Fireworks AI Logo

Fireworks AI

Senior GRC Specialist

Posted 21 Days Ago
Be an Early Applicant
In-Office
San Mateo, CA, USA
Senior level
In-Office
San Mateo, CA, USA
Senior level
Manage day-to-day GRC operations including access reviews, security awareness campaigns, third-party risk, risk assessments, control testing and evidence automation. Support external audits, maintain policies, translate findings into metrics, and partner with engineering and ops to remediate and operationalize controls.
The summary above was generated by AI
About Us:

At Fireworks, we’re building the future of generative AI infrastructure. Our platform delivers the highest-quality models with the fastest and most scalable inference in the industry. We’ve been independently benchmarked as the leader in LLM inference speed and are driving cutting-edge innovation through projects like our own function calling and multimodal models. Fireworks is a Series C company valued at $4 billion and backed by top investors including Benchmark, Sequoia, Lightspeed, Index, and Evantic. We’re an ambitious, collaborative team of builders, founded by veterans of Meta PyTorch and Google Vertex AI.

About the role

We're looking for a GRC Specialist to join our security and compliance team. You'll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale. From day one you'll own operational cornerstones of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with room to grow into broader audit and program leadership over time. This is a great fit for someone with a foundation in security or compliance who's ready to take ownership of meaningful work in a fast-moving SaaS environment.

What you'll do

  • Own day-to-day GRC operations - including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage and enforcement of policy and control exceptions.
  • Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
  • Manage third-party risk - run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors.
  • Design and execute targeted internal audits to test control effectiveness, and facilitate or support external audit cycles by coordinating evidence, control owners, and remediation.
  • Own continuous control monitoring and evidence automation - administer our GRC platform, keep automated control tests and evidence healthy, and maintain audit readiness year-round rather than point-in-time.
  • Build and foster relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping.
  • Partner with control owners to educate them on their control responsibilities, ownership, and expectations; prepare them for audits; and help them operationalize controls rather than treat compliance as a checkbox.
  • Keep the policy library current - review and update security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under.
  • Turn program data into action - translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, report to leadership, and drive targeted interventions.
  • Take on additional GRC projects as the program evolves; we're a growing team and priorities shift.

How the role will grow

As you build context on our environment and program, you'll take on broader ownership across third-party risk, audit leadership, and program maturity:

  • End-to-end audit leadership - move from supporting audits to owning them: scoping, auditor coordination, and driving the cycle to completion across frameworks.
  • Program and control maturity - lead control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale.
  • Leadership and influence - mentor newer team members, represent GRC in cross-functional projects, and help shape the direction of the program.

What we're looking for

  • 5-7 years of experience in GRC, IT audit, information security, or a closely related field
  • Working knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA
  • Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)
  • Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)
  • Hands-on experience administering a security awareness or phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar)
  • Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated
  • Strong written communication; you can translate control requirements and security concepts into language engineers, customers, and non-technical employees understand
  • Detail-oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines
  • A collaborative mindset; you enjoy working across teams rather than gatekeeping
Why Fireworks AI?
  • Solve Hard Problems: Tackle challenges at the forefront of AI infrastructure, from low-latency inference to scalable model serving.
  • Build What’s Next: Work with bleeding-edge technology that impacts how businesses and developers harness AI globally.
  • Ownership & Impact: Join a fast-growing, passionate team where your work directly shapes the future of AI—no bureaucracy, just results.
  • Learn from the Best: Collaborate with world-class engineers and AI researchers who thrive on curiosity and innovation.

Fireworks AI is an equal-opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all innovators.

HQ

Fireworks AI Redwood, California, USA Office

Redwood, CA, United States, 94063

Similar Jobs

10 Days Ago
In-Office or Remote
San Francisco, CA, USA
Senior level
Senior level
Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Generative AI
This role involves building and scaling compliance programs, translating security and regulatory requirements into scalable solutions, and collaborating across teams, specifically in AI governance and technical compliance automation.
Top Skills: DodFedrampHipaaIso 27001Iso 42001PythonSoc 2
An Hour Ago
Remote or Hybrid
California, USA
65K-116K Annually
Senior level
65K-116K Annually
Senior level
Digital Media • Information Technology • News + Entertainment
Drive territory strategy and acquire/retain mid-market and enterprise multi-location customers through direct and partner channels. Prospect, deliver face-to-face presentations, negotiate deals, meet/exceed sales targets, and coordinate internal teams to ensure service and operational excellence. Maintain sales records, stay current on competitive landscape and network technologies, and support customer retention.
Top Skills: 23)Business ContinuityCustomer Premises Equipment (Cpe)CybersecurityDisaster RecoveryEthernetInternet TechnologiesLanManNetwork DesignNetwork SecurityNetworking Protocols (Layers 1SdwanVoipVpnWanWdm
4 Hours Ago
Hybrid
San Francisco, CA, USA
108K-278K Annually
Senior level
108K-278K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Lead underwriting for emerging mobility products (ridehail, delivery, autonomous vehicles). Develop insights, underwrite commercial auto, workers' comp and GL, collaborate on cross-sell opportunities, curate a profitable diversified book, sustain broker relationships, and define underwriting processes. Use analytical, communication, and negotiation skills to evaluate complex risks and shape Liberty Mutual's mobility strategy.

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account