Planet Fitness

GRC Analyst

Planet Fitness$90K — $110K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or a related field with 5+ years of experience in information security and IT compliance
  • Proven experience in a GRC role and understanding of risk assessment methodologies and compliance frameworks
  • Relevant certifications (CISA, CISM, CRISC) preferred
  • Extensive experience developing and managing GDPR compliance programs
  • Strong knowledge of security frameworks, including NIST and ISO 27001

Responsibilities

  • Collaborate with the Senior Director of Information Security on GRC initiatives
  • Develop and maintain the company's GDPR compliance program
  • Conduct compliance audits and assessments according to regulations
  • Perform risk assessments to identify threats and vulnerabilities
  • Prepare reports and presentations on GRC activities for management

Benefits

  • Comprehensive medical, dental, and vision insurance
  • Generous time off program including volunteer time
  • Childcare reimbursement and paid parental leave
  • 401(k) Plan with employer matching
  • Free Black Card membership and learning development programs
Full Job Description
Overview

The Governance, Risk, and Compliance (GRC) Analyst is a strategic and critical role that closely collaborates with the Senior Director, Information Security on expanding and supporting the company's brand-wide governance, risk, and compliance programs by working with IT, various business units, and external vendors. As a GRC Analyst, you will play a crucial role in ensuring the organization adheres to regulatory guidelines, implements effective risk management practices, and maintains robust governance frameworks. This position requires a deep understanding of industry regulations, risk assessment methodologies, and compliance standards. The GRC Analyst role is pivotal in safeguarding the organization's assets, maintaining compliance with regulatory standards, and enhancing overall governance practices.

This role follows a hybrid schedule and requires regular, in-person work at our Boston, MA or Hampton, NH office. Our hybrid model is M/T/W in office and TH/F are optional work-from-home. Candidates must reside within commuting distance of one of these locations. Fully remote work is not available for this role.

Responsibilities

  • Collaborates closely with the Senior Director of Information Security on various governance, risk, and compliance initiatives.
  • Plays a pivotal role in the development and ongoing maintenance of the company's GDPR compliance program.
  • Interprets and stays informed on pertinent regulations and compliance requirements, including GDPR, CCPA, CPRA, PCI, and SOX.
  • Conducts comprehensive compliance audits and assessments to evaluate adherence to regulatory standards.
  • Ensures that policies, procedures, and controls align with established regulatory frameworks.
  • Performs risk assessments across diverse business units to identify potential threats and vulnerabilities.
  • Develops risk mitigation strategies and partners with stakeholders to implement effective controls.
  • Monitors governance processes to ensure accountability and transparency throughout the organization.
  • Assists in maintaining compliance with the NIST 800-171 security framework.
  • Prepares regular reports and presentations for management and stakeholders, detailing GRC activities, findings, effectiveness, and recommendations.
  • Maintains accurate documentation of risk assessments, compliance audits, and governance processes.
  • Participates in incident response efforts to investigate and mitigate potential security breaches or compliance violations.
  • Develops training materials and conducts educational sessions on compliance and risk management best practices.
  • Promotes a culture of compliance and awareness across the organization.


Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or a related field, coupled with a minimum of 5 years of relevant experience in information security and IT compliance, specifically in areas such as GDPR, CCPA, CPRA, PCI, and SOX
  • Proven track record in a Governance, Risk, and Compliance (GRC) role, demonstrating a strong understanding of risk assessment methodologies, regulatory requirements, and compliance frameworks
  • Relevant certifications, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC), are strongly preferred
  • Extensive experience in developing and managing GDPR compliance programs
  • Background in managing risk practices within retail, payment, and e-commerce sectors
  • Experience in risk management within development environments
  • Familiarity with GRC platforms, including Archer Insight and AuditBoard
  • Strong knowledge of security frameworks, including NIST and ISO 27001
  • Understanding of operational risk assessment methodologies, including mitigation development, monitoring, and reporting
  • Demonstrates a balanced approach to risk management, understanding the need to align risk strategies with business objectives
  • Strong analytical skills with the ability to interpret complex regulatory requirements
  • Extremely detail-oriented, efficient, and organized with exceptional planning, prioritization, organizational, and project management skills
  • Excellent presentation and communication skills along with the ability to effectively convey complex ideas to both technical and non-technical audiences across all organizational levels
  • Able to establish and maintain effective, collaborative work relationships with diverse individuals, internally and externally
  • Creative, progressive, thought leadership with the ability to influence at all levels of the organization
  • Dedicated learner with a natural curiosity for consistent growth
  • Exhibits comfort, ease, and flexibility working in an extremely fast-paced ever-changing, deadline-driven environment
  • Cooperative team player with an upbeat, positive, "can-do" attitude!
  • Ability to work off-hours and provide on-call support as needed


Perks

Planet Fitness cares about you and your well-being. We offer a comprehensive benefits package to eligible employees which includes the core medical, dental, vision, life and disability as well as supplemental accident, hospital and critical illness coverage options. In addition, we are proud to offer eligible employees a generous time off program (including volunteer time), childcare reimbursement, paid parental leave, pet care reimbursement, tuition reimbursement, free Black Card membership, learning and development programs and a whole host of engagement activities. We offer a 401(k) Plan with safe harbor employer matching and an employee stock purchase plan. This role is also eligible to participate in an annual corporate bonus incentive program based on company financial and personal performance.

The salary for MA-based and NH-based employees hired into this role will be aligned with the range below. This is a good faith estimate, and the amount of base salary will correspond with a candidate's professional experience, qualifications and internal equity.

Annual Base Salary Range: $90,000-$110,000

This role is also eligible to participate in an annual corporate bonus incentive program based on company financial and personal performance.

Note to Applicants: We have been made aware of an increasing number of hiring fraud schemes across numerous platforms. Planet Fitness never requires advance payments of any kind for computer equipment or any other purpose at the start of employment. Any request for you to provide payment information during the application process is part of a fraud scheme. Further, we recommend that you do not provide sensitive personal information (SSN, DOB, driver's license number) as part of the initial application process.

About Planet Fitness

Planet Fitness is an American franchisor and operator of fitness centers based in Hampton, New Hampshire. The company reports that it has 2,039 clubs, making it one of the largest fitness club franchises by number of members and locations. The company operates through three segments: Franchise, Corporate-owned stores, and Equipment. The Franchise segment includes operations related to the company's franchising business in the United States, Puerto Rico, Canada, the Dominican Republic, Panama, Mexico, and Australia. The Corporate-owned stores segment includes operations with respect to all corporate-owned stores throughout the United States and Canada. The Equipment segment includes the sale of equipment to franchisee-owned stores and third-party vendors.
Learn more about Planet Fitness
Size
1,529 employees
Market Cap
$6.8 billion
Industry
Net Income
-$14.9 million
Founded
1992
5 Year Trend
+9.2%
Revenue
$406.6 million
NASDAQ

Similar Jobs

More Jobs at Planet Fitness

More Information Technology Jobs

Find similar GRC Analyst jobs: