> Markdown version of [/jobs/ext/2987930-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2987930-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Planet Fitness - **Location:** Hampton, NH, United States (Remote available) - **Experience:** Expert - **Salary:** $90,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Technology, RSA Archer Platform - **Published:** September 18, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3394614505&tx=KJ5959FFI&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's degree in Computer Science, Information Systems, or a related field, coupled with a minimum of 5 years of relevant experience in information security and IT compliance, specifically in areas such as GDPR, CCPA, CPRA, PCI, and SOX * Proven track record in a Governance, Risk, and Compliance (GRC) role, demonstrating a strong understanding of risk assessment methodologies, regulatory requirements, and compliance frameworks * Relevant certifications, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC), are strongly preferred * Extensive experience in developing and managing GDPR compliance programs * Background in managing risk practices within retail, payment, and e-commerce sectors * Experience in risk management within development environments * Familiarity with GRC platforms, including Archer Insight and AuditBoard * Strong knowledge of security frameworks, including NIST and ISO 27001 * Understanding of operational risk assessment methodologies, including mitigation development, monitoring, and reporting * Demonstrates a balanced approach to risk management, understanding the need to align risk strategies with business objectives * Strong analytical skills with the ability to interpret complex regulatory requirements * Extremely detail-oriented, efficient, and organized with exceptional planning, prioritization, organizational, and project management skills * Excellent presentation and communication skills along with the ability to effectively convey complex ideas to both technical and non-technical audiences across all organizational levels * Able to establish and maintain effective, collaborative work relationships with diverse individuals, internally and externally * Creative, progressive, thought leadership with the ability to influence at all levels of the organization * Dedicated learner with a natural curiosity for consistent growth * Exhibits comfort, ease, and flexibility working in an extremely fast-paced ever-changing, deadline-driven environment * Cooperative team player with an upbeat, positive, "can-do" attitude! * Ability to work off-hours and provide on-call support as needed ## Description The Governance, Risk, and Compliance (GRC) Analyst is a strategic and critical role that closely collaborates with the Senior Director, Information Security on expanding and supporting the company's brand-wide governance, risk, and compliance programs by working with IT, various business units, and external vendors. As a GRC Analyst, you will play a crucial role in ensuring the organization adheres to regulatory guidelines, implements effective risk management practices, and maintains robust governance frameworks. This position requires a deep understanding of industry regulations, risk assessment methodologies, and compliance standards. The GRC Analyst role is pivotal in safeguarding the organization's assets, maintaining compliance with regulatory standards, and enhancing overall governance practices., * Collaborates closely with the Senior Director of Information Security on various governance, risk, and compliance initiatives. * Plays a pivotal role in the development and ongoing maintenance of the company's GDPR compliance program. * Interprets and stays informed on pertinent regulations and compliance requirements, including GDPR, CCPA, CPRA, PCI, and SOX. * Conducts comprehensive compliance audits and assessments to evaluate adherence to regulatory standards. * Ensures that policies, procedures, and controls align with established regulatory frameworks. * Performs risk assessments across diverse business units to identify potential threats and vulnerabilities. * Develops risk mitigation strategies and partners with stakeholders to implement effective controls. * Monitors governance processes to ensure accountability and transparency throughout the organization. * Assists in maintaining compliance with the NIST 800-171 security framework. * Prepares regular reports and presentations for management and stakeholders, detailing GRC activities, findings, effectiveness, and recommendations. * Maintains accurate documentation of risk assessments, compliance audits, and governance processes. * Participates in incident response efforts to investigate and mitigate potential security breaches or compliance violations. * Develops training materials and conducts educational sessions on compliance and risk management best practices. * Promotes a culture of compliance and awareness across the organization. ## Related Videos - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How Much FAANG Companies Actually Pay Software Engineers in 2025](https://www.wearedevelopers.com/magazine/230-how-much-faang-companies-actually-pay-software-engineers-in-2025) - [The Glassdoor Dilemma: Unveiling the Truth Behind Company Reviews](https://www.wearedevelopers.com/magazine/273-the-glassdoor-dilemma-unveiling-the-truth-behind-company-reviews) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)