GRC Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
We’re looking for a GRC Specialist to join our security and compliance team. You’ll help us mature our compliance program across frameworks like SOC 2, HIPAA, ISO 27001, ISO 27701, ISO 42001, and GDPR - supporting audits, managing risk, and partnering with engineering and operations teams to keep our controls effective as we scale. From day one you’ll own operational cornerstones of our program, including user access reviews, our security awareness program through the Adaptive Security platform, and third-party risk management, with room to grow into broader audit and program leadership over time. This is a great fit for someone with a foundation in security or compliance who’s ready to take ownership of meaningful work in a fast-moving SaaS environment., * Own day-to-day GRC operations - including (but not limited to) user access reviews and certifications, security awareness and phishing/deepfake simulation facilitation, JML tracking, and triage and enforcement of policy and control exceptions.
- Run the risk management program - perform annual and ad-hoc risk assessments, maintain the risk register, partner with risk owners on remediation, and track issues through to closure.
- Manage third-party risk - run vendor and subprocessor risk assessments, conduct ongoing monitoring, and track remediation across our critical vendors.
- Design and execute targeted internal audits to test control effectiveness, and facilitate or support external audit cycles by coordinating evidence, control owners, and remediation.
- Own continuous control monitoring and evidence automation - administer our GRC platform, keep automated control tests and evidence healthy, and maintain audit readiness year-round rather than point-in-time.
- Build and foster relationships with cross-functional partners across engineering, IT, operations, legal, and sales - meeting teams where they are rather than gatekeeping.
- Partner with control owners to educate them on their control responsibilities, ownership, and expectations; prepare them for audits; and help them operationalize controls rather than treat compliance as a checkbox.
- Keep the policy library current - review and update security policies, standards, and procedures so they stay practical and aligned to the frameworks we operate under.
- Turn program data into action - translate access review, awareness, and risk findings into insights and metrics that flag high-risk users, teams, or behaviors, report to leadership, and drive targeted interventions.
- Take on additional GRC projects as the program evolves; we’re a growing team and priorities shift.
How the role will grow
As you build context on our environment and program, you’ll take on broader ownership across third-party risk, audit leadership, and program maturity:
- End-to-end audit leadership - move from supporting audits to owning them: scoping, auditor coordination, and driving the cycle to completion across frameworks.
- Program and control maturity - lead control improvement and automation initiatives that raise the bar on how efficiently we run the program as we scale.
- Leadership and influence - mentor newer team members, represent GRC in cross-functional projects, and help shape the direction of the program., Artificial Intelligence * Big Data * Cloud * Machine Learning * Software * Business Intelligence * Data Privacy The role involves designing cloud infrastructure, managing production Kubernetes clusters, optimizing CI/CD pipelines, enhancing developer experience, and ensuring reliable AI workloads. Candidates should have extensive experience in infrastructure and distributed systems engineering with strong coding skills and cloud expertise. Top Skills: AWSAzureDatadogDockerElkGCPGoGrafanaJavaKubernetesPrometheusPythonTerraform Civic Roundtable
Requirements
- 5-7 years of experience in GRC, IT audit, information security, or a closely related field
- Working knowledge of major security and privacy frameworks such as SOC 2, ISO 27001/27701/42001, NIST CSF, HIPAA, GDPR, or CCPA
- Experience with GRC platforms (Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC)
- Experience running user access reviews and a solid understanding of identity and access management concepts (RBAC, least privilege, segregation of duties, JML processes)
- Hands-on experience administering a security awareness or phishing simulation platform (Adaptive Security, KnowBe4, Hoxhunt, Proofpoint, or similar)
- Comfort with cloud environments (AWS, GCP, or Azure) and how SaaS products are built and operated
- Strong written communication; you can translate control requirements and security concepts into language engineers, customers, and non-technical employees understand
- Detail-oriented and organized, with the ability to juggle multiple audits, campaigns, and deadlines
- A collaborative mindset; you enjoy working across teams rather than gatekeeping
Benefits & conditions
An Hour Ago In-Office or Remote 140K-170K Annually Senior level 140K-170K Annually Senior level Social Impact * Software Owns core product areas across the full lifecycle, from discovery and strategy through execution, launch, and iteration. Conducts customer research, workflow analysis, usability testing, competitive research, and data analysis. Partners closely with engineering and design to deliver scalable user experiences, defines success metrics and instrumentation, and supports launches through messaging and cross-functional readiness. The role also requires hands-on AI experience and operates in a high-ownership, low-structure B2B SaaS environment. Top Skills: AICRM SailPoint
Customer Success Manager
An Hour Ago Remote or Hybrid United States 60K-101K Annually Mid level 60K-101K Annually Mid level Artificial Intelligence * Cloud * Sales * Security * Software * Cybersecurity * Data Privacy Manage assigned client accounts to ensure satisfaction and renewals. Coach clients on SailPoint/IdentityIQ identity and access solutions, monitor usage and risks, provide strategic updates, identify expansion opportunities, and drive resolutions to customer issues. Top Skills: IdentityiqSailpoint
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
About the company
Fireworks is the platform for specialized intelligence, enabling companies to build, train, and serve AI models tailored to their own data, workflows, and products. Founded by the team behind PyTorch and backed by AMD, Atreides, Benchmark Capital, Index Ventures, Lightspeed, NVIDIA, Sequoia Capital, and TCV, Fireworks powers production AI with hundreds of state-of-the-art open models across text, image, embedding, audio, and multimodal workloads. Today, Fireworks is a Series D company valued at $17.5 billion, bringing together an ambitious, collaborative team that’s building the future of enterprise AI., * Solve Hard Problems: Tackle challenges at the forefront of AI infrastructure, from low-latency inference to scalable model serving.
- Build What’s Next: Work with bleeding-edge technology that impacts how businesses and developers harness AI globally.
- Ownership & Impact: Join a fast-growing, passionate team where your work directly shapes the future of AI-no bureaucracy, just results.
- Learn from the Best: Collaborate with world-class engineers and AI researchers who thrive on curiosity and innovation.
Fireworks AI is an equal-opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all innovators.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Dev Digest 120 - Apple and peers
Dev Digest 121 - AI goes offline
Dev Digest 138 - Are you secure about this?