room to grow into broader audit and program leadership over time. This is a great fit for someone with a foundation in security or compliance who's ready to take ownership of meaningful work in a fast-moving SaaS environment. What you'll do Own day-to-day GRC operations - including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage and enforcement of policy and control exceptions. Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure. Manage third-party risk - run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors. Design and execute targeted internal audits to test control effectiveness, and facilitate or support external audit cycles by coordinating evidence, control owners, and remediation. Own continuous control monitoring and evidence automation - administer our GRC platform, keep automated control tests and evidence healthy, and maintain audit readiness year-round rather than point-in-time. Build and foster relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping. Partner with control owners to educate them on their control responsibilities, ownership, and expectations; prepare them for audits; and help them operationalize controls rather than treat compliance as a checkbox. Keep the policy library current - review and update security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under. Turn program data into action - translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, report to leadership, and drive targeted interventions. Take on additional GRC projects as the program evolves; we're a growing team and priorities shift. How the role will grow As you build context on our environment and program, you'll take on broader ownership across third-party risk, audit leadership, and program maturity: End-to-end audit leadership - move from supporting audits to owning them: scoping, auditor coordination, and driving the cycle to completion across frameworks. Program and control maturity - lead control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale. Leadership and influence - mentor newer team members, represent GRC in cross-functional projects, and help shape the direction of the program. What we're looking for 5-7 years of experience in GRC, IT audit, information security, or a closely related field Wo…

Salary estimate

$162,000 – $218,000/yr
Provided by the employer.

Skills for this role

PytorchSalesLeadershipSecurityAutomation

Resume tips for Senior Grc Specialist applicants

Interview preparation

Prepare concrete STAR-format stories that show Senior Grc Specialist outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Senior Grc Specialist problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Fireworks AI

Fireworks AI is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles