GRC & Privacy Analyst

Thrive Global
United States
Workplace: RemoteFull timeUSD 115,000 - 125,000 annuallyFunction: Communications, PR & CommunitySkills: ["Communication","Attention to detail","Cross-functional coordination","Risk assessment","Project execution"]

Own and operationalize governance, risk, and compliance and privacy programs, including administering compliance automation (Vanta) and continuous control monitoring. Lead and support audits across SOC 2, ISO, HITRUST, HIPAA, NIST 800-53, and the NIST AI RMF, while maintaining evidence and control documentation. Apply HIPAA and GDPR privacy standards, conduct risk assessments, and drive remediation through clear timelines and cross-functional delivery.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Thrive Global
Thrive Global
1 day ago

GRC & Privacy Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Own and operationalize governance, risk, and compliance and privacy programs, including administering compliance automation (Vanta) and continuous control monitoring. Lead and support audits across SOC 2, ISO, HITRUST, HIPAA, NIST 800-53, and the NIST AI RMF, while maintaining evidence and control documentation. Apply HIPAA and GDPR privacy standards, conduct risk assessments, and drive remediation through clear timelines and cross-functional delivery.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Communications, PR & Community
Seniority: Mid level

Key Responsibilities

  • •Administer and optimize compliance automation platforms such as Vanta, including continuous control monitoring and evidence collection.
  • •Lead and support audits across multiple frameworks by coordinating with internal stakeholders and external assessors.
  • •Maintain and mature compliance programs mapped to SOC 2, ISO 27001/27701/42001, HITRUST, HIPAA, and NIST frameworks.
  • •Interpret and apply privacy standards (including HIPAA and GDPR) to ensure regulatory-compliant data handling.
  • •Conduct risk assessments, track remediation, and manage evidence and control documentation while using AI tools to improve efficiency in workflows.

Pay and Benefits

Salary: USD 115,000 - 125,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kPaid Leave

Key Requirements

  • •Demonstrated experience with GRC and compliance automation applications, particularly Vanta.
  • •Working knowledge of security and privacy frameworks including SOC 2, ISO 27001/27701/42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF.
  • •Strong understanding of privacy regulations including HIPAA and GDPR.
  • •Proven experience managing or supporting audits and applying structured project management practices.
  • •Relevant certifications (e.g., CISA, CIPP, ISO 27001 Implementer) and experience in a healthcare or otherwise regulated data environment.
Experience:HealthcareWellnessRegulated data
Skills:CommunicationAttention to detailCross-functional coordinationRisk assessmentProject execution
Certifications:CISACIPPISO 27001 Implementer
Tech Stack:VantaSOC 2ISO 27001ISO 27701ISO 42001HITRUSTHIPAANIST 800-53NIST AI RMFAI toolsGDPRPrivacy-by-designEvidence collectionControl monitoring

Company Brief

Thrive Global
Provides behavior-change technology, content, and programs aimed at reducing stress and improving well-being for individuals and workplaces through science-backed coaching, digital tools, and corporate wellness solutions.
Industry: Wellness & Preventive Health
Company Size: Medium (51 to 250 employees)
Growth: Established Company
Headquarters: New York, United States
Founded: 2016
WebsiteLinkedIn