Startups

GRC & Privacy Analyst

Thrive · Remote (United States) · Remote

← All jobs
About Thrive

Thrive is a leading behavior change technology company founded by Arianna Huffington in 2016 with the mission to end the stress and burnout epidemic. Backed by Kleiner Perkins and IVP.

About the role

Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and operationalize compliance programs, manage audit cycles, and help embed privacy-by-design principles across a health-focused, data-sensitive organization. This is an ideal position for someone who thrives at the intersection of security frameworks, privacy regulation, and modern automation tooling.

What they're looking for

  • Demonstrated experience with GRC and compliance automation applications, particularly Vanta
  • Working knowledge of key security and privacy frameworks: SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and NIST AI RMF
  • Strong understanding of privacy regulations, including HIPAA and GDPR
  • Proven experience managing or supporting audits and applying structured project management practices
  • Comfort and fluency with AI tools and a willingness to integrate them into daily workflows
  • Excellent written and verbal communication skills, with strong attention to detail
More about this role

Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and operationalize compliance programs, manage audit cycles, and help embed privacy-by-design principles across a health-focused, data-sensitive organization. This is an ideal position for someone who thrives at the intersection of security frameworks, privacy regulation, and modern automation tooling.

  • Administer and optimize compliance automation platforms such as Vanta , maintaining continuous control monitoring and evidence collection.
  • Lead and support audits across multiple frameworks, coordinating with internal stakeholders and external assessors.
  • Maintain and mature compliance programs mapped to SOC 2, ISO 27001, ISO 27701, ISO 42001, HITRUST, HIPAA, NIST 800-53, and the NIST AI Risk Management Framework (AI RMF) .
  • Interpret and apply privacy standards including HIPAA and GDPR , ensuring data handling practices meet regulatory obligations.
  • Conduct risk assessments, track remediation efforts, and manage evidence and control documentation.
  • Apply project management...

Read the full posting on Thrive's site ↗

Operations & IT

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.