# GRC Analyst

**Company:** [Fireworks AI](https://hotfix.jobs/companies/fireworks-ai)
**Location:** San Mateo, CA
**Role:** Security Engineering
**Salary:** $160k – $170k/yr
**Experience:** 3+ years
**Skills:** SOC 2, ISO 27001, Iso 27701, Iso 42001, Nist Csf, HIPAA, GDPR, Grc Platforms, Identity And Access Management, RBAC, AWS, GCP, Microsoft Azure, Security Awareness
**Posted:** 2026-08-21

> The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.

## Job Description

## Responsibilities
- Support GRC operations, including user access reviews and certifications, security awareness and phishing/deepfake simulations, joiner-mover-leaver tracking, and policy/control exception triage.
- Perform annual and ad hoc risk assessments, maintain the risk register, coordinate remediation, and track issues to closure.
- Conduct vendor and subprocessor risk assessments, ongoing monitoring, and remediation tracking for critical third parties.
- Execute internal audits and support external audit cycles by coordinating evidence, control owners, and remediation.
- Maintain continuous control monitoring, automated control tests, evidence health, GRC platform administration, and year-round audit readiness.
- Partner with engineering, IT, operations, legal, sales, and control owners to operationalize controls and prepare for audits.
- Maintain and update security policies, standards, and procedures.
- Analyze access review, security awareness, and risk data to produce metrics and leadership insights.
- Take on additional GRC projects as the program evolves.

## Requirements
- 3–5 years of experience in GRC, IT audit, information security, or a related field.
- Working knowledge of SOC 2, ISO 27001, ISO 27701, ISO 42001, NIST CSF, HIPAA, GDPR, or CCPA.
- Experience with GRC platforms such as Anecdotes, Vanta, Drata, Secureframe, OneTrust, or ServiceNow GRC.
- Experience running user access reviews and understanding IAM concepts including RBAC, least privilege, segregation of duties, and JML processes.
- Hands-on experience administering security awareness or phishing simulation platforms.
- Familiarity with AWS, Google Cloud, or Azure and SaaS operations.
- Strong written communication, organization, attention to detail, and cross-functional collaboration skills.

## Compensation
- Annual salary: $160,000–$170,000.

## Similar jobs

- [Application Security Engineer](https://hotfix.jobs/jobs/2910e6b0-19a3-46fe-9af2-2fe3f5ea6edf) - Vannevar - Remote - $160k – $210k/yr
- [Cyber Threat Intel Analyst](https://hotfix.jobs/jobs/56d78636-b895-48d1-a62c-1b5e253d3d78) - Wiz - Washington, DC - $160k – $220k/yr
- [Federal Compliance Manager](https://hotfix.jobs/jobs/1e20be75-7d2d-4b41-9067-ffbb919a86a7) - Figma - Remote - $153k – $245k/yr
- [Sensing and Perception System Safety Engineer](https://hotfix.jobs/jobs/6d559fa7-ea8f-41d7-b06f-9dcd21c834ac) - Zoox - Foster City, CA - $170k – $267k/yr
- [Security Engineer](https://hotfix.jobs/jobs/81e148cc-4e02-435e-8a54-df7bf4ca0b66) - Greptile - San Francisco, CA - $170k – $300k/yr

**Apply:** https://hotfix.jobs/jobs/8f835d00-9815-44c9-b8f9-d81dcab07741
**Canonical:** https://hotfix.jobs/jobs/8f835d00-9815-44c9-b8f9-d81dcab07741