Apply Edge Start your job search

GRC & Privacy Analyst

Jobgether · United States

Apply & track with Apply Edge
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC & Privacy Analyst based in United States.This role offers the opportunity to strengthen governance, risk, compliance, and privacy practices within a mission-driven, data-sensitive organization. You will help operationalize security and privacy programs while ensuring alignment with leading industry frameworks and regulations. The position combines compliance automation, audit management, risk assessment, privacy, and emerging AI governance. You’ll work cross-functionally with internal teams and external assessors to maintain strong controls and drive remediation efforts. The role also encourages the practical use of AI tools to streamline evidence review, policy development, risk analysis, and reporting. It is an ideal environment for a detail-oriented professional who enjoys working at the intersection of security, privacy, compliance, and technology. Your work will directly contribute to building trustworthy systems that support employee and customer well-being.AccountabilitiesAdminister and optimize compliance automation platforms such as Vanta, maintaining continuous control monitoring, evidence collection, and compliance visibility.Lead and support audit activities across multiple security, privacy, and compliance frameworks, coordinating internal stakeholders and external assessors.Maintain and continuously mature compliance programs aligned with SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework.Interpret and apply privacy requirements, including HIPAA and GDPR, and help ensure appropriate data-handling practices across the organization.Conduct risk assessments, document findings, track remediation activities, and maintain accurate control and evidence documentation.Coordinate compliance initiatives using structured project management practices, including establishing timelines, assigning responsibilities, monitoring progress, and driving deliverables to completion.Partner with security, privacy, IT, legal, and business stakeholders to strengthen governance processes and embed privacy-by-design principles.Identify opportunities to improve the efficiency and scalability of GRC processes through automation and emerging technologies.Leverage AI tools to enhance evidence analysis, policy drafting, risk assessment, reporting, and other compliance workflows.Monitor evolving regulatory, security, privacy, and AI governance requirements and help translate them into actionable compliance initiatives.RequirementsDemonstrated experience working in GRC, security compliance, privacy, or a closely related discipline, preferably with experience using compliance automation platforms such as Vanta.Working knowledge of major security and privacy frameworks, including SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF.Strong understanding of privacy regulations and data-protection requirements, particularly HIPAA and GDPR.Proven experience supporting or managing audits, evidence collection, control documentation, risk assessments, and remediation activities.Strong project management capabilities, with the ability to coordinate multiple stakeholders, establish priorities, manage timelines, and drive initiatives through completion.Comfort using AI tools and a willingness to incorporate them into everyday compliance, analysis, documentation, and reporting workflows.Excellent written and verbal communication skills, with the ability to explain technical, regulatory, and compliance topics clearly to different audiences.Strong attention to detail, organization, judgment, and ability to manage sensitive information responsibly.Experience working within healthcare, wellness, technology, or another regulated and data-sensitive environment is highly valuable.Familiarity with AI governance and emerging requirements surrounding responsible and compliant use of artificial intelligence.Relevant professional certifications such as CISA, CIPP, or ISO 27001 Implementer are a plus.A proactive, curious, and adaptable mindset, with the ability to work effectively in a changing technology and regulatory landscape.BenefitsCompetitive total compensation: Target compensation of $115,000–$125,000, combining salary, performance bonus, and equity; final compensation may vary based on experience and expertise.Health coverage: Medical, dental, and vision insurance.Retirement benefits: 401(k) program with company match.Generous paid time off: Programs designed to encourage employees to rest, recharge, and maintain sustainable performance.Thrive Time: Additional paid time off following major projects or particularly intense work periods, providing dedicated time to recover and reset.Wellness-focused culture: A supportive, human-centric environment with wellness-oriented benefits and a strong emphasis on employee well-being.Mission-driven work: Opportunity to contribute to technology designed to improve well-being, performance, and mental resilience for people around the world.Career growth: Opportunities to develop professionally while contributing to evolving security, privacy, compliance, and AI governance programs.Remote flexibility: Remote position based in the United States.How Jobgether WorksWe use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.We appreciate your interest and wish you the best! Why Apply Through Jobgether?Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.