About the role
TL;DR
GRC Analyst to mature compliance programs, manage risk, and support audits.
- •Fireworks is seeking a GRC Analyst to join their security and compliance team.
- •This role will focus on maturing the compliance program across various frameworks, supporting audits, managing risk, and collaborating with engineering and operations teams.
- •Key Responsibilities Support day-to-day GRC operations including user access reviews, security awareness programs, and JML tracking.
- •Assist with risk management, including risk assessments, maintaining the risk register, and tracking remediation.
- •Support third-party risk management by running vendor assessments and tracking remediation.
- •Execute internal audits and support external audit cycles by coordinating evidence and control owners.
- •Help maintain continuous control monitoring and evidence automation.
- •Requirements 3-5 years of experience in GRC, IT audit, or information security.
- •Working knowledge of security and privacy frameworks like SOC 2, ISO 27001, HIPAA, and GDPR.
- •Experience with GRC platforms and administering security awareness platforms.
- •Comfort with cloud environments (AWS, GCP, or Azure).
- •Strong written communication and organizational skills.
Required skills
SOC 2HIPAAGDPRAWSGoogle CloudAzureIAMSSOMFA
Domain expertise
aideveloper-tools
Tech stack
SOC 2HIPAAGDPRAWSGoogle CloudAzure