30 Sep
|
Shift Technology
|
Toronto
30 Sep
Shift Technology
Toronto
Who you are
- 7+ years of proven experience in a GRC, IT Audit, Security Assurance, or Information Security role
- Bachelor’s Degree in a relevant field or equivalent work experience
- Professional certifications such as CIPP/E, CIPP/US, CIPT CISA, CISM, CRISC, or CISSP are highly desirable
- Direct experience of delivery in highly regulated industries, i.e financial services, healthcare
- Direct experience managing or supporting formal audit and certification processes from start to finish
- Deep knowledge of security and privacy frameworks is required (e.g., ISO 27001, ISO27701, SOC 2 Type II, HITRUST, NIST CSF)
- Strong knowledge of global privacy and healthcare regulations (e.g., GDPR, HIPAA)
- Working knowledge of AI regulations, frameworks, and standards (e.g., EU AI Act, ISO 42001)
- Working knowledge of business continuity, disaster recovery, and incident response planning, including plan structure, exercise and test methodologies
- Hands-on experience with modern GRC management tools, preferably Drata - connecting integrations, tuning automated evidence collection and monitoring tests, and building custom controls and frameworks
- Exceptional communication and presentation skills, with the ability to translate complex compliance requirements into clear business guidance
- Robust stakeholder management skills with the ability to influence and align teams without direct authority
- Highly organized with strong project management skills, capable of managing multiple audits and assessments simultaneously
- An analytical mindset with the ability to balance regulatory requirements with business objectives and priorities
What the job involves
- As a Senior GRC Analyst, you will be a cornerstone of Shift’s security program, responsible for developing, maintaining,
and assessing our integrated security and privacy management framework
- You will manage our compliance with key industry standards, lead risk assessments, oversee our third-party security assurance program, and support TrustOps efforts for customer collateral, questions, contract reviews, and due diligence
- This role is critical for ensuring that Shift meets its regulatory obligations and maintains the trust of our customers
- As part of the Information Security department, this role reports to the GRC Lead
- Governance & Policy Management:
- Act as a lead contact to translate Shift’s global information security expectations into actionable policies, standards, and procedures
- Promote a mind-set of security and compliance across the organization, transferring knowledge of standards and acting as a subject matter expert (SME)
- Contribute to the development and support of the security awareness program to ensure it aligns with policy and compliance requirements
- Partner with the Data Protection Officer to develop and maintain privacy policies, data handling standards, and public-facing privacy notices in line with privacy laws and global regulations such as GDPR
- Risk Management & Security Assurance:
- Develop and maintain the security assurance plan, ensuring key controls are effectively designed and implemented to meet Shift policies and standards
- Improve the third-party information security assurance and continuous assessment process
- Identify key risk areas in collaboration with engineering and business teams and facilitate security control evaluations and testing
- Review architectural designs and new initiatives to ensure they align with security policies and effectively mitigate risk
- Proactively identify potential information security GRC problem areas and execute plans to improve the overall assurance workflow
- Support and facilitate Data Protection Impact Assessments (DPIAs) for new products and initiatives
- Compliance & Audits:
- Manage and coordinate internal and external audits for certifications such as ISO 27001 and SOC 2 Type II
- Perform analysis and compile documentation and evidence to demonstrate the compliance level of systems, services, and controls
- Work with internal teams to manage the remediation of audit findings and track them to closure
- Support legal and stakeholder teams in responding to Data Subject Access Requests (DSARs)
- Third-Party Risk Management:
- Develop, execute, and improve the third-party information security assurance and continuous assessment process
- Communicate with third parties and suppliers to conduct risk assessments, review their security posture, and manage the remediation of identified issues
The application process
- First fit call with our Talent Acquisition Manager
- Team fit call with the Hiring Manager
- Tech round with the Team
- A final interview with our CISO
Benefits
- Flexible remote and hybrid working options
- Competitive Salary and a variable component tied to personal and company performance
- Company equity
- Generous PTO and paid holidays
- Parental leave opportunities
- Extensive mental health benefits provided via our global Employee Assistance Program
- Paid volunteering time - 16 hours annually
📌 Senior GRC Analyst (Toronto)
🏢 Shift Technology
📍 Toronto