openleverjobgether
GRC & Privacy Analyst
Jobgether
LocationUS
EmploymentFull-time
Posted2026-08-21T07:14:57.761000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:c428e858-1175-4488-8adc-108b6e31b0c7
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC & Privacy Analyst based in United States. This role offers the opportunity to strengthen governance, risk, compliance, and privacy practices within a mission-driven, data-sensitive organization. You will help operationalize security and privacy programs while ensuring alignment with leading industry frameworks and regulations. The position combines compliance automation, audit management, risk assessment, privacy, and emerging AI governance. You’ll work cross-functionally with internal teams and external assessors to maintain strong controls and drive remediation efforts. The role also encourages the practical use of AI tools to streamline evidence review, policy development, risk analysis, and reporting. It is an ideal environment for a detail-oriented professional who enjoys working at the intersection of security, privacy, compliance, and technology. Your work will directly contribute to building trustworthy systems that support employee and customer well-being. Administer and optimize compliance automation platforms such as Vanta, maintaining continuous control monitoring, evidence collection, and compliance visibility. Lead and support audit activities across multiple security, privacy, and compliance frameworks, coordinating internal stakeholders and external assessors. Maintain and continuously mature compliance programs aligned with SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework. Interpret and apply privacy requirements, including HIPAA and GDPR, and help ensure appropriate data-handling practices across the organization. Conduct risk assessments, document findings, track remediation activities, and maintain accurate control and evidence documentation. Coordinate compliance initiatives using structured project management practices, including establishing timelines, assigning responsibilities, monitoring progress, and driving deliverables to completion. Partner with security, privacy, IT, legal, and business stakeholders to strengthen governance processes and embed privacy-by-design principles. Identify opportunities to improve the efficiency and scalability of GRC processes through automation and emerging technologies. Leverage AI tools to enhance evidence analysis, policy drafting, risk assessment, reporting, and other compliance workflows. Monitor evolving regulatory, security, privacy, and AI governance requirements and help translate them into actionable compliance initiatives. Requirements: Demonstrated experience working in GRC, security compliance, privacy, or a closely related discipline, preferably with experience using compliance automation platforms such as Vanta. Working knowledge of major security and privacy frameworks, including SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF. Strong understanding of privacy regulations and data-protection requirements, particularly HIPAA and GDPR. Proven experience supporting or managing audits, evidence collection, control documentation, risk assessments, and remediation activities. Strong project management capabilities, with the ability to coordinate multiple stakeholders, establish priorities, manage timelines, and drive initiatives through completion. Comfort using AI tools and a willingness to incorporate them into everyday compliance, analysis, documentation, and reporting workflows. Excellent written and verbal communication skills, with the ability to explain technical, regulatory, and compliance topics clearly to different audiences. Strong attention to detail, organization, judgment, and ability to manage sensitive information responsibly. Experience working within healthcare, wellness, technology, or another regulated and data-sensitive environment is highly valuable. Familiarity with AI governance and emerging requirements sur
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.