Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
GRC Specialist I image - Rise Careers
Job details

GRC Specialist I

Who we are: 

Want to make an impact? Join our pack and come work (and play!) with us.


We believe everyone deserves the unconditional love of a pet—and at Rover, our mission is to make it easier to experience that love. Founded in 2011, the Rover app and website connect dog and cat parents with loving pet sitters and dog walkers in neighborhoods across the US, Canada, and Europe. We empower our community of trusted pet sitters and dog walkers to run their own pet care businesses on Rover with the tools and security of a global company to back them.


Headquartered in Seattle, Washington, we work closely with our teams in Barcelona, San Antonio, Spokane, and remote locations. We’ve got a reputation for being a great place to work, having been named among the 100 Best Companies to Work For in Seattle Business Magazine and Washington’s Best Workplaces in the Puget Sound Business Journal. We're an agile, fast-growing company, and our leadership comes from some of the world's most respected tech companies. 


At Rover, our furry coworkers are just as important as our human ones—and we wouldn’t have it any other way. Along with making the joys of pet parenthood more accessible, we’re committed to fostering a diverse, inclusive, and welcoming community of pet people—and that starts with our employees.


This role is based in our Barcelona office and is hybrid, one day in office per week (Thursday)


Who We're Looking For:

We are seeking a detail-oriented and proactive GRC Specialist to join our team at Rover. This role will support our efforts to ensure proper data governance, policy development, and regulatory adherence with a specific focus on global privacy regulations, including CCPA, GDPR, and other privacy laws. The ideal candidate will work closely with our legal and cybersecurity to ensure that our GRC practices are robust, effective, and compliant.


Your Responsibilities:
  • Manage and Respond to Data Subject Requests Escalations (DSRs): Handle customer escalations from CX around requests for data access, rectification, erasure, restriction, portability, and objections to processing, ensuring timely and compliant responses under CCPA, GDPR, and other regulations.
  • Assist in Privacy Expertise and Guidance: Offer insights and best practices to internal stakeholders on privacy compliance, supporting a culture of privacy and data protection within the organization and new Rover companies.
  • Policy and Procedure Development: Contribute to the development and maintenance of privacy and data governance policies, ensuring they are up-to-date with evolving regulatory requirements.
  • Maintain Training Records and Key Learning Indicators: Track key learning indicator measures related to privacy compliance and maintain training records to ensure continuous improvement and awareness among staff.
  • Assist in Developing Metrics to Track Success of Program: Specifically, we need someone who can help to develop strong metrics to track and report on the health/success of our privacy programs.  This will be done in conjunction with our Privacy Program Manager to be reported out to our executives on the success or failure of the programs we develop.
  • Assist with Record of Data Processing Activities (ROPA): Work with Legal counterparts to develop and maintain the ROPA, ensuring accurate documentation of data processing activities.
  • Assist in Configuration and Customize Ketch Platform: Assist in configuration and customization to the Ketch privacy management platform, with Data Security Engineer, to meet the needs of the privacy program, including creating and refining workflows, assessments, and reports.
  • Assist in Compliance Monitoring: Monitor and track compliance activities, including the effectiveness of privacy and data security controls, and provide regular reports to management.
  • Support Data Privacy Audits: Assist in or conduct data privacy audits to identify and address vulnerabilities in data privacy processes, ensuring alignment with regulatory requirements.
  • Governance Activities: Support the GRC team in maintaining records of data processing activities, conducting privacy impact assessments, and ensuring documentation is compliant with CCPA, GDPR, and other relevant regulations.
  • Assist in Conducting Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs): Collaborate with Legal and Privacy Program Manager to evaluate and mitigate privacy  risks through PIAs and DPIAs, supporting the privacy program’s risk management efforts.
  • Collaborate on Privacy Law Compliance: Partner with Legal and Privacy Program Manager counterparts and to ensure compliance with existing and emerging privacy regulations, providing insights on changes that impact the organization.
  • Training and Awareness: Assist in developing training materials and programs to enhance employee awareness regarding privacy practices, data protection requirements, and internal policies.
  • Incident Response Support: As necessary, aid in the documentation and investigation of data breaches or other security incidents, ensuring a swift and compliant response in collaboration with the Data Security Engineer and other stakeholders.


Your Qualifications:
  • Education: Bachelor’s degree in Information Security, Risk Management, Compliance, Business Administration, or a related field.
  • Experience: 0-2 years of experience in governance, risk management, compliance, or a related field, with a focus on privacy regulations (e.g., GDPR, CCPA).
  • Knowledge of Privacy Management Platforms: Familiarity with platforms like Ketch or similar tools for managing data subject rights and automating privacy workflows.
  • Regulatory Understanding: Strong understanding of global privacy laws and regulations, including GDPR, CCPA, and industry standards for data protection.
  • Communication Skills: Excellent written and verbal communication skills, with the ability to clearly present complex privacy concepts to stakeholders at all levels.
  • Attention to Detail: Meticulous attention to detail, particularly in documentation, policy development, and audit processes.
  • Collaborative Mindset: Ability to work effectively in cross-functional teams, collaborating with legal, cybersecurity, and business units.


Preferred Qualifications:
  • Certifications: Privacy certifications such as CIPP/US, CIPP/E, or CIPM are highly desirable.
  • Experience with GRC Tools: Experience with GRC software or platforms for tracking compliance and developing metrics.
  • Knowledge of Data Security Practices: Understanding of encryption, data anonymization, and data protection practices to support data privacy initiatives.


Why Join Rover?
  • Competitive Compensation: A comprehensive package, including a 401(k), equity, and flexible PTO.
  • Professional Development: Opportunities for growth and professional certification support.
  • Collaborative Environment: Work in a team-oriented environment where you’ll have the opportunity to engage with multiple departments, including Legal, IT, and Cybersecurity.
  • Unique Benefits: From dog-friendly offices to regular team events, Rover offers a fun and inclusive culture that values work-life balance.


Rover is an equal-opportunity employer committed to promoting a diverse, inclusive, and inventive environment with the best employees. We’re driven by seeing our people succeed and grow, and we work to ensure everyone contributes to their fullest potential. We consider all qualified applicants without regard to age, race, color, ancestry, national origin, religion, disability, protected veteran status, sex, gender identity or expression, sexual orientation, or any other protected status in accordance with applicable laws, regulations, and ordinances.

Rover.com Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Rover.com DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Rover.com
Rover.com CEO photo
Aaron Easterly
Approve of CEO

Average salary estimate

$60000 / YEARLY (est.)
min
max
$50000K
$70000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About GRC Specialist I, Rover.com

Join Rover as a GRC Specialist I in our vibrant Barcelona office, where you’ll be part of a team that’s passionate about pets and committed to data privacy! At Rover, we connect pet parents with loving sitters and walkers, making pet ownership easier and more joyful. In this role, you’ll dive into the world of Governance, Risk, and Compliance, focusing on global privacy regulations like GDPR and CCPA. Be prepared to engage with our legal and cybersecurity teams as you manage Data Subject Requests, assist with privacy audits, and contribute to developing metrics for essential privacy programs. You’ll help craft policies that evolve with legislation, maintain training records that promote data protection awareness, and support incident response efforts to safeguard our community. Your proactive approach will ensure that we stay compliant and supportive of our internal teams. With Rover’s dedicated culture of inclusion and collaboration, you’ll find yourself thriving in an environment where your contributions are valued. Plus, we offer fantastic perks, like flexible PTO and a supportive atmosphere, perfect for both your professional growth and furry friend-loving side. If you’re ready to embrace a career in data privacy while enjoying a pet-friendly workplace, apply today and let’s make a lasting impact together!

Frequently Asked Questions (FAQs) for GRC Specialist I Role at Rover.com
What does a GRC Specialist I at Rover in Barcelona do?

As a GRC Specialist I at Rover, you will manage Data Subject Requests and assist with privacy compliance efforts under CCPA and GDPR. Your responsibilities will include policy development, tracking compliance activities, and collaborating with legal teams to ensure the privacy program's integrity. Additionally, you'll help document data processing activities, conduct audits, and support training initiatives to raise awareness regarding data protection practices.

Join Rise to see the full answer
What qualifications are needed for the GRC Specialist I position at Rover?

To succeed as a GRC Specialist I at Rover, candidates should possess a Bachelor’s degree in Information Security, Risk Management, Compliance, or related fields. Most importantly, a strong understanding of global privacy regulations like GDPR and CCPA is crucial, along with 0-2 years of relevant experience. Additionally, excellent communication skills, attention to detail, and a collaborative mindset are highly valued in this role.

Join Rise to see the full answer
How does Rover support professional development for GRC Specialist I employees?

Rover is committed to fostering professional growth for its employees, including those in the GRC Specialist I role. The company offers opportunities for professional development and supports certification endeavors, allowing employees to enhance their expertise in governance, risk management, and compliance. Rover values continuous learning and encourages team members to engage in programs that support their career advancement.

Join Rise to see the full answer
What type of work environment can a GRC Specialist I expect at Rover in Barcelona?

At Rover, the work environment is collaborative and inclusive, focusing on teamwork among various departments such as Legal, IT, and Cybersecurity. As a GRC Specialist I, you can expect a supportive culture where your ideas are welcomed, and your contributions are recognized. The Barcelona office, being hybrid, also supports a work-life balance while enabling a dynamic and engaging atmosphere.

Join Rise to see the full answer
What tools and platforms would a GRC Specialist I use at Rover?

A GRC Specialist I at Rover will have the opportunity to work with privacy management platforms like Ketch. Familiarity with GRC tools for tracking compliance and developing metrics is beneficial. This role will involve customizing workflows, assessments, and reports in line with privacy practices, ensuring comprehensive support for data management initiatives.

Join Rise to see the full answer
Common Interview Questions for GRC Specialist I
Can you explain your understanding of GDPR and CCPA as it relates to the GRC Specialist I role?

In preparing for the interview, demonstrate your comprehensive knowledge of GDPR and CCPA regulations, emphasizing their impact on data protection and privacy compliance. Discuss specific examples of how businesses must manage personal data, address Data Subject Requests, and mitigate risks associated with data breaches.

Join Rise to see the full answer
How would you approach managing a Data Subject Request at Rover?

When discussing this question, detail the step-by-step process you would follow to handle a Data Subject Request effectively. Emphasize the importance of timely responses, understanding the regulatory framework, and collaborating with customer experience teams to ensure compliance with privacy laws.

Join Rise to see the full answer
What strategies would you use to promote a culture of privacy within an organization?

In answering this question, outline your ideas for implementing training programs and creating informative resources to educate employees about privacy practices. Highlight the need for ongoing communication and the role of leadership in emphasizing the value of compliance and data protection.

Join Rise to see the full answer
Can you discuss your experience with privacy management platforms like Ketch?

Be prepared to share specific experiences you have with privacy management platforms. Focus on how you have utilized such tools to manage Data Subject Requests, track compliance activities, and ensure effective documentation of data processing activities.

Join Rise to see the full answer
What is your process for developing privacy and data governance policies?

When discussing your process, emphasize collaboration with legal teams, staying updated on regulatory changes, and involving relevant stakeholders. Mention how you would ensure policies are practical, enforceable, and communicated clearly across the organization.

Join Rise to see the full answer
How would you handle discrepancies found during a data privacy audit?

In answering this question, explain your approach to identifying the root cause of discrepancies, coordinating with various teams to address issues, and implementing corrective actions to strengthen privacy practices in line with regulatory requirements.

Join Rise to see the full answer
Describe a situation where you had to communicate complex privacy concepts to non-technical stakeholders.

Provide an example where you successfully translated complex privacy information into relatable concepts for non-technical stakeholders. Focus on your communication skills, emphasizing clarity and engaging language to foster understanding and engagement.

Join Rise to see the full answer
What metrics would you suggest tracking to assess the effectiveness of a privacy program?

Be ready to discuss specific metrics that measure compliance, such as the number of Data Subject Requests processed on time and the training completion rates of employees regarding privacy practices. Emphasize the importance of continual assessment and improvement.

Join Rise to see the full answer
How do you stay informed about changes in privacy regulations?

In your response, highlight various resources such as professional networks, webinars, and industry publications that you utilize to keep updated on privacy-related regulatory changes. Describe how this knowledge informs your work as a GRC Specialist I.

Join Rise to see the full answer
Why do you want to work as a GRC Specialist I at Rover?

When answering this question, express genuine enthusiasm for joining Rover’s mission to support pet owners while ensuring data privacy. Discuss how your values align with Rover’s commitment to inclusion and community, and your eagerness to contribute to a team that creates a positive impact in the pet care industry.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Incommunities Remote No location specified
Posted 13 days ago
Photo of the Rise User
Posted 3 hours ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Box Hybrid Redwood City, CA, United States
Posted 5 days ago
Customer-Centric
Dare to be Different
Diversity of Opinions
Feedback Forward
Take Risks
Growth & Learning
Transparent & Candid
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
Posted 5 days ago

We believe in the unconditional love of dogs, and Rover exists to make it possible for everyone to experience this love in their lives. As we strive to achieve this mission, our core values guide us in how we conduct our business and ourselves. To...

75 jobs
MATCH
VIEW MATCH
BADGES
Badge ChangemakerBadge Flexible CultureBadge Global CitizenBadge Work&Life Balance
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
February 9, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!