Senior GRC Analyst, Privacy
BenevityJob Description
📋 Description Own and maintain ROPA across controller/processor regimes and jurisdictions. Develop privacy policies, notices, standards, and controls across GDPR, CPRA, PIPEDA, CASL. Manage DSAR intake, triage, and responses with deadlines; coordinate with business. Design and operationalize DPIA; embed into product/data workflows; support DPO readiness. Maintain privacy workflows in GRC tools; deliver exec reports; leverage AI to scale. 🎯 Requirements 5+ years in privacy, data protection, or related field. Deep knowledge of GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, CASL. Hands-on DSAR and DPIA experience; DPIA process design. Experience with privacy or GRC tooling (OneTrust, Hyperproof, or equivalent). Able to communicate complex privacy concepts to diverse audiences. Certifications such as CIPP/E, CIPP/US, or CIPM are valued. 🎁 Benefits Flexible hybrid work model with optional in-office time. Strong DEIB culture and employee resource groups. Growth opportunities and purpose-driven work. Accommodations available for candidates with disabilities.