Senior GRC Analyst, Privacy

Posted 2 weeks ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior GRC Analyst at Benevity managing privacy compliance across multiple frameworks and jurisdictions. Responsible for ROPAs, DSAR workflows and collaboration with various teams.

Responsibilities

  • Own and maintain Benevity’s Records of Processing Activities (ROPA) under both controller and processor regimes.
  • Develop and maintain privacy policies, notices, standards, and control frameworks aligned with GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, CASL, and emerging global laws.
  • Build and manage DSAR intake, triage, and response workflows in compliance with statutory deadlines.
  • Design, operationalize, and continuously improve the Data Protection Impact Assessment (DPIA) process.
  • Review and support the negotiation of Data Processing Agreements and data transfer mechanisms in collaboration with Legal.
  • Maintain and enhance privacy workflows in GRC platforms to automate compliance operations at scale.
  • Design and deliver privacy awareness and training programs to build a culture of data protection.

Requirements

  • 5+ years of experience in privacy, data protection, GRC, or a closely related field, ideally within a SaaS or high-growth technology environment.
  • Deep, practical knowledge of global privacy frameworks, including GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, and CASL, with working familiarity of emerging regimes (India DPDP, Swiss FADP, AU Privacy Act reforms).
  • Hands-on experience building and maintaining ROPAs under both controller and processor regimes, managing DSAR workflows, conducting DPIAs, and maintaining subprocessor inventories.
  • Experience supporting or operating within a DPO function, including regulatory interface and breach notification processes.
  • Proven ability to review and support the negotiation of Data Processing Agreements and data transfer mechanisms in collaboration with Legal.
  • Hands-on experience with privacy or GRC tooling (e.g., OneTrust Privacy module, Hyperproof, or equivalent) to operationalize compliance workflows at scale.
  • Ability to communicate complex privacy and regulatory concepts clearly to technical, legal, and business audiences.
  • A demonstrated interest and track record in leveraging AI and automation as a force multiplier, streamlining privacy operations, accelerating routine workflows, and expanding program capacity without proportional headcount growth.
  • Certifications such as CIPP/E, CIPP/US, or CIPM are highly valued; CIPT, CISM, or CRISC are also welcomed.

Benefits

  • Flexible hybrid work arrangements
  • Opportunity to build a culture of data protection
  • Growth opportunities

Job title

Job type

Full Time

Experience level

Senior

Salary

Not specified

Degree requirement

Bachelor's Degree

Location requirements

HybridCalgaryCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.