GRC & Privacy Analyst

Thrive Global
$115,000 - $125,000

About The Position

Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and operationalize compliance programs, manage audit cycles, and help embed privacy-by-design principles across a health-focused, data-sensitive organization. This is an ideal position for someone who thrives at the intersection of security frameworks, privacy regulation, and modern automation tooling.

Requirements

  • Demonstrated experience with GRC and compliance automation applications, particularly Vanta.
  • Working knowledge of key security and privacy frameworks: SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF.
  • Strong understanding of privacy regulations, including HIPAA and GDPR.
  • Proven experience managing or supporting audits and applying structured project management practices.
  • Comfort and fluency with AI tools and a willingness to integrate them into daily workflows.
  • Excellent written and verbal communication skills, with strong attention to detail.
  • Relevant certifications (e.g., CISA, CIPP, ISO 27001 Implementer).
  • Experience in a healthcare, wellness, or otherwise regulated data environment.
  • Familiarity with AI governance and emerging AI compliance requirements.

Responsibilities

  • Administer and optimize compliance automation platforms such as Vanta, maintaining continuous control monitoring and evidence collection.
  • Lead and support audits across multiple frameworks, coordinating with internal stakeholders and external assessors.
  • Maintain and mature compliance programs mapped to SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework (AI RMF).
  • Interpret and apply privacy standards including HIPAA and GDPR, ensuring data handling practices meet regulatory obligations.
  • Conduct risk assessments, track remediation efforts, and manage evidence and control documentation.
  • Apply project management discipline to compliance initiatives — setting timelines, coordinating cross-functional owners, and driving deliverables to completion.
  • Leverage AI tools to improve efficiency in evidence review, policy drafting, risk analysis, and reporting workflows.

Benefits

  • Medical coverage
  • Dental coverage
  • Vision coverage
  • 401(k) program with company match
  • Generous paid time-off programs
  • Thrive Time (additional paid time off after major projects or intense periods of work)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service