Jobgether
Jobgether

GRC & Privacy Analyst

operationsfull-timeUS
SALARY
$115k – $125k/yr
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

Accountabilities:

    • Administer and optimize compliance automation platforms such as Vanta, maintaining continuous control monitoring, evidence collection, and compliance visibility.
    • Lead and support audit activities across multiple security, privacy, and compliance frameworks, coordinating internal stakeholders and external assessors.
    • Maintain and continuously mature compliance programs aligned with SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework.
    • Interpret and apply privacy requirements, including HIPAA and GDPR, and help ensure appropriate data-handling practices across the organization.
    • Conduct risk assessments, document findings, track remediation activities, and maintain accurate control and evidence documentation.
    • Coordinate compliance initiatives using structured project management practices, including establishing timelines, assigning responsibilities, monitoring progress, and driving deliverables to completion.
    • Partner with security, privacy, IT, legal, and business stakeholders to strengthen governance processes and embed privacy-by-design principles.
    • Identify opportunities to improve the efficiency and scalability of GRC processes through automation and emerging technologies.
    • Leverage AI tools to enhance evidence analysis, policy drafting, risk assessment, reporting, and other compliance workflows.
    • Monitor evolving regulatory, security, privacy, and AI governance requirements and help translate them into actionable compliance initiatives.
    • Requirements:

      • Demonstrated experience working in GRC, security compliance, privacy, or a closely related discipline, preferably with experience using compliance automation platforms such as Vanta.
      • Working knowledge of major security and privacy frameworks, including SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF.
      • Strong understanding of privacy regulations and data-protection requirements, particularly HIPAA and GDPR.
      • Proven experience supporting or managing audits, evidence collection, control documentation, risk assessments, and remediation activities.
      • Strong project management capabilities, with the ability to coordinate multiple stakeholders, establish priorities, manage timelines, and drive initiatives through completion.
      • Comfort using AI tools and a willingness to incorporate them into everyday compliance, analysis, documentation, and reporting workflows.
      • Excellent written and verbal communication skills, with the ability to explain technical, regulatory, and compliance topics clearly to different audiences.
      • Strong attention to detail, organization, judgment, and ability to manage sensitive information responsibly.
      • Experience working within healthcare, wellness, technology, or another regulated and data-sensitive environment is highly valuable.
      • Familiarity with AI governance and emerging requirements surrounding responsible and compliant use of artificial intelligence.
      • Relevant professional certifications such as CISA, CIPP, or ISO 27001 Implementer are a plus.
      • A proactive, curious, and adaptable mindset, with the ability to work effectively in a changing technology and regulatory landscape.
      • Benefits:

        • Competitive total compensation: Target compensation of $115,000–$125,000, combining salary, performance bonus, and equity; final compensation may vary based on experience and expertise.
        • Health coverage: Medical, dental, and vision insurance.
        • Retirement benefits: 401(k) program with company match.
        • Generous paid time off: Programs designed to encourage employees to rest, recharge, and maintain sustainable performance.
        • Thrive Time: Additional paid time off following major projects or particularly intense work periods, providing dedicated time to recover and reset.
        • Wellness-focused culture: A supportive, human-centric environment with wellness-oriented benefits and a strong emphasis on employee well-being.
        • Mission-driven work: Opportunity to contribute to technology designed to improve well-being, performance, and mental resilience for people around the world.
        • Career growth: Opportunities to develop professionally while contributing to evolving security, privacy, compliance, and AI governance programs.
        • Remote flexibility: Remote position based in the United States.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now