Thrive Global Logo

Thrive Global

GRC & Privacy Analyst

Posted One Month Ago
Remote
Hiring Remotely in United States
115K-125K Annually
Entry level
Remote
Hiring Remotely in United States
115K-125K Annually
Entry level
The GRC and Privacy Analyst will administer compliance automation, maintain continuous control monitoring, support audits, and manage security and privacy programs. Responsibilities include mapping controls to SOC 2, ISO, HIPAA, HITRUST, NIST, and AI risk frameworks; conducting risk assessments; tracking remediation; documenting evidence; applying privacy regulations such as GDPR; coordinating cross-functional compliance projects; and using AI tools to improve compliance workflows.
The summary above was generated by AI

Founded by Arianna Huffington in 2016, Thrive Global is a leading behavior change technology company with the mission to improve productivity and health outcomes – one Microstep at a time. Thrive helps individuals and organizations improve well-being, performance and mental resilience with its AI-powered behavior change technology platform. Thrive’s Microsteps – small, science-backed steps to improve health and productivity – have been adopted by employees at more than 230 organizations in over 160 countries, from frontline and call center workers to executives at multinational companies. For more information, visit www.thriveglobal.com.


Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and operationalize compliance programs, manage audit cycles, and help embed privacy-by-design principles across a health-focused, data-sensitive organization. This is an ideal position for someone who thrives at the intersection of security frameworks, privacy regulation, and modern automation tooling.

How You’ll Contribute
  • Administer and optimize compliance automation platforms such as Vanta, maintaining continuous control monitoring and evidence collection.
  • Lead and support audits across multiple frameworks, coordinating with internal stakeholders and external assessors.
  • Maintain and mature compliance programs mapped to SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework (AI RMF).
  • Interpret and apply privacy standards including HIPAA and GDPR, ensuring data handling practices meet regulatory obligations.
  • Conduct risk assessments, track remediation efforts, and manage evidence and control documentation.
  • Apply project management discipline to compliance initiatives — setting timelines, coordinating cross-functional owners, and driving deliverables to completion.
  • Leverage AI tools to improve efficiency in evidence review, policy drafting, risk analysis, and reporting workflows.
Qualifications & Skills
  • Demonstrated experience with GRC and compliance automation applications, particularly Vanta.
  • Working knowledge of key security and privacy frameworks: SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF.
  • Strong understanding of privacy regulations, including HIPAA and GDPR.
  • Proven experience managing or supporting audits and applying structured project management practices.
  • Comfort and fluency with AI tools and a willingness to integrate them into daily workflows.
  • Excellent written and verbal communication skills, with strong attention to detail.
  • Relevant certifications (e.g., CISA, CIPP, ISO 27001 Implementer).
  • Experience in a healthcare, wellness, or otherwise regulated data environment.
  • Familiarity with AI governance and emerging AI compliance requirements.


✨ What We Offer:

  • 🌍 Mission-Driven Impact: Be part of a company that’s truly making a difference in people’s lives around the world.
  • 🚀 Career Growth: Develop within the company and help shape our growth strategy.
  • 💙 Human-Centric Culture: Thrive in a supportive environment with a range of wellness perks and benefits.
  • 💰 Competitive Compensation: Enjoy a comprehensive and rewarding total compensation package.
  • 🩺 Health & Financial Benefits: Medical, dental, and vision coverage plus a 401(k) program with company match.
  • 🌴 Time to Recharge: Generous paid time-off programs designed to help you rest, reset, and recharge — including Thrive Time, a benefit unique to Thrive that gives employees additional paid time off after major projects or intense periods of work to truly recharge and recover.


Compensation:

Total target compensation for this role will be $115,000 - $125,000.

  • Please note: We provide a competitive mix of salary, performance bonus, and equity. The final offer amount will depend on factors like experience, expertise, and may differ from the range above. This range also excludes additional benefits, such as 401(k), and medical, dental, or vision insurance.

Thrive is deeply committed to creating a safe and welcoming work environment free of discrimination and harassment so that all employees can bring their whole selves to work.


Thrive is proud to ensure equal employment opportunity (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, disability, genetics, gender, gender identity, gender expression, sexual orientation, age, marital status, family or parental status, veteran status, or any other characteristic protected by applicable federal, state or local law.


Thrive is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. Please inform Thrive’s Recruiting team if you need any assistance completing any forms or to otherwise participate in the application process.

Similar Jobs

3 Minutes Ago
Remote or Hybrid
United States
66K-89K Annually
Junior
66K-89K Annually
Junior
Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Performs cybersecurity consulting engagements including vulnerability assessments, social engineering exercises, penetration testing, risk analysis, remediation recommendations, reporting, and client presentations. Coordinates engagement activities, monitors scope and budgets, documents findings, supports service development and sales opportunities, and mentors junior consultants. The role assesses networks, applications, cloud configurations, infrastructure, and employee awareness while maintaining current cybersecurity knowledge and pursuing relevant certifications.
Top Skills: Burp SuiteCloud ComputingNessus ProfessionalNetwork SecurityNipper StudioNmapOsintPhishing SimulationsSaaSTcp/IpTenable Vulnerability ManagementVirtualizationVulnerability AssessmentWireshark
2 Hours Ago
Remote or Hybrid
USA
160K-220K Annually
Senior level
160K-220K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Leads CrowdStrike’s Operational Services portfolio across active and pipeline deployments. Oversees delivery metrics, customer engagements, scoping, forecasting, contracts, resource allocation, and continuous improvement. Partners with Sales, Legal, Product, Engineering, and go-to-market teams while building and mentoring a high-performing services organization. Supports cybersecurity platform engagements and ensures consistent, high-quality customer outcomes.
Top Skills: Ai TechnologiesCrowdstrike FalconEdrGainsightPortfolio Management ToolsProject Management ToolsSalesforceSIEMSoar
2 Hours Ago
Remote or Hybrid
CA, USA
100K-145K Annually
Senior level
100K-145K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Manage data center financial operations through budgeting, variance analysis, financial modeling, month-end close reporting, cost-saving initiatives, and strategic analysis. The role requires data warehousing and modeling expertise, hardware and asset-management understanding, process improvement, automation, and effective communication with leadership and cross-functional partners.
Top Skills: Artificial IntelligenceData ModelingData WarehousingExcelMicrosoft Powerpoint

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account