Senior Grc Analyst - Privacy

Iterable Iterable · Enterprise · Lisbon, Portugal · Security & IT

Senior GRC Analyst - Privacy role focused on advancing the company's privacy program and supporting security and compliance risk management efforts within a SaaS company. Responsibilities include privacy operations, third-party risk reviews, audit support, and handling customer privacy inquiries, partnering with Legal, DPO, Security, Product, and business teams.

What you'd actually do

  1. Lead privacy operations within the Security GRC function by developing, implementing, and maintaining privacy program processes and documentation, including:
  2. Support privacy-by-design practices by embedding privacy considerations into GRC workflows, risk assessments, and third-party reviews
  3. Support the privacy risk register by providing input and context on privacy and security risks, and ensure key stakeholders, including Legal, the DPO, and business teams, are kept informed of risk status and updates
  4. Assist with third-country data transfer risk assessments (Transfer Impact Assessments), Legitimate Interest Assessments (LIAs), and related privacy evaluations in consultation with Legal and the DPO
  5. Participate in GRC rotational responsibilities, including third-party security and privacy vendor reviews and support for internal and external audits (e.g., SOC 2, ISO 27001), including evidence collection and remediation tracking

Skills

Required

  • GDPR
  • global privacy operations
  • SaaS or technology environment experience
  • PIAs/DPIAs
  • ROPA
  • DSARs
  • privacy risk assessments
  • third-party risk management
  • security reviews
  • customer trust and privacy inquiries
  • SOC 2
  • ISO 27001
  • ISO 27701
  • cross-functional communication
  • stakeholder management

Nice to have

  • Privacy certifications (CIPP/E, CIPP/US, CIPM, or similar)
  • US state privacy laws (HIPAA, CCPA and others)
  • SaaS company experience

What the JD emphasized

  • Strong experience with GDPR and global privacy operations in a SaaS or technology environment
  • Hands-on experience with PIAs/DPIAs, ROPA, DSARs, and privacy risk assessments
  • Experience with third-party risk management and security reviews
  • Experience supporting customer trust and privacy inquiries
  • Familiarity with SOC 2, ISO 27001, and ISO 27701 audit processes