×
Register Here to Apply for Jobs or Post Jobs. X

GRC Analyst - Hybrid AZ

Job in Mesa, Maricopa County, Arizona, 85201, USA
Listing for: BWI Best Western International, Inc.
Full Time position
Listed on 2026-08-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 90000 - 130000 USD Yearly USD 90000.00 130000.00 YEAR
Job Description & How to Apply Below

Join BWH Hotels – Where Passion Meets Purpose

At BWH Hotels, we don't just offer employment opportunities, we create opportunities to be part of something extraordinary. As a global leader in hospitality for nearly 80 years, our vision is to inspire travel through unique experiences. Joining our corporate team means becoming part of a dynamic and inclusive community that values innovation, collaboration, and making a meaningful impact in the travel industry.

Headquartered in Phoenix, Arizona, BWH Hotels boasts a powerful portfolio of 18 brands, including World Hotels™, Best Western® Hotels & Resorts, and Sure Stay Hotels®, with approximately 4,300 hotels in over 100 countries. We take pride in our top-ranking employee engagement scores and foster a workplace culture where your contributions truly matter. Join us and be part of a team that's shaping the future of hospitality!

Job

Purpose

Ensures the confidentiality, integrity, and availability of Company data and information technology assets by supporting governance, risk, and compliance activities, including security policy and standards management, risk management, disaster recovery coordination, audit readiness, and regulatory compliance. This role supports PCI DSS, SOX, privacy, and broader cybersecurity compliance activities across the organization.

Key Responsibilities
  • The ideal candidate will be able to build rapport and credibility with internal stakeholders, business partners, member hotel representatives, and technology teams to support effective governance, risk, and compliance outcomes.
  • Excellent communication and interpersonal skills are required to coordinate evidence requests, explain control expectations, and drive timely follow-through.
  • Demonstrated experience supporting compliance frameworks and control environments such as PCI DSS v4.0.1, NIST, COBIT, ISO 27001, SOX, privacy regulations, and related cybersecurity standards.
  • Coordinate with internal stakeholders and external auditors to maintain current documentation for control scoping, evidence collection, testing support, remediation tracking, and validation of IT and cybersecurity controls.
  • Work with stakeholders to fulfill evidence requests within committed timelines and ensure evidence is complete, accurate, and mapped to applicable control requirements.
  • Conduct recurring control reviews with stakeholders to identify gaps, track remediation progress, and provide actionable advisement to management.
  • Review audit findings, control gaps, and compliance risks; partner with control owners to document remediation plans, track progress, and elevate delays or blockers as appropriate.
  • General understanding of Sarbanes-Oxley (SOX) compliance requirements, IT General Controls, and audit evidence expectations.
  • Thorough knowledge of PCI-related standards and guidance, including PCI DSS v4.0.1, ASV requirements, payment security documentation, and software security requirements where applicable.
  • Thorough understanding of applicable privacy and data protection requirements, including GDPR, the California Consumer Privacy Act (CCPA), and related organizational privacy obligations.
  • Familiarity with a broad range of IT and information security products and technologies such as GRC platforms, central logging systems, file integrity monitoring, vulnerability management, endpoint security, and cloud security tools.
  • Excellent documentation, communication, organization, and follow-through skills, with the ability to coordinate multiple evidence, audit, and remediation activities at the same time.
Preferred Experience and Education
  • Bachelor's or Master's degree in a computer or information management field or related experience preferred.
  • CISSP, CISA, CISM, CRISC, or equivalent security, audit, risk, or compliance certification preferred.
  • 3-5 years’ experience in an information security compliance, audit, governance, or risk management role with hands‑on experience in compliance initiatives including, but not limited to: PCI DSS v4.0.1 Software security, secure software lifecycle, or application security compliance requirements where applicable SOX‑404 and IT General Controls EU‑GDPR, CCPA, and related…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary