GRC Engineer (Ottawa)

GRC Engineer (Ottawa)

02 Sep
|
GRC Concierge
|
Ottawa

02 Sep

GRC Concierge

Ottawa

Location: Ottawa, ON or Calgary, AB

Job Type: Full-Time

Department: Service Delivery

About Us:

GRC Concierge is a trusted partner for SaaS, healthcare, and enterprise organizations, delivering managed security and compliance services that combine automation, engineering expertise, and white-glove client support.

We simplify complex frameworks like SOC 2, ISO 27001, HIPAA, NIST, and GDPR, while managing ongoing security operations such as vendor risk assessments, vulnerability scanning, and user onboarding/offboarding. Our mission is simple: help clients build trust, reduce risk, and stay audit-ready - without the operational burden.

Job Overview:

As a GRC Engineer at GRC Concierge, you’ll act as both a compliance advisor and an extension of our clients’ security teams. You’ll manage compliance automation platforms, implement and monitor security controls, and provide hands-on support across multiple clients and frameworks.

This role is perfect for someone who enjoys consulting across industries, thrives in a multi-client setting, and wants to balance governance expertise with hands-on technical execution.

Key Responsibilities:

- Compliance Implementation: Design and oversee controls for frameworks like SOC 2, ISO 27001, HIPAA, NIST, and GDPR.
- Automation Management: Configure and optimize compliance automation tools (Vanta, Drata, and GRC Concierge’s own platforms).
- Security Operations: Support clients with vendor risk assessments, vulnerability scans, and onboarding/offboarding workflows.
- Continuous Monitoring: Track client ongoing compliance posture, ensure evidence collection, and proactively close gaps before audits.
- Policy Development: Draft and refine security policies, standards, and procedures tailored to client needs.




- Audit Readiness: Prepare clients for SOC 2 Type I/II, ISO, and HIPAA audits through evidence collection, mock audits, and direct collaboration with audit partners.
- Education & Training: Deliver training to client stakeholders on compliance best practices and regulatory changes.

Qualifications:

Education

- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).

Experience

- 5+ years in compliance, cybersecurity, or consulting roles.
- Experience in MSP/MSSP or professional services environments preferred.
- Familiarity with frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, and NIST.
- Ability to manage compliance for multiple clients simultaneously across different frameworks.

Certifications (Nice to Have)
- CISSP, CISA, CISM, CCSK, or similar is a plus.

Technical Skills

- Knowledge of SaaS and cloud platforms (AWS, Azure, GCP).
- Experience with compliance automation platforms (Vanta, Drata, etc.).
- Understanding of vulnerability management, vendor risk, and IT governance.

Soft Skills

- Excellent communication and consulting skills for client-facing work.
- Ability to translate technical requirements into business value.
- Project management skills with a proven ability to juggle multiple clients and deadlines.
- Collaborative, solutions-driven mindset.

Why GRC Concierge?

- At GRC Concierge, you won’t just “check boxes” - you’ll help clients transform compliance into a business enabler. You’ll work with a tight-knit, fast-growing team where your expertise and ideas directly shape our clients’ success. If you want to solve real problems, build lasting relationships, and grow your career in compliance and security, we want to meet you.

📌 GRC Engineer (Ottawa)
🏢 GRC Concierge
📍 Ottawa

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: grc engineer (ottawa) / ottawa

Subscribe to this job alert:

Get the latest job offers by email for: grc engineer (ottawa) / ottawa