GRC Analyst

Spectraforce
Seattle, WA, United States
20 days ago
Apply on leoforce.us
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Data Mapping Privacy Controls Information Technology

Job description

Plays a critical role in advancing the company’s privacy program to ensure compliance with applicable privacy laws, company policies and standards, and industry best practices. Leads privacy projects, working independently and collaborating closely with business and IT teams, escalating when situations require senior input to ensure proper controls are identified and risks escalated to support compliance with privacy laws.

Data Analyst + Program Management Responsibility. Supporting the privacy assessment process at Client

  • Lead end-to-end privacy impact assessments, including assessments of first- and third-party applications, systems and business processes, and identification of privacy and technological considerations and gaps based on applicable laws, regulations and business requirements
  • Evaluate complex privacy risks and document recommended mitigation strategies for partner teams to execute. Collaborate with cross-functional teams to implement effective privacy controls
  • Collaborate with Legal, IT, and Cybersecurity teams to ensure privacy controls are aligned and reflect ongoing changes to Client’s risk and compliance posture
  • Identify opportunities for operational improvements in privacy assessment processes, data mapping tools, and documentation, escalating implementation decisions to leadership as appropriate
  • Assist with audit or maturity assessment initiatives
  • Respond to and fulfill complex data subject access requests (DSARs)
  • Maintain and supplement data mapping and governance documentation
  • Support rollout of privacy-enhancing technologies and tools
  • Identify and escalate potential privacy risks or threats and recommend mitigation strategies
  • Lead incident response processes for privacy-related events

Requirements

  • Experience: 2+ years of privacy or related experienc
  • Certifications: IAPP certification (CIPP/US, CIPM, or CIPT) strongly preferred
  • Strong working knowledge of Canadian (PIPEDA) and U.S. state-level privacy regulations (CCPA, OCPA, Colorado AI Act, Illinois BIPA) and sectoral privacy laws (e.g. CASL, FCRA, HIPAA, CAN-SPAM, COPPA).
  • Experience with privacy management platforms (e.g. OneTrust, TrustArc).
  • Strong attention to detail, quality and consistency in both written and verbal communications

Education: Bachelor’s degree or master’s in information technology, Computer Science, Cybersecurity or related experience required.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on leoforce.us
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:39 min

Harnessing data mapping tools to identify unmapped opportunities

Laura Möller Laura Möller +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:13 min

Requirements and licensing plans for GitHub Copilot

lgonta lgonta +1 · World Congress 2024

2:14 min

Securing analysis platforms via network access controls

Jennifer Reif · LIVE

3:57 min

Mapping abstract data attributes into geometric visual configurations

Johanna Schmidt · LIVE

2:11 min

Addressing security audits and regional data compliance legislation

Videos

See all

Related articles

See all