Benevity
Technology
SeniorGRCAnalyst,Privacy
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior GRC Analyst, Privacy at Benevity. Skills: Privacy program, Data protection, Regulatory compliance. Own and maintain Records of Processing Activities. Develop and maintain privacy policies”
Industry & Context.
What They're Looking For.
Must Have
5+ years experience in privacy, 5+ years experience in data protection, 5+ years experience in GRC, 5+ years experience in closely related field
Nice to Have
CIPP/E certification, CIPP/US certification, CIPM certification, CIPT certification, CISM certification, CRISC certification
What You'll Do.
Own and maintain Records of Processing Activities
Develop and maintain privacy policies
Develop and maintain privacy notices
Develop and maintain privacy standards
Develop and maintain control frameworks
Support privacy policy approval
Support exception management
Support attestation processes
Build and manage DSAR intake workflows
Build and manage DSAR triage workflows
Build and manage DSAR response workflows
Maintain and refresh subprocessor listing
Design Data Protection Impact Assessments
Operationalize Data Protection Impact Assessments
Improve Data Protection Impact Assessments
Embed DPIA requirements into workflows
Support DPO operational function
Partner on Data Processing Agreement reviews
Translate privacy requirements into controls
Review Data Processing Agreements
Support negotiation of Data Processing Agreements
Support data transfer mechanisms
Monitor global privacy regulatory landscape
Assess impact of new requirements
Support multi-entity privacy obligations
Maintain privacy workflows in GRC platforms
Enhance privacy workflows in GRC platforms
Deliver executive-ready privacy reports
Deliver risk insights
Design privacy awareness programs
Design privacy training programs
Serve as privacy advisor
Partner with teams to embed privacy
How You'll Work.
Team & Collaboration
Cross-functional teams; Legal; Security; Engineering; Product; Data Governance
Communication Scope
Executive presentations; Privacy reports; Risk insights; Dashboards
Full Job Description
MEET BENEVITY Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits. We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more! Benevity is seeking a Sr. GRC Analyst, Privacy to anchor and advance our data protection program across a complex, multi-jurisdictional regulatory landscape. In this role, you will own the design, operationalization, and continuous maturity of Benevity’s privacy compliance program, spanning GDPR, UK-GDPR, CPRA, PIPEDA, CASL, and emerging global frameworks. You will build the foundational infrastructure that keeps Benevity accountable to its regulatory obligations: Records of Processing Activities, Data Subject Access Request workflows, Data Protection Impact Assessments, and subprocessor governance, ensuring the program is not only defensible to regulators but scalable as Benevity grows. As a trusted privacy advisor embedded across cross-functional teams, you will work closely with Legal, Security, Engineering, Product, and Data Governance to embed Privacy by Design into the business. You will support the DPO operational function, partner on Data Processing Agreement reviews, and translate complex privacy requirements into practical, business-aligned controls. Your work will directly protect Benevity’s clients, employees, and the communities they serve, and ensure that trust remains a core competitive advantage. What you’ll do: Privacy Program & Governance - Own and maintain Benevity’s Records of Processing Activities (ROPA) under both controller and processor regimes, ensuring compliance w
Applying for this Senior GRC Analyst, Privacy role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Benevity?
Real rants from real employees. Read before you apply.