Fluidstack Logo

Fluidstack

GRC Analyst

Posted 19 Days Ago
In-Office
New York, NY, USA
218K-269K Annually
Mid level
In-Office
New York, NY, USA
218K-269K Annually
Mid level
Manage day-to-day GRC program across SOC 2, ISO 27001, NIST 800-53 and FedRAMP equivalency: evidence collection, control monitoring, audit readiness, policy ownership, recurring control operations, POA&M management, and onboarding new sites into the compliance program.
The summary above was generated by AI
About Fluidstack

We exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we've ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don't share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.

We're singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization-scale infrastructure for AI.


We hire people who care deeply about this problem space. If that is you, please apply!

How We Operate

  • Extreme ownership. Full autonomy. Own things end to end often taking on scope outside your core role without being asked to get things done.

  • Velocity. We drive everything forward as fast as possible.

  • First principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.

  • Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.

The Security Team

Examples of key problems the team is working on

  • You’re securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and we’re standing up the compute to hold them faster than anyone ever has. A breach isn’t a leak, it’s the frontier walking out the door.

  • Build the entire security program from scratch. Most leaders inherit someone else’s system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents.

  • Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small.

Role Scope

  • Run the day-to-day compliance program end to end across SOC 2 Type II, ISO 27001, NIST 800-53, and FedRAMP Moderate equivalency: continuous evidence collection, control monitoring, and audit readiness held on GRC platforms (Vanta) and the tooling we build in-house.

  • Own the policy and procedure set: draft, maintain, and run the review cycle so documentation keeps pace with the controls as the program grows.

  • Run recurring control operations on cadence, access reviews, control owner attestations, and evidence refreshes, chasing system owners and employees across the org directly to get them done on time.

  • Drive audit and assessment cycles with external auditors and assessors and manage the POA&M to closure, tracking each finding to a named owner and milestone so nothing ages past its deadline.

  • Bring each new site and team into the compliance program as we scale, mapping their systems to existing controls so coverage stays consistent instead of fragmenting facility by facility.

What We’re Looking For

The below is a starting point. We always make space for exceptional people, so if you don’t fit this role exactly, tell us where you would.

  • You’ve operated controls and pulled evidence against at least one major framework (SOC 2, ISO 27001, NIST 800-53, or FedRAMP) through a real audit, not just read the policy.

  • You’ve owned a compliance documentation set, policies, procedures, and control narratives, and kept it current as the environment changed underneath you.

  • You’ve sat across from an auditor or assessor, defended how a control runs in practice, and closed findings without escalating every question upward.

  • You get evidence and adherence out of busy engineers, system owners, and employees across the org, on time, without a manager pushing you to do it.

  • You catch a stale control, an expired access grant, or a coverage gap before an assessor does, because you watch the portfolio continuously, not once a quarter.

  • You translate a control requirement into the exact artifact that proves it, and you keep that mapping tight across overlapping frameworks instead of collecting the same evidence twice.

  • Bonus: FedRAMP Moderate equivalency or NIST 800-53 evidence work. GRC platforms (Vanta) or comparable continuous-compliance tooling. Cloud, GPU, or data center environments. Mapping controls across SOC 2, ISO 27001, and NIST in parallel.

Salary & Benefits
  • Competitive total compensation package (salary + equity).

  • Retirement or pension plan, in line with local norms.

  • Health, dental, and vision insurance.

  • Generous PTO policy, in line with local norms.

Total compensation may also include equity in the form of stock options.

We are committed to pay equity and transparency.

Fluidstack is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Fluidstack will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

You will receive a confirmation email once your application has successfully been accepted. If there is an error with your submission and you did not receive a confirmation email, please email [email protected] with your resume/CV, the role you've applied for, and the date you submitted your application-- someone from our recruiting team will be in touch.

Similar Jobs

25 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
134K-202K Annually
Mid level
134K-202K Annually
Mid level
Artificial Intelligence • Cloud • Software
Manage and maintain compliance with security and privacy frameworks (ISO 27001, SOC 2, HIPAA, PCI DSS). Coordinate audits, drive remediation, improve controls and evidence management, support security questionnaires for deal cycles, and design compliance training while partnering across teams to integrate controls into the SDLC.
Top Skills: AWSAzureDatadogDrataFrontend DevelopmentHipaaIso 27001LinearOpen Source ComponentsPci DssSdlcSoc 2
22 Days Ago
Hybrid
New York, NY, USA
162K-202K Annually
Senior level
162K-202K Annually
Senior level
Consumer Web • Healthtech • Professional Services • Social Impact • Software
Lead and mature Headway's GRC program across certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk, security awareness training, and technical risk management. Manage audit readiness, vendor assessments, risk register, and cross-functional embedding of compliance. Build repeatable, AI-enabled processes and coordinate remediation and assessor activities.
Top Skills: AIDrataGrc PlatformsHipaaHitrustOnetrustPci-DssSoc 2Vanta
13 Days Ago
In-Office or Remote
New York, NY, USA
106K-222K Annually
Senior level
106K-222K Annually
Senior level
Events • Analytics • Consulting
Conduct research and deliver strategic advice on risk management and cyber risk quantification. Develop and maintain risk artifacts (standards, procedures, appetite, registry), produce 6–8 research projects yearly, consult with clients, collaborate across Forrester teams, advise vendors, publish insights, and present externally. Support C-suite and risk leaders and travel up to 20%.
Top Skills: Grc Platforms

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account