ShipHero Logo

ShipHero

GRC & Privacy Analyst

Posted 2 Days Ago
Remote
Hiring Remotely in United States
Junior
Remote
Hiring Remotely in United States
Junior
The GRC & Privacy Analyst will manage compliance tools, support SOC 2 audits, handle vendor risk, and conduct compliance research.
The summary above was generated by AI

About ShipHero

ShipHero is a technology company that provides a leading Warehouse Management System (WMS) and outsourced fulfillment services to over 5,000 e-commerce brands. We are a globally remote company with a passion for building innovative solutions and supporting our customers' growth. Our team is agile, collaborative, and dedicated to excellence.

The Role

ShipHero is seeking a highly motivated and detail-oriented GRC & Privacy Analyst to join our Compliance team. Reporting directly to the Head of Compliance (DPO), you will be a key player in the day-to-day operations of our global security, privacy, and compliance programs.

This is a hands-on role for a proactive "self-starter" who is eager to learn and grow. You will gain invaluable mentorship and broad exposure to all facets of GRC in a modern, cloud-native tech environment. You will be responsible for managing critical compliance tools, supporting our SOC 2 audits, handling vendor risk management, and operationalizing our global data privacy program.

What You'll Do:

  • Privacy Operations: Manage and configure our data privacy platform (Osano) to ensure compliance with global regulations. This includes managing our consent management program, cookie categorization, and the operational response to Universal Opt-Out Mechanisms (UOOM) and Global Privacy Control (GPC).
  • Third-Party Risk Management (TPRM): Own the end-to-end vendor risk assessment process, from initial due diligence and security questionnaires to reviewing Data Processing Agreements (DPAs) and managing the vendor lifecycle.
  • GRC & Audit Support: Play a critical role in our compliance programs by managing our GRC platform (Drata). You will be responsible for collecting, reviewing, and organizing audit evidence, monitoring control effectiveness, and supporting our annual SOC 2 Type 2 audits.
  • Compliance Research & Documentation: Proactively research, summarize, and provide guidance on emerging data privacy regulations in the U.S. (state-level), Canada (PIPEDA, Law 25), and the EU/UK (GDPR).
  • Policy & Awareness: Assist in drafting, reviewing, and maintaining compliance policies, procedures, and internal documentation. You will also help support our security awareness training program (KnowBe4).

What You'll Bring (Qualifications):

  • Experience: 2-3 years of hands-on experience in a GRC, data privacy, compliance, or IT audit role.
  • Core Knowledge: A strong foundational understanding of U.S. Data Privacy Regulations (e.g., CCPA/CPRA, VCDPA, etc.) is required.
  • Global Familiarity: Working knowledge of GDPR and Canadian privacy laws (PIPEDA, Law 25).
  • The "Self-Starter" DNA: You must be a highly motivated, self-directed learner. You have the resilience to conduct independent research, the curiosity to learn new tools, and the professional judgment to know when to ask for help.
  • Technical Aptitude: You are "tool-savvy" and comfortable mastering new SaaS platforms. High proficiency in spreadsheets (Google Sheets / Excel) for tracking, analysis, and reporting is essential.
  • Communication: Flawless written and verbal communication skills in English.
  • Soft Skills: Exceptional organizational skills, high attention to detail, and the ability to manage multiple priorities in a fast-paced, remote environment.

Preferred Qualifications (Strong Pluses):

  • Direct, hands-on experience participating in one or more SOC 2 Type 2 audits.
  • Experience with a GRC automation platform (e.g., Drata, Vanta, Secureframe).
  • Experience with a data privacy management platform (e.g., Osano, OneTrust, TrustArc), especially for consent management (GPC/UOOM).
  • Experience working in a SaaS, cloud-native, or e-commerce technology company.
  • A strong interest in emerging technologies and regulations, such as AI governance.

Why ShipHero?

  • Direct Impact: As part of a lean and agile team, your work will have a direct and immediate impact on our compliance and security posture.
  • Growth & Mentorship: This is a unique opportunity to be mentored directly by the Head of Compliance/DPO and gain comprehensive experience across all GRC domains.
  • Work-Life Balance: We are a 100% remote company. We offer a flexible and autonomous work environment where you are trusted to manage your own time and deliver results.

Our Core Values:

  • Do the right thing - Our employees are held to the highest standards. We act with integrity and honesty, embrace accountability, and do what’s right, even when no one is watching.
  • Tenacity - We take a relentless approach in our business: We show up expecting to win every day, obsess about serving our clients and employees, and are driven by results.
  • Have Fun & Be Bold - We support work-life balance and have fun while being our bold and authentic selves.
  • Scrappiness - We do more with less. We are scrappy, determined, resourceful, and relentless in delivering results.

ShipHero would like to thank all applicants for their interest; however, only those selected for an interview will be contacted.

Ship Hero is committed to a diverse and inclusive workplace. ShipHero is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, disability, age or any other characteristic protected by law. We are committed to providing employment accommodation in accordance with the law. If you require accommodations due to a disability at any stage of our hiring process, please notify our Human Resources Team.

Top Skills

Data Privacy Management Platforms (Osano)
Excel
Google Sheets
Grc Platforms (Drata)

Similar Jobs

11 Hours Ago
Remote or Hybrid
Atlanta, GA, USA
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Seeking a Lead Client Director to manage executive relationships, drive multi-year transformation initiatives, and oversee strategic account planning to foster business growth.
11 Hours Ago
Remote or Hybrid
Chicago, IL, USA
170K-298K Annually
Expert/Leader
170K-298K Annually
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Director will manage release and deployment processes, lead a team, define release vision and metrics, and ensure efficient delivery of software releases.
Top Skills: Agile MethodologiesCi/Cd PipelinesCloud PlatformsDevops PracticesItsm PlatformsSource Control
11 Hours Ago
Remote or Hybrid
Memphis, TN, USA
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Client Director will manage relationships with major clients like FedEx, lead teams to develop solutions, and achieve financial targets.
Top Skills: AIIt Service Management

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account