GRC Analyst

Planet Fitness - Boston, MA

Hiring: GRC Analyst Company: Planet Fitness Location: Boston, MA Job Posted Time: 2026-09-16 21:16:31 Employment Type: Remote Target Skills & Keywords : GDPR, Project Management, Risk Management About the job Experience: •5 years of relevant experience in information security and IT compliance, specifically in areas such as GDPR, CCPA, CPRA, PCI, and SOX Required Skills: •Collaborates closely with the Senior Director of Information Security on various governance, risk, and compliance initiatives •Plays a pivotal role in the development and ongoing maintenance of the company’s GDPR compliance program •Interprets and stays informed on pertinent regulations and compliance requirements, including GDPR, CCPA, CPRA, PCI, and SOX •Conducts comprehensive compliance audits and assessments to evaluate adherence to regulatory standards •Ensures that policies, procedures, and controls align with established regulatory frameworks •Performs risk assessments across diverse business units to identify potential threats and vulnerabilities •Develops risk mitigation strategies and partners with stakeholders to implement effective controls •Monitors governance processes to ensure accountability and transparency throughout the organization Qualifications: •Bachelor's degree in Computer Science, Information Systems, or a related field, coupled with a minimum of 5 years of relevant experience in information security and IT compliance, specifically in areas such as GDPR, CCPA, CPRA, PCI, and SOX •Proven track record in a Governance, Risk, and Compliance (GRC) role, demonstrating a strong understanding of risk assessment methodologies, regulatory requirements, and compliance frameworks •Relevant certifications, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC), are strongly preferred •Extensive experience in developing and managing GDPR compliance programs •Background in managing risk practices within retail, payment, and e-commerce sectors •Operational familiarity with GRC platforms, including Archer Insight and AuditBoard •Strong knowledge of security frameworks, including NIST and ISO 27001 •Understanding of operational risk assessment methodologies, including mitigation development, monitoring, and reporting •Demonstrates a balanced approach to risk management, understanding the need to align risk strategies with business objectives •Strong analytical skills with the ability to interpret complex regulatory requirements Compensation: •$90,000 - $110,000 / year •Competitive benefits and rewards package Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!