BWH Hotels Logo

BWH Hotels

GRC Analyst - Hybrid AZ

Posted 3 Hours Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in AZ
Mid level
Remote or Hybrid
Hiring Remotely in AZ
Mid level
Support governance, risk, and compliance programs to protect data and IT assets. Manage security policy and standards, coordinate evidence collection and audit readiness for PCI DSS, SOX, privacy and other frameworks, track remediation, conduct control reviews, liaise with auditors and stakeholders, and maintain compliance documentation and reporting.
The summary above was generated by AI

Join BWH Hotels – Where Passion Meets Purpose

At BWH® Hotels, we don't just offer employment opportunities, we create opportunities to be part of something extraordinary. As a global leader in hospitality for nearly 80 years, our vision is to inspire travel through unique experiences. Joining our corporate team means becoming part of a dynamic and inclusive community that values innovation, collaboration, and making a meaningful impact in the travel industry.

Headquartered in Phoenix, Arizona, BWH Hotels boasts a powerful portfolio of 18 brands, including WorldHotels™, Best Western® Hotels & Resorts, and SureStay Hotels®, with approximately 4,300 hotels in over 100 countries. We take pride in our top-ranking employee engagement scores and foster a workplace culture where your contributions truly matter. Join us and be part of a team that's shaping the future of hospitality!

Job Purpose:

Ensures the confidentiality, integrity, and availability of Company data and information technology assets by supporting governance, risk, and compliance activities, including security policy and standards management, risk management, disaster recovery coordination, audit readiness, and regulatory compliance. This role supports PCI DSS, SOX, privacy, and broader cybersecurity compliance activities across the organization.

Key Responsibilities:

  • The ideal candidate will be able to build rapport and credibility with internal stakeholders, business partners, member hotel representatives, and technology teams to support effective governance, risk, and compliance outcomes. Excellent communication and interpersonal skills are required to coordinate evidence requests, explain control expectations, and drive timely follow-through.
  • Demonstrated experience supporting compliance frameworks and control environments such as PCI DSS v4.0.1, NIST, COBIT, ISO 27001, SOX, privacy regulations, and related cybersecurity standards.
  • Coordinate with internal stakeholders and external auditors to maintain current documentation for control scoping, evidence collection, testing support, remediation tracking, and validation of IT and cybersecurity controls.
  • Work with stakeholders to fulfill evidence requests within committed timelines and ensure evidence is complete, accurate, and mapped to applicable control requirements.
  • Conduct recurring control reviews with stakeholders to identify gaps, track remediation progress, and provide actionable advisement to management.
  • Review audit findings, control gaps, and compliance risks; partner with control owners to document remediation plans, track progress, and escalate delays or blockers as appropriate.
  • General understanding of Sarbanes-Oxley (SOX) compliance requirements, IT General Controls, and audit evidence expectations.
  • Thorough knowledge of PCI-related standards and guidance, including PCI DSS v4.0.1, ASV requirements, payment security documentation, and software security requirements where applicable.
  • Thorough understanding of applicable privacy and data protection requirements, including GDPR, the California Consumer Privacy Act (CCPA), and related organizational privacy obligations.
  • Familiarity with a broad range of IT and information security products and technologies such as GRC platforms, central logging systems, file integrity monitoring, vulnerability management, endpoint security, and cloud security tools.
  • Excellent documentation, communication, organization, and follow-through skills, with the ability to coordinate multiple evidence, audit, and remediation activities at the same time.

Preferred Experience and Education:

  • Bachelor's or Master's degree in a computer or information management field or related experience preferred.
  • CISSP, CISA, CISM, CRISC, or equivalent security, audit, risk, or compliance certification preferred.
  • 3-5 years’ experience in an information security compliance, audit, governance, or risk management role with hands-on experience in compliance initiatives including, but not limited to:
    • PCI DSS v4.0.1
    • Software security, secure software lifecycle, or application security compliance requirements where applicable
    • SOX-404 and IT General Controls
    • EU-GDPR, CCPA, and related privacy or data protection requirements
  • Strong analytical and problem-solving skills with the ability to interpret control requirements, identify risk, and function as a change agent.
  • Intermediate to advanced expertise in Excel, PowerPoint, reporting, documentation, evidence tracking, and use of systems or repositories used to manage audit and compliance artifacts.
  • Demonstrated experience working within a team in a fast-paced environment with competing audit, compliance, and operational priorities.
  • Understanding of security metrics, compliance reporting, evidence tracking, and dashboard creation for management review and control-owner visibility.
  • Demonstrated ability to create, maintain, and present security awareness, compliance, or control-owner training content a plus.

Work Location and Schedule

This is a hybrid position, requiring onsite presence Mondays, Wednesdays and Fridays at our Global Operations Center, with the option to work remote on Tuesdays and Thursdays. This hybrid model fosters intentional collaboration, teamwork, connection, and productivity, while still providing flexibility and work life balance. The office address is 20400 N 29th Avenue, Phoenix, Arizona 85027.

This position is not eligible for immigration sponsorship. 

Benefits Summary for Full-Time Employees  

· Medical/Dental/Vision available day one 

· Vacation/Sick- accruals start day one 

· Paid company holidays and personal holidays to celebrate what’s important to you  

· 401K - company contribution and match (U.S.) 

· Registered Retirement Savings Plan (RRSP) – company contribution and match (Canada) 

· Employee discounts/hotel discounts 

· Free financial and health wellness programs 

· Tuition Reimbursement 

Equal Employment Opportunity

BWH Hotels (the "Company") maintains a policy of equal employment opportunity for all employees and qualified applicants for employment without regard to race (including hair textures and hair styles associated with race), color or pigmentation, religion, religious creed (including religious dress and grooming practices), national origin, ancestry, alienage or citizenship status, caste, age, disability, gender, gender identity or expression, sex, sexual orientation, LGBTQIA+ individuals, height, weight, pregnancy status, childbirth or related medical conditions, genetic information, uniformed service or veteran status, marital status, or any other characteristic protected by applicable federal, state, provincial, or local laws. The Company’s equal employment opportunity policy applies to all aspects of employment with the Company, including, but not limited to, hiring, promotion, transfer, benefits, discipline, and termination. 

Similar Jobs

An Hour Ago
Remote or Hybrid
Mid level
Mid level
Fintech • Financial Services
Full Stack Software Developer responsible for designing, building, testing, and deploying scalable member-facing and internal applications. Work includes building APIs, database components, cloud-native solutions, CI/CD pipelines, and adopting AI-assisted development practices while collaborating in an Agile environment to improve member digital experiences.
Top Skills: .NetAmazon Web Services (Aws)APIsAzureAzure Devops ServicesC#Ci/CdCloud-Native ApplicationsGitGithub ActionsGoogle Cloud Platform (Gcp)JavaJavaScriptJenkinsPowershellPythonReactSQLTeamcityTest-Driven Development (Tdd)Typescript
An Hour Ago
Remote or Hybrid
Expert/Leader
Expert/Leader
Hospitality
Lead the enterprise AI roadmap and delivery, directing a small technical team to prioritize, build, and govern AI capabilities. Drive product strategy, value-based prioritization, end-to-end delivery, governance, and adoption while aligning stakeholders and reporting outcomes to executives. Recruit and develop talent, manage budgets and risks, and champion responsible-AI and platform decisions (build vs buy).
Top Skills: ClaudeCopilotKore.AiLlm
3 Hours Ago
In-Office or Remote
Junior
Junior
Professional Services
Provide remote technical support via chat and email, manage tickets with a 24-hour SLA, reproduce and troubleshoot issues using logs and browser tools, participate in engineering planning, run support retrospectives, optimize AI chatbot and support workflows, maintain documentation in GitBook, and improve Zendesk/Linear systems while protecting sensitive data and meeting KPIs.
Top Skills: Ai ToolsCrm SystemsGitbookGrafanaJSONLinearZendesk

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account