Fireblocks logo
Posted 1w agoTel Aviv-Yafo, Tel Aviv District, Israel

GRC Operations Specialist

MiddleOn-site (Tel Aviv)Salary undisclosed
Job Description

Fireblocks is the company bringing global finance onchain. Backed by over $1 billion in capital, we are the premier digital asset infrastructure provider trusted by thousands of industry-defining financial institutions, including banks, payment providers, fintechs, and global corporates such as BNY Mellon, BNP Paribas, ANZ Bank, Western Union, Stripe, and Revolut. Built for institutional scale and security, our enterprise-grade platform and network have powered over $14 trillion in digital asset transfers worldwide.

About The Role

We are looking for a passionate and experienced Governance, Risk, and Compliance (GRC) operations specialist to contribute to our company's efforts in making Fireblocks the most secure and trusted provider of digital asset management solutions. This role is critical in driving our day-to-day GRC programs, ensuring they are well maintained, run according to schedule, and align with our business needs.

As the GRC operations specialist, you will oversee the successful implementation and progress of GRC programs, practices, and projects, while collaborating with multiple cross-functional teams within the security department and outside of it. This role will focus on the GRC's Third Party Risk Management (TPRM) and Employee Awareness programs, while also contributing to additional team activities and duties.

We're looking for someone who goes beyond traditional GRC operations. Hands-on, daily use of AI tools, from chatbot-assisted research and document creation to AI-assisted development, is a core part of how this role operates, not a nice-to-have. This is a driver of change and innovation, not just an operational function.

Reporting line: GRC Director

What You Will Do

  • Own, manage, and continuously improve the company's Third Party Risk Management (TPRM) program: conducting vendor risk assessments in line with the company's information security requirements, maintaining the supplier register, running annual follow-ups with vendors, and building workflows for the end-to-end process.
  • Own, manage, and continuously improve the company's security awareness program, including employee training, phishing simulations, and organizational resilience, making sure its scope, content, cadence and overall performance stay aligned with the latest expectations and relevant to the business.
  • Manage ongoing operations within the GRC team, including project planning and tracking, and periodic and annual planning.
  • Drive ongoing GRC efficiency through innovation, automation, and data-driven research using AI tools as a primary lever, this is a central expectation of the role, not a peripheral skill.
  • Support and contribute to ongoing GRC operations such as internal and external audits, risk assessments, certification processes, policy management, business continuity program and more.

What You Will Bring:

  • Minimum of 3+ years of experience in cybersecurity or GRC.
  • Proven experience in cyber or IT or third party risk management.
  • Proven experience in the security awareness domain, including development and implementation of security training programs and their testing (phishing, vishing, social engineering etc.).
  • Demonstrated, hands-on fluency with AI tools as part of your daily workflow, using AI chatbots/assistants, and comfort with AI-assisted development (e.g., building scripts, automations, or internal tools with the help of AI coding assistants). This is a critical part of the profile.
  • Visionary and innovation-driven, capable of implementing security and compliance programs in complex, fast-paced organizations.
  • Exceptional communication, collaboration, and interpersonal skills, with the ability to engage both technical and non-technical audiences.
  • Strong analytical, problem-solving skills and attention to detail, with the ability to manage multiple projects simultaneously and meet tight deadlines.

Preferred Qualifications:

  • Familiarity with industry best practices, regulations, frameworks, standards and certifications such as SOC 2, ISO, NIST, CIS, DORA, GDPR, etc. A plus, but not a minimum requirement.
  • Experience working with GRC software and utilities such as compliance management, policy management, risk management, vendor management, awareness, training and phishing simulation platforms, etc.
  • Background in the financial/digital assets sector.
  • Good technological understanding and familiarity with product development practices.

Fireblocks' mission is to enable every business to easily and securely access digital assets and cryptocurrencies. In order to do that, we strongly believe our workforce should be as diverse as our clients, and this is why we embrace diversity and inclusion in all its forms. 

Please see our candidate privacy policy here.

Similar Openings in Other

View all in category