SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Fireworks is a Series D AI infrastructure platform (valued at $17.5B) backed by NVIDIA, Sequoia, and others, enabling companies to build and serve specialized AI models. The GRC Analyst role supports the security and compliance team in maturing Fireworks' compliance program across SOC 2, HIPAA, ISO 27001/27701/42001, and GDPR frameworks.
Day-to-day responsibilities include executing user access reviews and certifications, administering security awareness and phishing simulation campaigns, managing JML (joiners/movers/leavers) tracking, and triaging policy exceptions. You'll support the risk management program by performing annual and ad-hoc risk assessments, maintaining the risk register, and partnering with risk owners on remediation. Third-party risk management includes vendor and subprocessor assessments, ongoing monitoring, and remediation tracking across critical vendors.
You'll execute internal audits using established test procedures to validate control effectiveness and support external audit cycles by coordinating evidence, control owners, and remediation efforts. The role includes maintaining continuous control monitoring and evidence automation—administering the GRC platform, keeping automated tests healthy, and supporting year-round audit readiness rather than point-in-time compliance.
Cross-functional collaboration is central: you'll build relationships with engineering, IT, operations, legal, and sales teams, helping control owners understand their responsibilities and operationalize controls rather than treating compliance as a checkbox. You'll help keep the policy library current through reviews and updates to security policies and procedures. The role also involves translating program data into insights—flagging high-risk users, teams, or behaviors through access review and awareness findings, and supporting leadership reporting.
Growth trajectory includes moving from supporting established processes to owning entire workstreams (access reviews, awareness, third-party risk) end-to-end, progressing from executing test procedures to designing new ones and coordinating auditors, contributing to control improvement and automation initiatives, and mentoring newer team members as you build expertise.