Benevity Logo

Benevity

Senior GRC Analyst

Posted 8 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
The Senior GRC Analyst will enhance Benevity's governance, risk, compliance, and regulatory framework by leading risk assessments, compliance activities, and fostering a culture of security and accountability while mentoring junior team members.
The summary above was generated by AI

Meet Benevity

Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits. We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more!

Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits. We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more! 

Benevity is seeking a Senior Governance, Risk & Compliance (GRC) Analyst to elevate our security governance, risk, privacy, and regulatory posture. In this senior role, you will drive the execution, innovation, and continuous improvement of Benevity’s GRC program. You will lead compliance activities, conduct risk assessments, contribute to third-party risk management, respond to client due diligence requests, support FINTRAC/AML obligations, and influence policies and controls that strengthen trust with our clients, partners, and stakeholders.

As a trusted advisor across teams, you will help ensure Benevity aligns with leading standards, privacy laws, and regulatory requirements while fostering a culture of security, compliance, and accountability. You’ll also mentor junior members of the team, helping to grow Benevity’s next generation of security and compliance professionals, with a focus on developing proactive and innovative approaches to GRC challenges.

What you’ll do:

  • Contribute to the development and maintenance of security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, NIST, PCI DSS, GDPR, PIPEDA, FINTRAC, and other global regulations
  • Support policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvements
  • Lead and execute enterprise risk assessments, including vendor and process-level reviews
  • Maintain and enhance the enterprise risk register, track remediation efforts, and support risk treatment planning
  • Support Benevity’s Third-Party Risk Management program including vendor assessments, monitoring, and remediation tracking
  • Lead readiness and response efforts for ISO 27001, SOC 2, PCI DSS, GDPR, and other audits and certifications
  • Coordinate evidence collection, control validation, and engagement with auditors and external assessors
  • Use GRC platforms to streamline audit, privacy, and compliance workflows
  • Support Sales by responding to client inquiries, RFPs, and third-party risk requests related to security and privacy
  • Partner with Sales and Client Success to deliver accurate, timely information that builds client trust and confidence
  • Support cross-jurisdictional privacy compliance initiatives (GDPR, PIPEDA, CCPA/CPRA) in collaboration with Legal and Data Governance
  • Assist with FINTRAC-related requirements, including AML/ATF risk assessments and reporting
  • Monitor privacy, AML, and financial crime regulations and contribute to process alignment and compliance readiness
  • Partner with business and technical teams to embed risk and compliance into key initiatives
  • Deliver executive-ready reports, dashboards, and risk insights to inform leadership decision-making
  • Lead the Security Awareness & Training program, including campaigns, training modules, and phishing simulations
  • Create documentation, training, and awareness activities that promote a strong culture of security, privacy, and compliance
  • Mentor junior team members by providing guidance, feedback, and knowledge sharing to support their development

What you’ll bring:

  • 5+ years of experience in cybersecurity, governance, risk, compliance, or privacy, ideally in a SaaS or high-growth environment.
  • Strong knowledge of security, privacy, and regulatory frameworks including ISO 27001, NIST, SOC 2, PCI DSS, GDPR, PIPEDA, FINTRAC, and CCPA/CPRA.
  • Hands-on experience with GRC tooling (e.g., OneTrust, Hyperproof, SecurityPal, AuditBoard, Drata) to manage policies, risks, audits, privacy, and vendor risk workflows.
  • Proven success in conducting risk assessments, managing vendor risk/TPRM, maintaining risk registers, and driving remediation.
  • Experience supporting client due diligence processes (security questionnaires, RFPs, TPRM).
  • Ability to clearly communicate risk, security, privacy, and regulatory concepts to both technical and non-technical stakeholders.
  • Strong organizational and project management skills with experience leading cross-functional initiatives.
  • A demonstrated interest and track record in leveraging automation and AI to streamline GRC processes and enhance efficiency.
  • Certifications such as CISM, CRISC, CISSP, CISA, or CIPM/CIPP are highly valued.
Discover your purpose at work

We’re not employees, we’re Benevity-ites. From all locations, backgrounds and walks of life, who deserve more …

Innovative work. Growth opportunities. Caring co-workers. And a chance to do work that fills us with a sense of purpose.

If the idea of working on tech that helps people do good in the world lights you up ... If you want a career where you’re valued for who you are and challenged to see who you can become …

It’s time to join Benevity. We’re so excited to meet you.

Where We Work

At Benevity, we embrace a flexible hybrid approach to where we work that empowers our people in a way that supports great work, strong relationships, and personal well-being. For those located near one of our offices, while there’s no set requirement for in-office time, we do value the moments when coming together in person helps us build connection and collaboration. Whether it’s for onboarding, project work, or a chance to align and bond as a team, we trust our people to make thoughtful decisions about when showing up in person matters most.

Join a company where DEIB isn’t a buzzword
Diversity, equity, inclusion and belonging are part of Benevity’s DNA. You’ll see the impact of our massive investment in DEIB daily — from our well-supported employee resources groups to the exceptional diversity on our leadership and tech teams.

We know that diverse backgrounds, experiences, skills and passions are what move our business and our people forward, so we're committed to creating a culture of belonging with equal opportunities for everyone to shine. 

That starts with a fair and accessible hiring process. If you want to feel seen, heard and celebrated, you belong at Benevity.

Candidates with disabilities who may require accommodations throughout the hiring or assessment process are encouraged to reach out to [email protected].

Discover your purpose at work

We’re not employees, we’re Benevity-ites. From all locations, backgrounds and walks of life, who deserve more …

Innovative work. Growth opportunities. Caring co-workers. And a chance to do work that fills us with a sense of purpose.

If the idea of working on tech that helps people do good in the world lights you up ... If you want a career where you’re valued for who you are and challenged to see who you can become …

It’s time to join Benevity. We’re so excited to meet you.

Where We Work

At Benevity, we embrace a flexible hybrid approach to where we work that empowers our people in a way that supports great work, strong relationships, and personal well-being. For those located near one of our offices, while there’s no set requirement for in-office time, we do value the moments when coming together in person helps us build connection and collaboration. Whether it’s for onboarding, project work, or a chance to align and bond as a team, we trust our people to make thoughtful decisions about when showing up in person matters most.

Join a company where DEIB isn’t a buzzword
Diversity, equity, inclusion and belonging are part of Benevity’s DNA. You’ll see the impact of our massive investment in DEIB daily — from our well-supported employee resources groups to the exceptional diversity on our leadership and tech teams.

We know that diverse backgrounds, experiences, skills and passions are what move our business and our people forward, so we're committed to creating a culture of belonging with equal opportunities for everyone to shine. 

That starts with a fair and accessible hiring process. If you want to feel seen, heard and celebrated, you belong at Benevity.

Candidates with disabilities who may require accommodations throughout the hiring or assessment process are encouraged to reach out to [email protected].

Top Skills

Auditboard
Ccpa/Cpra
Drata
Fintrac
Gdpr
Hyperproof
Iso 27001
Nist
Onetrust
Pci Dss
Pipeda
Securitypal
Soc 2

Similar Jobs

23 Days Ago
Remote
USA
Senior level
Senior level
Internet of Things
Lead the development of a Governance, Risk, and Compliance framework, ensuring regulatory compliance and risk management across Mozilla's products and enterprise sectors.
Top Skills: Bi ToolsCcpaGdprIsoNistSeimSoc2
23 Days Ago
Remote
US
178K-259K Annually
Senior level
178K-259K Annually
Senior level
Internet of Things
Define, develop, and implement Governance, Risk, and Compliance (GRC) framework while ensuring alignment across security, privacy, and regulatory requirements. Lead audits and manage cross-functional relationships.
Top Skills: Bi ToolsCcpaGdprIsoNistSeimSoc2
4 Days Ago
Remote
United States
Senior level
Senior level
Software
The Senior GRC Analyst will lead compliance strategies, assist in FedRAMP certification, maintain SOC 2 compliance, and manage vendor security assessments.
Top Skills: AWSAzureCcpaCompliance Automation ToolsFedrampGCPGdprIso 27001Soc 2

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account