Jobgether
GRC & Privacy Analyst
operationsfull-timeUS
SALARY
$115k – $125k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
Accountabilities:
- Administer and optimize compliance automation platforms such as Vanta, maintaining continuous control monitoring, evidence collection, and compliance visibility.
- Lead and support audit activities across multiple security, privacy, and compliance frameworks, coordinating internal stakeholders and external assessors.
- Maintain and continuously mature compliance programs aligned with SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework.
- Interpret and apply privacy requirements, including HIPAA and GDPR, and help ensure appropriate data-handling practices across the organization.
- Conduct risk assessments, document findings, track remediation activities, and maintain accurate control and evidence documentation.
- Coordinate compliance initiatives using structured project management practices, including establishing timelines, assigning responsibilities, monitoring progress, and driving deliverables to completion.
- Partner with security, privacy, IT, legal, and business stakeholders to strengthen governance processes and embed privacy-by-design principles.
- Identify opportunities to improve the efficiency and scalability of GRC processes through automation and emerging technologies.
- Leverage AI tools to enhance evidence analysis, policy drafting, risk assessment, reporting, and other compliance workflows.
- Monitor evolving regulatory, security, privacy, and AI governance requirements and help translate them into actionable compliance initiatives.
- Demonstrated experience working in GRC, security compliance, privacy, or a closely related discipline, preferably with experience using compliance automation platforms such as Vanta.
- Working knowledge of major security and privacy frameworks, including SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF.
- Strong understanding of privacy regulations and data-protection requirements, particularly HIPAA and GDPR.
- Proven experience supporting or managing audits, evidence collection, control documentation, risk assessments, and remediation activities.
- Strong project management capabilities, with the ability to coordinate multiple stakeholders, establish priorities, manage timelines, and drive initiatives through completion.
- Comfort using AI tools and a willingness to incorporate them into everyday compliance, analysis, documentation, and reporting workflows.
- Excellent written and verbal communication skills, with the ability to explain technical, regulatory, and compliance topics clearly to different audiences.
- Strong attention to detail, organization, judgment, and ability to manage sensitive information responsibly.
- Experience working within healthcare, wellness, technology, or another regulated and data-sensitive environment is highly valuable.
- Familiarity with AI governance and emerging requirements surrounding responsible and compliant use of artificial intelligence.
- Relevant professional certifications such as CISA, CIPP, or ISO 27001 Implementer are a plus.
- A proactive, curious, and adaptable mindset, with the ability to work effectively in a changing technology and regulatory landscape.
- Competitive total compensation: Target compensation of $115,000–$125,000, combining salary, performance bonus, and equity; final compensation may vary based on experience and expertise.
- Health coverage: Medical, dental, and vision insurance.
- Retirement benefits: 401(k) program with company match.
- Generous paid time off: Programs designed to encourage employees to rest, recharge, and maintain sustainable performance.
- Thrive Time: Additional paid time off following major projects or particularly intense work periods, providing dedicated time to recover and reset.
- Wellness-focused culture: A supportive, human-centric environment with wellness-oriented benefits and a strong emphasis on employee well-being.
- Mission-driven work: Opportunity to contribute to technology designed to improve well-being, performance, and mental resilience for people around the world.
- Career growth: Opportunities to develop professionally while contributing to evolving security, privacy, compliance, and AI governance programs.
- Remote flexibility: Remote position based in the United States.
Requirements:
Benefits:
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply