Best Western

GRC Analyst - Hybrid AZ

Best Western$70K — $95K *
US-AnywhereRemote in Arizona, US
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years in information security compliance, governance, or risk management.
  • Experience with compliance frameworks like PCI DSS, SOX, and GDPR.
  • Possession of certifications such as CISSP, CISA, or CISM preferred.
  • Proficiency in documentation, reporting, and evidence tracking tools.
  • Strong analytical skills and ability to function as a change agent.

Responsibilities

  • Build relationships with internal stakeholders and partners to foster compliance outcomes.
  • Support documentation maintenance for control scoping and audit readiness.
  • Conduct recurring reviews to track control gaps and remediation efforts.
  • Collaborate with audit teams to fulfill evidence requests and ensure accuracy.
  • Review audit findings and partner with control owners to track remediation plans.

Benefits

  • Medical, dental, and vision coverage available from day one.
  • Accrual of vacation and sick leave starts immediately.
  • Paid company holidays and personal holidays offered.
  • 401K plan with company contributions and matches.
  • Tuition reimbursement to support continued education.
Full Job Description

Job Purpose:

Ensures the confidentiality, integrity, and availability of Company data and information technology assets by supporting governance, risk, and compliance activities, including security policy and standards management, risk management, disaster recovery coordination, audit readiness, and regulatory compliance. This role supports PCI DSS, SOX, privacy, and broader cybersecurity compliance activities across the organization.


Key Responsibilities:

  • The ideal candidate will be able to build rapport and credibility with internal stakeholders, business partners, member hotel representatives, and technology teams to support effective governance, risk, and compliance outcomes. Excellent communication and interpersonal skills are required to coordinate evidence requests, explain control expectations, and drive timely follow-through.
  • Demonstrated experience supporting compliance frameworks and control environments such as PCI DSS v4.0.1, NIST, COBIT, ISO 27001, SOX, privacy regulations, and related cybersecurity standards.
  • Coordinate with internal stakeholders and external auditors to maintain current documentation for control scoping, evidence collection, testing support, remediation tracking, and validation of IT and cybersecurity controls.
  • Work with stakeholders to fulfill evidence requests within committed timelines and ensure evidence is complete, accurate, and mapped to applicable control requirements.
  • Conduct recurring control reviews with stakeholders to identify gaps, track remediation progress, and provide actionable advisement to management.
  • Review audit findings, control gaps, and compliance risks; partner with control owners to document remediation plans, track progress, and escalate delays or blockers as appropriate.
  • General understanding of Sarbanes-Oxley (SOX) compliance requirements, IT General Controls, and audit evidence expectations.
  • Thorough knowledge of PCI-related standards and guidance, including PCI DSS v4.0.1, ASV requirements, payment security documentation, and software security requirements where applicable.
  • Thorough understanding of applicable privacy and data protection requirements, including GDPR, the California Consumer Privacy Act (CCPA), and related organizational privacy obligations.
  • Familiarity with a broad range of IT and information security products and technologies such as GRC platforms, central logging systems, file integrity monitoring, vulnerability management, endpoint security, and cloud security tools.
  • Excellent documentation, communication, organization, and follow-through skills, with the ability to coordinate multiple evidence, audit, and remediation activities at the same time.

Preferred Experience and Education:

  • Bachelor's or Master's degree in a computer or information management field or related experience preferred.
  • CISSP, CISA, CISM, CRISC, or equivalent security, audit, risk, or compliance certification preferred.
  • 3-5 years’ experience in an information security compliance, audit, governance, or risk management role with hands-on experience in compliance initiatives including, but not limited to:
    • PCI DSS v4.0.1
    • Software security, secure software lifecycle, or application security compliance requirements where applicable
    • SOX-404 and IT General Controls
    • EU-GDPR, CCPA, and related privacy or data protection requirements
  • Strong analytical and problem-solving skills with the ability to interpret control requirements, identify risk, and function as a change agent.
  • Intermediate to advanced expertise in Excel, PowerPoint, reporting, documentation, evidence tracking, and use of systems or repositories used to manage audit and compliance artifacts.
  • Demonstrated experience working within a team in a fast-paced environment with competing audit, compliance, and operational priorities.
  • Understanding of security metrics, compliance reporting, evidence tracking, and dashboard creation for management review and control-owner visibility.
  • Demonstrated ability to create, maintain, and present security awareness, compliance, or control-owner training content a plus.

Work Location and Schedule

This is a hybrid position, requiring onsite presence Mondays, Wednesdays and Fridays at our Global Operations Center, with the option to work remote on Tuesdays and Thursdays. This hybrid model fosters intentional collaboration, teamwork, connection, and productivity, while still providing flexibility and work life balance. The office address is 20400 N 29th Avenue, Phoenix, Arizona 85027.

This position is not eligible for immigration sponsorship.

Benefits Summary for Full-Time Employees 

· Medical/Dental/Vision available day one

·Vacation/Sick- accruals start day one

·Paid company holidays and personal holidays to celebrate what’s important to you 

·401K - company contribution and match (U.S.)

·Registered Retirement Savings Plan (RRSP) – company contribution and match (Canada)

·Employee discounts/hotel discounts

·Free financial and health wellness programs

·Tuition Reimbursement

About Best Western

Best Western International, Inc. is a hotel chain with over 4,700 hotels in over 100 countries. The chain, with its corporate headquarters in Phoenix, Arizona, operates 17 brands of hotels, each suited to different market segments. Best Western has a long history dating back to 1946 when it was founded by M.K. Guertin. The company has grown to become one of the largest hotel chains in the world. Best Western is known for its commitment to providing quality accommodations and exceptional customer service. The company has won numerous awards for its hotels and its loyalty program, Best Western Rewards.
Learn more about Best Western
Size
4,381 employees
Market Cap
$45.2 million
Industry
Net Income
-$2 billion
5 Year Trend
+5.3%
Revenue
$31.8 billion
NASDAQ

Similar Jobs

More Jobs at Best Western

More Information Technology Jobs

Find similar GRC Analyst - Hybrid AZ jobs: