Iterable - Senior GRC Analyst
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• Strong experience with GDPR and global privacy operations in a SaaS or technology environment • Hands-on experience with PIAs/DPIAs, ROPA, DSARs, and privacy risk assessments • Experience with third-party risk management and security reviews • Experience supporting customer trust and privacy inquiries • Ability to analyze complex privacy and security issues and provide clear, actionable recommendations • Familiarity with SOC 2, ISO 27001, and ISO 27701 audit processes • Strong cross-functional communication and stakeholder management skills, including the ability to explain privacy and security risks to technical and non-technical audiences • Highly organized with strong attention to detail and the ability to manage multiple priorities under tight deadlines • Experience with US state privacy laws (HIPAA, CCPA and others) • Experience working at a SaaS company
Responsibilities
• Lead privacy operations within the Security GRC function by developing, implementing, and maintaining privacy program processes and documentation, including: • Records of Processing Activities (ROPA) and data inventories • Data Subject Access Requests (DSARs), in coordination with Legal, HR, and Marketing • Support privacy-by-design practices by embedding privacy considerations into GRC workflows, risk assessments, and third-party reviews • Support the privacy risk register by providing input and context on privacy and security risks, and ensure key stakeholders, including Legal, the DPO, and business teams, are kept informed of risk status and updates • Assist with third-country data transfer risk assessments (Transfer Impact Assessments), Legitimate Interest Assessments (LIAs), and related privacy evaluations in consultation with Legal and the DPO • Participate in GRC rotational responsibilities, including third-party security and privacy vendor reviews and support for internal and external audits (e.g., SOC 2, ISO 27001), including evidence collection and remediation tracking • Provide rotational support for customer trust and privacy inquiries, partnering with Sales and Customer Success on customer-requested DPIAs, privacy questionnaires, and data protection assessments • Collaborate cross-functionally with Legal, the DPO, Product, Engineering, Security, and business teams to operationalize privacy and security requirements in a scalable, risk-based manner by providing innovative solutions and automation initiatives
Benefits
• Competitive salaries & meaningful equity • Private Medical Insurance • Life/Risk Assurance • Meal Allowance: 8.55€ per day • Paid Annual Leave (22 days) • Global Lifestyle Reimbursement Account • Paid Sabbatical • Complete laptop workstation • Recruitment Disclaimer: • Please be aware that Iterable, Inc. (“Iterable”) and our official professional recruiting agencies and platforms do not: • Send job offers from free email services like Gmail, Yahoo mail, Hotmail, etc. • Request money, fees, or payment of any kind from prospective candidates to apply to Iterable, for employment, or for the recruitment process (e.g. for home office supplies, or training, etc.). • Request or require personal documents like bank account details, tax forms, or credit card information as part of the recruitment process prior to the candidate signing an engagement letter or an employment contract with Iterable. • You may see all job vacancies on our official Iterable channels: • Official Iterable website, Careers page: https://iterable.com/careers/ • Official LinkedIn Jobs page: https://www.linkedin.com/company/iterable/jobs/ • Iterable is not affiliated in any way to these impostors and we hereby confirm that such individuals/entities are not authorized, encouraged, or sponsored to act on behalf of Iterable. Such job opportunities are entirely fake and not valid. Therefore, please disregard any written or oral request for a job offer or an interview that you believe is or might be fraudulent or suspicious and immediately reach out to us via email at [email protected] upon receiving a suspicious job offer. • [email protected] • Criminal and/or civil liabilities may arise from such actions, and Iterable expressly reserves the right to take legal action, including criminal action, against such individuals/entities whenever such phenomena occur. In any case, please note that under no circumstances shall Iterable and any of its affiliates be held liable or responsible for any claims, losses, damages, expenses or other inconvenience resulting from or in any way connected to the actions of these impostors.Iterable is an Equal Employment Opportunity employer that proudly pursues and hires a diverse workforce. Iterable does not make hiring or employment decisions on the basis of race, color, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender-identity, sexual orientation, disability, age, military or veteran status, or any other basis protected by applicable local, state, or federal laws or prohibited by Company policy. Iterable also strives for a healthy and safe workplace and strictly prohibits harassment of any kind. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Iterable will also consider for employment qualified applicants with arrest and conviction records.
No credit card. Takes 10 seconds.