GRC Analyst
FluidStackGPU Cloud company
New York, United StatesMid
Situational Awareness
Astro Capital (NY)
7GC & Co
Armyn Capital
Autopilot Management Company
Bare Metal Ventures
About the role
TL;DR
Manage compliance program for AI infrastructure security.
- •Run the day-to-day compliance program end to end across SOC 2, ISO 27001, NIST 800-53, and FedRAMP Moderate equivalency.
- •Key Responsibilities Continuous evidence collection, control monitoring, and audit readiness on GRC platforms (Vanta) and in-house tooling.
- •Own the policy and procedure set: draft, maintain, and run the review cycle.
- •Run recurring control operations on cadence, access reviews, control owner attestations, and evidence refreshes.
- •Drive audit and assessment cycles with external auditors and assessors and manage the POA&M to closure.
- •Bring each new site and team into the compliance program as we scale.
- •Requirements Experience operating controls and pulling evidence against at least one major framework through a real audit.
- •Experience owning a compliance documentation set, policies, procedures, and control narratives.
- •Experience sitting across from an auditor or assessor, defending how a control runs in practice, and closing findings.
- •Ability to get evidence and adherence out of busy engineers, system owners, and employees across the org, on time.
- •Ability to catch a stale control, an expired access grant, or a coverage gap before an assessor does.
- •Ability to translate a control requirement into the exact artifact that proves it.
Required skills
SOC 2Compliance Management
Domain expertise
cybersecurity
Benefits & perks
Competitive total compensation package (salary + equity), Retirement or pension plan, Health, dental, and vision insurance, Generous PTO policy
Tech stack
SOC 2