GRC & Privacy Analyst

Thrive Global

$115K — $125K *
US-AnywhereRemote in United States
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Experience with GRC and compliance automation, especially Vanta.
  • Knowledge of security and privacy frameworks like SOC 2, ISO 27001, and NIST.
  • Understanding of HIPAA and GDPR regulations.
  • Experience in managing audits and applying project management practices.
  • Fluency with AI tools in compliance contexts.
  • Strong communication skills and attention to detail.
  • Relevant certifications such as CISA or CIPP.

Responsibilities

  • Administer and optimize compliance automation platforms like Vanta.
  • Lead and support audits across multiple frameworks.
  • Maintain compliance programs linked to various security standards.
  • Interpret privacy standards ensuring adherence to regulations.
  • Conduct risk assessments and manage evidence documentation.
  • Apply project management discipline to compliance initiatives.
  • Leverage AI tools for improving compliance workflows.

Benefits

  • Mission-driven impact with a focus on improving lives globally.
  • Opportunities for career growth and shaping company strategy.
  • Supportive, human-centric culture with wellness benefits.
  • Comprehensive health and financial benefits including medical and 401(k).
  • Generous paid time-off including unique 'Thrive Time' for recovery.
Full Job Description
Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and operationalize compliance programs, manage audit cycles, and help embed privacy-by-design principles across a health-focused, data-sensitive organization. This is an ideal position for someone who thrives at the intersection of security frameworks, privacy regulation, and modern automation tooling.

How You'll Contribute

  • Administer and optimize compliance automation platforms such as Vanta, maintaining continuous control monitoring and evidence collection.
  • Lead and support audits across multiple frameworks, coordinating with internal stakeholders and external assessors.
  • Maintain and mature compliance programs mapped to SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework (AI RMF).
  • Interpret and apply privacy standards including HIPAA and GDPR, ensuring data handling practices meet regulatory obligations.
  • Conduct risk assessments, track remediation efforts, and manage evidence and control documentation.
  • Apply project management discipline to compliance initiatives - setting timelines, coordinating cross-functional owners, and driving deliverables to completion.
  • Leverage AI tools to improve efficiency in evidence review, policy drafting, risk analysis, and reporting workflows.

Qualifications & Skills

  • Demonstrated experience with GRC and compliance automation applications, particularly Vanta.
  • Working knowledge of key security and privacy frameworks: SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF.
  • Strong understanding of privacy regulations, including HIPAA and GDPR.
  • Proven experience managing or supporting audits and applying structured project management practices.
  • Comfort and fluency with AI tools and a willingness to integrate them into daily workflows.
  • Excellent written and verbal communication skills, with strong attention to detail.
  • Relevant certifications (e.g., CISA, CIPP, ISO 27001 Implementer).
  • Experience in a healthcare, wellness, or otherwise regulated data environment.
  • Familiarity with AI governance and emerging AI compliance requirements.


What We Offer:

  • Mission-Driven Impact: Be part of a company that's truly making a difference in people's lives around the world.
  • Career Growth: Develop within the company and help shape our growth strategy.
  • Human-Centric Culture: Thrive in a supportive environment with a range of wellness perks and benefits.
  • Competitive Compensation: Enjoy a comprehensive and rewarding total compensation package.
  • Health & Financial Benefits: Medical, dental, and vision coverage plus a 401(k) program with company match.
  • Time to Recharge: Generous paid time-off programs designed to help you rest, reset, and recharge - including Thrive Time, a benefit unique to Thrive that gives employees additional paid time off after major projects or intense periods of work to truly recharge and recover.


Compensation:

Total target compensation for this role will be $115,000 - $125,000.

  • Please note: We provide a competitive mix of salary, performance bonus, and equity. The final offer amount will depend on factors like experience, expertise, and may differ from the range above. This range also excludes additional benefits, such as 401(k), and medical, dental, or vision insurance.

Similar Jobs

More Jobs at Thrive Global

More Healthcare Jobs

Find similar GRC & Privacy Analyst jobs: