Product Manager — GRC / Compliance (Toronto)

Product Manager — GRC / Compliance (Toronto)

10 Sep
|
OBRYN GUARD
|
Toronto

10 Sep

OBRYN GUARD

Toronto

Product Manager — GRC / Compliance

OBRYN GUARD Inc. is building a continuous cyber risk and compliance platform designed for hospitality and multi-location organizations.

Our platform helps organizations continuously assess controls, collect evidence, identify compliance gaps, and maintain readiness across frameworks including PCI DSS, SOC 2, and ISO 27001.

We are looking for an exceptional Product Manager — GRC / Compliance who can become one of the deepest internal experts on the OBRYN GUARD product and help translate complex compliance requirements into a clear, scalable SaaS platform.

This is not a generic Product Manager position.

We need someone who understands GRC, security controls, compliance frameworks, evidence requirements, SaaS product development, and how organizations actually prepare for audits and assessments.

You will work directly with the Founder/CEO, Engineering, Security, Sales, and Customer Success to help shape what OBRYN GUARD becomes.

THE ROLEYou will own and help define the compliance-product layer of OBRYN GUARD.

Your responsibility is to understand:

- What each compliance framework requires
- What OBRYN GUARD can automatically verify
- What requires manual evidence or human validation
- What data must be collected from customer systems
- How evidence maps to individual controls
- How controls should be presented inside the platform
- How compliance gaps should be identified and prioritized
- How customers move from initial assessment to continuous readiness
- How Engineering should translate these requirements into product functionality

You should eventually understand the OBRYN GUARD platform end-to-end and be capable of explaining exactly how the product supports a customer's compliance and security-readiness program. WHAT YOU'LL OWNCompliance Framework ArchitectureHelp structure and maintain OBRYN GUARD's control library across:

- PCI DSS v4.0.1
- SOC 2
- ISO/IEC 27001
- Additional frameworks as the platform expands

Map requirements into clear product controls, evidence requirements, testing procedures, and remediation workflows. Product RequirementsTurn compliance and customer requirements into clear specifications for Engineering.

This includes

- User stories
- Product requirements
- Acceptance criteria
- Control logic
- Evidence requirements
- Workflow definitions
- Dashboard requirements
- Risk and compliance scoring
- Alerts and remediation workflows

Engineering should not have to interpret a 300-page compliance framework themselves. You should be able to translate it into something they can build.





Automated Control MonitoringWork with Engineering and Security to determine which controls can be evaluated through integrations such as:

- Microsoft Entra ID / Microsoft 365
- Google Workspace
- Okta
- MDM / endpoint management platforms
- EDR platforms
- SIEM platforms
- Cloud infrastructure
- Other enterprise security systems

Help define: Data Source → Security Signal → Control → Evidence → Finding → Remediation

Evidence ManagementDefine what constitutes acceptable evidence for each supported control.

Help design

- Automated evidence collection
- Manual evidence submission
- Evidence review
- Evidence expiration
- Historical evidence
- Audit trails
- Evidence ownership
- Continuous verification

Product RoadmapHelp determine what OBRYN GUARD should build next based on:
- Customer requirements
- Compliance requirements
- Security value
- Engineering effort
- Market demand
- Competitive positioning
- Commercial impact

You must be comfortable saying no to features that create complexity without meaningful customer value. Customer WorkflowHelp ensure the platform supports the full customer lifecycle:

Customer Onboarding → Environment Mapping → Baseline Assessment → Gap Identification → Remediation → Verification → Readiness Baseline → Continuous Monitoring → Evidence Collection → Reporting

Cross-Functional LeadershipYou will work closely with:

- Founder / CEO
- Head of Security
- Engineering
- Sales
- Customer Success
- Partnerships

You may also participate in selected customer or enterprise conversations where deeper product or compliance expertise is required. WHAT WE'RE LOOKING FORWe are looking for someone with strong experience in one or more of the following:
- GRC platforms
- Cybersecurity compliance
- Compliance automation
- Security assurance
- SaaS product management
- Audit readiness
- Security control testing
- Risk management
- Governance, Risk & Compliance consulting

You should understand how security controls operate beyond simply reading the framework. ROBUST KNOWLEDGE OFCandidates should have strong working knowledge of several of the following:
- PCI DSS
- SOC 2 / Trust Services Criteria




- ISO 27001
- Security control frameworks
- Identity and Access Management
- MFA
- Privileged access
- Security logging
- Vulnerability management
- Incident management
- Vendor risk
- Risk registers
- Evidence collection
- Audit preparation
- Security policies
- Continuous control monitoring

IDEAL BACKGROUNDStrong candidates may have previously worked at:
- A GRC SaaS company
- A compliance automation company
- A cybersecurity SaaS company
- A Big Four / security consulting firm
- A PCI / SOC 2 / ISO compliance practice
- An enterprise security or risk team

Experience with platforms such as Vanta, Drata, Secureframe, Sprinto, OneTrust, AuditBoard, Hyperproof, LogicGate, ServiceNow GRC, or comparable platforms is highly relevant. Experience building or managing a B2B cybersecurity or compliance SaaS product is highly desirable.

WHAT WILL MAKE YOU STAND OUTYou will stand out if you can look at a compliance requirement and immediately determine:

1. What the requirement is actually asking
2. What systems could provide evidence
3. What can be automatically verified
4. What requires manual validation
5. What the customer should see inside the product
6. What Engineering needs to build
7. What evidence an auditor or assessor would expect

That ability is extremely valuable to us. WHAT WE DO NOT WANTWe are not looking for someone who:
- Only manages Jira tickets
- Has never worked with security or compliance
- Cannot understand technical documentation
- Needs Engineering to define the product for them
- Treats compliance as a checklist
- Cannot communicate with both technical and non-technical teams
- Uses vague product language instead of making decisions

We want someone capable of becoming a true product authority inside the company. ABOUT OBRYN GUARDOBRYN GUARD is developing a browser-based platform that brings compliance monitoring, security evidence, risk visibility, and readiness workflows into one system.

Our focus is not simply helping organizations complete a compliance exercise once per year.

The objective is continuous assurance.

Organizations should be able to understand:

- Which controls are working
- Which controls are failing
- What evidence exists
- What has changed
- What needs remediation
- Where risk exists
- How prepared they are for an assessment

Our initial focus is the hospitality industry, with expansion into larger multi-location and regulated organizations. OBRYN GUARD Inc.

Automated Cyber Assurance. Built for hospitality.

📌 Product Manager — GRC / Compliance (Toronto)
🏢 OBRYN GUARD
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: product manager — grc / compliance (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: product manager — grc / compliance (toronto) / toronto