GRC Lead

location_onCanadapayments$160,000 – $230,000/yrschedule8 hours ago
homeWork style:Remote
trending_upExperience level:Lead
badgeEmployment:Full-time
historyMinimum experience:2+ years
Apply Nowopen_in_new

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Lead based in Canada.

This is a senior, high-impact opportunity to build and lead a Governance, Risk, and Compliance function in a fast-moving, remote-first technology environment. You will be the primary owner of customer security assurance, compliance programs, audits, and risk follow-through. The role combines strategic judgment with hands-on execution, requiring you to translate complex security requirements into practical decisions and measurable actions. You will work closely with Engineering, Security, IT, Legal, and customer-facing teams to strengthen the organization’s security posture. AI and automation will play an important role in accelerating customer reviews, evidence collection, and recurring compliance workflows. With significant autonomy and room to shape the function, this role is ideal for a GRC professional who enjoys building scalable processes from the ground up.

Accountabilities

  • Own customer security reviews, including security questionnaires, due diligence requests, and customer security calls, using AI-assisted workflows to accelerate research and drafting while applying rigorous judgment to ensure accuracy.
  • Analyze unfamiliar or complex security questions and collaborate with the appropriate technical experts to provide precise, credible, and well-supported responses.
  • Help teams evaluate customer security requirements, vendor risks, compliance gaps, and other risk-related concerns, ensuring decisions are clearly documented, appropriately owned, and followed through to completion.
  • Maintain accurate and approved security responses and supporting evidence, using AI and automation to identify inconsistencies, outdated information, and differences across products, configurations, and planned capabilities.
  • Own SOC 2 and ISO 27001 compliance programs, including audit preparation, control management, external partner coordination, gap assessment, remediation, and ongoing effectiveness between audits.
  • Establish priorities for external compliance and audit partners, evaluate the quality of their work, and ensure identified gaps are addressed efficiently.
  • Evaluate potential new compliance programs based on customer requirements, target markets, implementation effort, and ongoing maintenance costs.
  • Track security and compliance commitments with clear owners, deadlines, and follow-through mechanisms to ensure remediation efforts are completed.
  • Build automation, self-service resources, and scalable processes that reduce repetitive GRC work and increase the efficiency of a lean team.
  • Identify recurring customer security questions and translate those patterns into improvements to documentation, controls, processes, and product capabilities.
  • Partner cross-functionally with Engineering, Security, IT, Legal, and customer-facing teams to continuously strengthen security and compliance practices.
  • Requirements

    • Proven experience personally owning a compliance program or leading a significant audit cycle, combined with hands-on experience managing customer security reviews.
    • Strong understanding of governance, risk, and compliance principles, with practical experience across security assurance, audits, controls, and remediation.
    • Demonstrated ability to make sound risk-based decisions, articulate tradeoffs, and determine when risks should be accepted, mitigated, or escalated.
    • Strong technical curiosity and the ability to engage credibly with engineers on topics such as data flows, access controls, cloud infrastructure, and data storage.
    • Experience with SOC 2 and ISO 27001 programs, including control management, evidence collection, audit preparation, and remediation activities.
    • Strong AI fluency and attention to detail, with the ability to build or leverage AI-assisted workflows while identifying unsupported, inaccurate, or misleading outputs.
    • Excellent written and verbal communication skills, particularly the ability to explain security posture and compliance requirements clearly to customers and internal stakeholders.
    • Strong customer-facing skills and the ability to communicate transparently when requirements are complex or specific capabilities are not yet available.
    • High ownership, urgency, and accountability, with the ability to make progress despite incomplete information and consistently close open loops.
    • A builder-oriented mindset, with demonstrated experience simplifying processes, automating repetitive work, developing self-service resources, or creating more efficient ways to meet security and compliance requirements.
    • Ability to operate autonomously in a fast-paced environment and collaborate effectively across technical, legal, security, IT, and customer-facing functions.
    • Experience in a senior individual contributor or hands-on management capacity is welcome; demonstrated impact and growth potential are valued more highly than a specific number of years of experience.
    • Benefits

      • Competitive annual salary of $160,000–$230,000 USD, location-independent in accordance with the remote-first policy.
      • Meaningful equity compensation.
      • Fully remote opportunity across North America.
      • High degree of autonomy and ownership in building a GRC function from the ground up.
      • Opportunity to directly shape customer security assurance, compliance strategy, risk management, and audit programs.
      • Exposure to AI-powered workflows and automation designed to increase the impact and efficiency of a lean GRC function.
      • Close collaboration with Engineering, Security, IT, Legal, and customer-facing teams.
      • Opportunity to grow the GRC function and potentially develop into a management role as the organization scales.
      • Fast-paced environment focused on practical decision-making, continuous improvement, and measurable impact.
How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

Skills mentioned


Recruitment
Canada

Jobgether is a Belgium-based, AI-powered remote-work job platform founded in 2020 in Brussels. It aggregates and enriches large volumes of remote and flexible job listings from many employers and matches candidates to roles; it is a job aggregator rather than the hiring employer.

Apply for this job

Use the application link supplied with this listing to apply to jobgether. Check the destination before entering personal information.

Apply Nowopen_in_new