ironquill.tech/board

$ cat jobs/grc-privacy-analyst-thrive-global-f208cebe19e5.json

GRC & Privacy Analyst

thrive global·US·United States·mid
Apply on himalayas → Get AI match score →
Thrive is a leading behavior change technology company founded by Arianna Huffington in 2016 with the mission to end the stress and burnout epidemic. Thrive helps individuals and organizations improve well-being, performance and mental resilience with its AI-powered behavior change technology platform. Thrive’s Microsteps – small, science-backed steps to improve health and productivity – have been adopted by employees at more than 125 organizations in over 140 countries, from frontline and call center workers to executives at multinational companies. If you’re not sure that you’re 100% qualified, but this sounds like a role you would Thrive in – we want you to apply! We believe skills are transferable and passion for our mission goes a long way. Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and operationalize compliance programs, manage audit cycles, and help embed privacy-by-design principles across a health-focused, data-sensitive organization. This is an ideal position for someone who thrives at the intersection of security frameworks, privacy regulation, and modern automation tooling. How You’ll Contribute Administer and optimize compliance automation platforms such as Vanta , maintaining continuous control monitoring and evidence collection. Lead and support audits across multiple frameworks, coordinating with internal stakeholders and external assessors. Maintain and mature compliance programs mapped to SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework (AI RMF) . Interpret and apply privacy standards including HIPAA and GDPR , ensuring data handling practices meet regulatory obligations. Conduct risk assessments, track remediation efforts, and manage evidence and control documentation. Apply project management discipline to compliance initiatives — setti