GRC Analyst

Planet FitnessHampton, NH
$90,000 - $110,000Hybrid

About The Position

The Governance, Risk, and Compliance (GRC) Analyst is a strategic and critical role that closely collaborates with the Senior Director, Information Security on expanding and supporting the company’s brand-wide governance, risk, and compliance programs by working with IT, various business units, and external vendors. As a GRC Analyst, you will play a crucial role in ensuring the organization adheres to regulatory guidelines, implements effective risk management practices, and maintains robust governance frameworks. This position requires a deep understanding of industry regulations, risk assessment methodologies, and compliance standards. The GRC Analyst role is pivotal in safeguarding the organization’s assets, maintaining compliance with regulatory standards, and enhancing overall governance practices. This role follows a hybrid schedule and requires regular, in-person work at our Boston, MA or Hampton, NH office. Our hybrid model is M/T/W in office and TH/F are optional work-from-home. Candidates must reside within commuting distance of one of these locations. Fully remote work is not available for this role.

Requirements

  • Bachelor's degree in Computer Science, Information Systems, or a related field, coupled with a minimum of 5 years of relevant experience in information security and IT compliance, specifically in areas such as GDPR, CCPA, CPRA, PCI, and SOX
  • Proven track record in a Governance, Risk, and Compliance (GRC) role, demonstrating a strong understanding of risk assessment methodologies, regulatory requirements, and compliance frameworks
  • Extensive experience in developing and managing GDPR compliance programs
  • Background in managing risk practices within retail, payment, and e-commerce sectors
  • Experience in risk management within development environments
  • Familiarity with GRC platforms, including Archer Insight and AuditBoard
  • Strong knowledge of security frameworks, including NIST and ISO 27001
  • Understanding of operational risk assessment methodologies, including mitigation development, monitoring, and reporting
  • Demonstrates a balanced approach to risk management, understanding the need to align risk strategies with business objectives
  • Strong analytical skills with the ability to interpret complex regulatory requirements
  • Extremely detail-oriented, efficient, and organized with exceptional planning, prioritization, organizational, and project management skills
  • Excellent presentation and communication skills along with the ability to effectively convey complex ideas to both technical and non-technical audiences across all organizational levels
  • Able to establish and maintain effective, collaborative work relationships with diverse individuals, internally and externally
  • Creative, progressive, thought leadership with the ability to influence at all levels of the organization
  • Dedicated learner with a natural curiosity for consistent growth
  • Exhibits comfort, ease, and flexibility working in an extremely fast-paced ever-changing, deadline-driven environment
  • Cooperative team player with an upbeat, positive, “can-do” attitude!
  • Ability to work off-hours and provide on-call support as needed

Nice To Haves

  • Relevant certifications, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC), are strongly preferred

Responsibilities

  • Collaborates closely with the Senior Director of Information Security on various governance, risk, and compliance initiatives.
  • Plays a pivotal role in the development and ongoing maintenance of the company’s GDPR compliance program.
  • Interprets and stays informed on pertinent regulations and compliance requirements, including GDPR, CCPA, CPRA, PCI, and SOX.
  • Conducts comprehensive compliance audits and assessments to evaluate adherence to regulatory standards.
  • Ensures that policies, procedures, and controls align with established regulatory frameworks.
  • Performs risk assessments across diverse business units to identify potential threats and vulnerabilities.
  • Develops risk mitigation strategies and partners with stakeholders to implement effective controls.
  • Monitors governance processes to ensure accountability and transparency throughout the organization.
  • Assists in maintaining compliance with the NIST 800-171 security framework.
  • Prepares regular reports and presentations for management and stakeholders, detailing GRC activities, findings, effectiveness, and recommendations.
  • Maintains accurate documentation of risk assessments, compliance audits, and governance processes.
  • Participates in incident response efforts to investigate and mitigate potential security breaches or compliance violations.
  • Develops training materials and conducts educational sessions on compliance and risk management best practices.
  • Promotes a culture of compliance and awareness across the organization.

Benefits

  • medical
  • dental
  • vision
  • life
  • disability
  • supplemental accident coverage
  • supplemental hospital coverage
  • supplemental critical illness coverage
  • generous time off program
  • volunteer time
  • childcare reimbursement
  • paid parental leave
  • pet care reimbursement
  • tuition reimbursement
  • free Black Card membership
  • learning and development programs
  • engagement activities
  • 401(k) Plan with safe harbor employer matching
  • employee stock purchase plan
  • annual corporate bonus incentive program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service