Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior GRC Analyst, Privacy

Benevity

Meet Benevity

Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We're also one of the first B Corporations in Canada, meaning we're as committed to purpose as we are to profits. We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more!

Sr. GRC Analyst, Privacy

Benevity is seeking a Sr. GRC Analyst, Privacy to anchor and advance our data protection program across a complex, multi-jurisdictional regulatory landscape. In this role, you will own the design, operationalization, and continuous maturity of Benevity's privacy compliance program, spanning GDPR, UK-GDPR, CPRA, PIPEDA, CASL, and emerging global frameworks. You will build the foundational infrastructure that keeps Benevity accountable to its regulatory obligations: Records of Processing Activities, Data Subject Access Request workflows, Data Protection Impact Assessments, and subprocessor governance, ensuring the program is not only defensible to regulators but scalable as Benevity grows.

As a trusted privacy advisor embedded across cross-functional teams, you will work closely with Legal, Security, Engineering, Product, and Data Governance to embed Privacy by Design into the business. You will support the DPO operational function, partner on Data Processing Agreement reviews, and translate complex privacy requirements into practical, business-aligned controls. Your work will directly protect Benevity's clients, employees, and the communities they serve, and ensure that trust remains a core competitive advantage.

What You'll Do

Privacy Program & Governance

  • Own and maintain Benevity's Records of Processing Activities (ROPA) under both controller and processor regimes, ensuring compliance with GDPR Article 30 and equivalent requirements across applicable jurisdictions.
  • Develop and maintain privacy policies, notices, standards, and control frameworks aligned with GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, CASL, and emerging global laws (AU Privacy Act, India DPDP, Swiss FADP, and others).
  • Support privacy policy approval, exception management, and attestation processes, actively seeking opportunities for process improvement and automation.

Data Subject Rights & DSAR

  • Build and manage DSAR intake, triage, and response workflows in compliance with statutory deadlines (30 days under GDPR; 45 days under CPRA), including coordination with business and legal stakeholders.
  • Maintain and refresh the subprocessor listing in alignment with client Data Processing Agreement commitments and GDPR Article 28 obligations.

Data Protection Impact & Risk

  • Design, operationalize, and continuously improve the Data Protection Impact Assessment (DPIA) process; embed DPIA requirements into product, data, and business initiative workflows.
  • Support the DPO operational function, including regulatory correspondence readiness, breach notification preparedness, and supervisory authority interface support in coordination with Legal.
  • Partner with Security, Engineering, Product, Legal, and Data Governance teams to embed privacy by design and by default into key business initiatives.

Regulatory Compliance & Monitoring

  • Review and support the negotiation of Data Processing Agreements and data transfer mechanisms (SCCs, UK IDTAs) in collaboration with Legal.
  • Monitor the global privacy regulatory landscape and assess the impact of new and evolving requirements on Benevity's operations and client commitments.
  • Support multi-entity privacy obligations across Benevity's partner ecosystem, including jurisdiction-specific compliance requirements and data processing documentation.

Tooling & Operational Delivery

  • Maintain and enhance privacy workflows in GRC platforms (e.g., OneTrust Privacy module) to automate and streamline compliance operations at scale.
  • Deliver executive-ready privacy reports, risk insights, and dashboards to inform leadership decision-making.
  • Leverage AI tools and automation as a force multiplier, accelerating DSAR triage, regulatory horizon scanning, policy drafting, and evidence workflows to scale program output without scaling headcount.

Advisory & Awareness

  • Design and deliver privacy awareness and training programs to build a culture of data protection across Benevity.
  • Serve as a cross-functional privacy advisor, partnering with teams across the organization to embed privacy requirements into products, services, and operational decisions.
What You'll Bring
  • 5+ years of experience in privacy, data protection, GRC, or a closely related field, ideally within a SaaS or high-growth technology environment.
  • Deep, practical knowledge of global privacy frameworks, including GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, and CASL, with working familiarity of emerging regimes (India DPDP, Swiss FADP, AU Privacy Act reforms).
  • Hands-on experience building and maintaining ROPAs under both controller and processor regimes, managing DSAR workflows, conducting DPIAs, and maintaining subprocessor inventories.
  • Experience supporting or operating within a DPO function, including regulatory interface and breach notification processes.
  • Proven ability to review and support the negotiation of Data Processing Agreements and data transfer mechanisms in collaboration with Legal.
  • Hands-on experience with privacy or GRC tooling (e.g., OneTrust Privacy module, Hyperproof, or equivalent) to operationalize compliance workflows at scale.
  • Ability to communicate complex privacy and regulatory concepts clearly to technical, legal, and business audiences.
  • A demonstrated interest and track record in leveraging AI and automation as a force multiplier, streamlining privacy operations, accelerating routine workflows, and expanding program capacity without proportional headcount growth.
  • Certifications such as CIPP/E, CIPP/US, or CIPM are highly valued; CIPT, CISM, or CRISC are also welcomed.
Discover Your Purpose at Work

We're not employees, we're Benevity-ites. From all locations, backgrounds and walks of life, who deserve more …

Innovative work. Growth opportunities. Caring co-workers. And a chance to do work that fills us with a sense of purpose.

If the idea of working on tech that helps people do good in the world lights you up... If you want a career where you're valued for who you are and challenged to see who you can become …

It's time to join Benevity. We're so excited to meet you.

Where We Work

At Benevity, we embrace a flexible hybrid approach to where we work that empowers our people in a way that supports great work, strong relationships, and personal well-being. For those located near one of our offices, while there's no set requirement for in-office time, we do value the moments when coming together in person helps us build connection and collaboration. Whether it's for onboarding, project work, or a chance to align and bond as a team, we trust our people to make thoughtful decisions about when showing up in person matters most.

Join a Company Where DEIB Isn't a Buzzword

Diversity, equity, inclusion and belonging are part of Benevity's DNA. You'll see the impact of our massive investment in DEIB daily — from our well-supported employee resources groups to the exceptional diversity on our leadership and tech teams.

We know that diverse backgrounds, experiences, skills and passions are what move our business and our people forward, so we're committed to creating a culture of belonging with equal opportunities for everyone to shine.

That starts with a fair and accessible hiring process. If you want to feel seen, heard and celebrated, you belong at Benevity.

Candidates with disabilities who may require accommodations throughout the hiring or assessment process are encouraged to reach out to View email address on click.appcast.io.

Vacancy posted 15 hours ago
Similar jobs that could be interesting for youBased on the Senior GRC Analyst, Privacy in United States vacancy
  • $70 - $80 per hour

     ...professionals with meaningful career opportunities. We are seeking a GRC Analyst to support our client's team. Created Date: April 15, 2026...  ...be subject to criminal penalties and civil liability. Privacy: Information collected and processed as part of your... 
    Senior
    Hourly pay
    Contract work
    Temporary work
    Local area
    Monday to Friday
    Shift work
    Day shift

    Eastridge Workforce Solutions

    Austin, TX
    1 day ago
  • $130k - $160k

     ...Employment Type Full time Department Engineering Team & Role As a Senior GRC Analyst at Benepass, you will help operate and mature the governance...  .... Experience supporting HIPAA, PCI DSS, GDPR, or other privacy and security frameworks. Experience at a startup or high-... 
    Senior
    Full time
    Work at office
    Remote work
    Work from home
    Flexible hours

    Benepass

    New York, NY
    5 days ago
  • $161.6k - $202k

     ...that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security...  ...Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams. What You'll Own * Support HITRUST,... 
    Senior
    Work from home
    Flexible hours

    Headway - Design & Development

    Seattle, WA
    1 day ago
  • $135k - $190k

     ...in an office some or all of the time. About your role As a Senior GRC Analyst, you are responsible for supporting the organization's governance...  ...base up-to-date Support sales teams with open security and privacy questions Review incoming security and privacy addendums to... 
    Senior
    Full time
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours

    Juniper Square

    New York, NY
    2 days ago
  •  ...conduct independent control assessments within the Cybersecurity GRC function. The primary focus will be on the design,...  ...with current and proposed security changes impacting regulatory, privacy, and security industry best practice guidance, leveraging technological... 
    Senior
    Work at office
    Local area

    ShiftCode Analytics

    Tulsa, OK
    1 day ago
  • $193.8k - $228k

    Senior GRC Analyst II job at Carta. San Francisco, CA. The Problems You'll Solve As a Senior GRC Analyst II , you’ll work to assess regulatory...  ...for employment authorization. For information on our data privacy policies, see Privacy, CA Candidate Privacy, and Brazil... 
    Senior
    Full time

    Itlearn360

    San Francisco, CA
    1 day ago
  • $88k - $121k

    About the Role Flagship's GRC program has matured from build to operate. We have a functioning GRC system of record in Jira, active...  ...deadlines Manage sub‑processor and DPA tracking for portfolio company privacy programs, including gap identification and remediation follow‑up... 
    Senior

    Flagship Pioneering

    Cambridge, MA
    9 hours ago
  • $84.5k - $109.85k

     ...Senior Consultant - Governance, Risk and Compliance (GRC) Analyst Job Category: Professional Requisition Number: SENIO001234 Posted: June 4, 2026 Full-Time...  ...) Analyst within NYSTEC's Cybersecurity and Data Privacy practice area, you will support governance, compliance... 
    Senior
    Full time
    Local area
    Visa sponsorship
    Shift work

    NYSTEC

    Albany, NY
    1 day ago
  • Sun Life Financial is seeking a Senior Compliance Analyst to oversee privacy program and regulatory compliance at its Wellesley location. This role involves conducting privacy impact assessments, investigating incidents, and supporting compliance initiatives across multiple... 
    Senior

    Sun Life Financial

    Wellesley, MA
    4 days ago
  • $145.19k - $203.26k

     ...include but are not limited to: Use automation for various GRC tasks including scorecard creation, roadmap updates, and...  ...cybersecurity standards including NIST, ISO 27001, ISO 28000, SOC, and privacy frameworks ~ Experience with 3rd party information security... 
    Senior
    Permanent employment
    Temporary work
    Local area

    Blue Origin

    Seattle, WA
    2 days ago
  • $75.1k - $126.33k

    Allstate Insurance Company is seeking an experienced Senior Consultant for the Enterprise Business Conduct (EBC) Risk Management team...  ...candidates will have at least 3 years of experience in compliance, privacy risk management, or internal audit, with strong communication... 
    Senior

    Allstate Insurance Company

    Northbrook, IL
    2 days ago
  •  ...dynamic consulting firm in the United States seeks a Senior Associate for its Cyber Security & Data Privacy (CSDP) group. This role involves leading client...  ...knowledge of compliance frameworks. Experience with GRC tools is also essential. The firm values collaboration... 
    Senior

    Riveron Corp

    New York, NY
    2 days ago
  •  ...About the job Senior Privacy & Compliance Manager (Fractional | Remote) PLEASE READ THE FULL JD BEFORE APPLYING. INCOMPLETE APPLICATIONS MAY NOT BE CONSIDERED. Senior Privacy & Compliance Manager (Fractional | Remote) Location: Remote Working Pattern... 
    Senior
    Contract work
    Part time
    Remote work
    Flexible hours

    Rosie’s People Inc.

    United States
    15 hours ago
  •  ...skilled and proactive Cybersecurity GRC (Governance, Risk, and Compliance) Analyst to join our dynamic cybersecurity...  ...reports, and audit findings for senior management and other stakeholders....  ...security, IT governance, and data privacy. Knowledge of threat intelligence... 
    Senior
    Work experience placement

    6AM City, LLC

    Wisconsin
    4 days ago
  • Mmc,-LLC- is seeking a Data Privacy Manager to lead our comprehensive privacy strategy across all operations. You will be responsible...  ...safeguarding of personal information for our clients and employees. This senior leadership role requires collaboration with various departments... 
    Senior

    Mmc,-LLC-

    Washington DC
    3 days ago
  • $118.38k - $141.13k

    The University of Southern California is seeking a Privacy Specialist to oversee its privacy compliance program. This role requires a Bachelor's degree and at least 5 years of experience, focusing on compliance with federal and state privacy laws. The successful candidate... 
    Senior

    University of Southern California

    Glendale, CA
    3 days ago
  • Elliot Hospital - Compliance and Privacy Senior Manager Position Summary - 40 hr/wk Days, hours can be flexible. Required on site presence located in Manchester NH. About the Job: The Compliance and Privacy Senior Manager, under the direction of the Chief Compliance Officer... 
    Senior
    Full time
    Part time
    Local area
    Flexible hours

    Nneshrm

    Manchester, NH
    2 days ago
  • A leading financial services firm in Washington is seeking a Compliance Consultant to enhance and maintain its privacy program. This role involves managing regulatory compliance, conducting assessments, and ensuring adherence to privacy laws like GLBA and CCPA. With over... 
    Senior
    Flexible hours

    Symetra Financial Corporation

    Bellevue, WA
    2 days ago
  • $90k - $135k

     ...at your best. Together we win! THE OPPORTUNITY The Senior GRC Information Security Analyst role will be part of the Information Security...  ...Information Security Incident Response team during cyber/privacy incidents. Support internal and external audits by providing... 
    Senior
    Local area
    Immediate start
    Flexible hours

    Banc of California

    Santa Ana, CA
    1 day ago
  •  ...like to modernise an enterprise privacy program and not just keep the...  ...an Advanced Risk & Compliance Analyst – Privacy to join the Governance, Risk & Compliance (GRC) team. This role is ideal for someone...  .... To be a good fit for the Senior Privacy & Compliance Specialist... 
    Senior
    Contract work
    For subcontractor
    Remote work
    Worldwide

    Sowelo Consulting

    United States
    3 days ago
  • Continental General in Austin, TX is seeking a Compliance Specialist to support compliance efforts focused on privacy issues and new products. You will help manage regulatory obligations and conduct legal research within a collaborative environment. The ideal candidate... 
    Senior

    Continental General

    Austin, TX
    1 day ago
  •  ...Privacy Senior Regulatory Compliance Analyst The Privacy Senior Regulatory Compliance Analyst is responsible for leading and driving complex regulatory and compliance initiatives with a specialized emphasis on privacy laws and data protection regulations. This role... 
    Senior
    Work experience placement
    Work at office

    E-Solutions

    Oakland, CA
    3 days ago
  •  ...Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8... 
    Senior
    Flexible hours

    Crunchyroll

    Dallas, TX
    16 hours ago
  •  ...Director/Senior Director Of Compliance, Privacy, And Safety Our mission: To make independence a gift for all. Anne Carlsen Center (Anne Carlsen) is a non-profit organization which has been providing supports and services for 80 years to individuals in North Dakota... 
    Senior
    Full time
    Contract work
    Local area
    Monday to Friday
    Flexible hours
    Shift work

    Anne Carlsen Center

    Grand Forks, ND
    4 days ago
  • $95k - $105k

     ...Subsplash is looking for a GRC Analyst to join its Remote team in the United States. In this role, you'll be a strategic lead in advancing security and risk operations by identifying gaps and implementing best practices. With a salary range of $95,000-$105,000/yr, you'... 
    Senior
    Remote work

    Subsplash

    New York, NY
    2 days ago
  •  ...A cutting-edge technology firm in the United States is seeking a Senior GRC Analyst. The role requires 5+ years of experience in risk management, compliance, and governance. You will support the organization's GRC program, maintain security compliance frameworks, and... 
    Senior
    Remote work

    Juniper Square

    New York, NY
    2 days ago
  • $130k - $160k

     ...Alumni Ventures is seeking a Senior GRC Analyst to operate and mature governance, risk, compliance, and audit readiness programs. This role involves collaboration across departments to ensure effective compliance practices. Ideal candidates have 5+ years in GRC and experience... 
    Senior
    Remote work
    Flexible hours

    Benepass

    New York, NY
    1 day ago
  • $80k - $95k

    Bumble Inc. in Austin, Texas, is looking for a Senior Compliance Specialist to handle complex, high-risk cases related to data privacy and compliance operations. You will work with Legal and Privacy teams to uphold regulatory standards and ensure member safety. Ideal candidates... 
    Senior

    Bumble Inc.

    Austin, TX
    1 day ago
  •  ...GRC Analyst Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools, Upwind uses runtime data proactively... 
    Senior
    Remote work

    Upwind

    United States
    1 day ago
  • $142.5k - $237.5k

     ...TransUnion's Job Applicant Privacy Notice Personal Information We Collect Your Privacy Choices Team Overview The Senior Privacy Compliance Advisor serves as a trusted compliance and privacy advisor to the Marketing Solutions business, with a strong emphasis... 
    Senior
    Full time
    Fixed term contract
    Work experience placement
    Work at office
    Flexible hours
    2 days per week

    TransUnion

    Boca Raton, FL
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior GRC Analyst, Privacy. Be the first to apply!