Senior GRC Analyst

2 weeks ago


Calgary, Canada Benevity Full time

Meet BenevityBenevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits. We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and moreBenevity is seeking a Senior Governance, Risk & Compliance (GRC) Analyst to elevate our security governance, risk, privacy, and regulatory posture. In this senior role, you will drive the execution, innovation, and continuous improvement of Benevity’s GRC program. You will lead compliance activities, conduct risk assessments, contribute to third-party risk management, respond to client due diligence requests, support FINTRAC/AML obligations, and influence policies and controls that strengthen trust with our clients, partners, and stakeholders.As a trusted advisor across teams, you will help ensure Benevity aligns with leading standards, privacy laws, and regulatory requirements while fostering a culture of security, compliance, and accountability. You’ll also mentor junior members of the team, helping to grow Benevity’s next generation of security and compliance professionals, with a focus on developing proactive and innovative approaches to GRC challenges.What you’ll do:Contribute to the development and maintenance of security and privacy policies, standards, and control frameworks aligned with ISO 27001, SOC 2, NIST, PCI DSS, GDPR, PIPEDA, FINTRAC, and other global regulationsSupport policy approvals, exception handling, and attestation processes while identifying opportunities for automation and process improvementsLead and execute enterprise risk assessments, including vendor and process-level reviewsMaintain and enhance the enterprise risk register, track remediation efforts, and support risk treatment planningSupport Benevity’s Third-Party Risk Management program including vendor assessments, monitoring, and remediation trackingLead readiness and response efforts for ISO 27001, SOC 2, PCI DSS, GDPR, and other audits and certificationsCoordinate evidence collection, control validation, and engagement with auditors and external assessorsUse GRC platforms to streamline audit, privacy, and compliance workflowsSupport Sales by responding to client inquiries, RFPs, and third-party risk requests related to security and privacyPartner with Sales and Client Success to deliver accurate, timely information that builds client trust and confidenceSupport cross-jurisdictional privacy compliance initiatives (GDPR, PIPEDA, CCPA/CPRA) in collaboration with Legal and Data GovernanceAssist with FINTRAC-related requirements, including AML/ATF risk assessments and reportingMonitor privacy, AML, and financial crime regulations and contribute to process alignment and compliance readinessPartner with business and technical teams to embed risk and compliance into key initiativesDeliver executive-ready reports, dashboards, and risk insights to inform leadership decision-makingLead the Security Awareness & Training program, including campaigns, training modules, and phishing simulationsCreate documentation, training, and awareness activities that promote a strong culture of security, privacy, and complianceMentor junior team members by providing guidance, feedback, and knowledge sharing to support their developmentWhat you’ll bring:5+ years of experience in cybersecurity, governance, risk, compliance, or privacy, ideally in a SaaS or high-growth environment.Strong knowledge of security, privacy, and regulatory frameworks including ISO 27001, NIST, SOC 2, PCI DSS, GDPR, PIPEDA, FINTRAC, and CCPA/CPRA.Hands‑on experience with GRC tooling (e.g., OneTrust, Hyperproof, SecurityPal, AuditBoard, Drata) to manage policies, risks, audits, privacy, and vendor risk workflows.Proven success in conducting risk assessments, managing vendor risk/TPRM, maintaining risk registers, and driving remediation.Experience supporting client due diligence processes (security questionnaires, RFPs, TPRM).Ability to clearly communicate risk, security, privacy, and regulatory concepts to both technical and non‑technical stakeholders.Strong organizational and project management skills with experience leading cross‑functional initiatives.A demonstrated interest and track record in leveraging automation and AI to streamline GRC processes and enhance efficiency.Certifications such as CISM, CRISC, CISSP, CISA, or CIPM/CIPP are highly valued.Discover your purpose at workWe’re not employees, we’re Benevity‑ites. From all locations, backgrounds and walks of life, who deserve more …Innovative work. Growth opportunities. Caring co‑workers. And a chance to do work that fills us with a sense of purpose.If the idea of working on tech that helps people do good in the world lights you up ... If you want a career where you’re valued for who you are and challenged to see who you can become …It’s time to join Benevity. We’re so excited to meet you.Where We WorkAt Benevity, we embrace a flexible hybrid approach to where we work that empowers our people in a way that supports great work, strong relationships, and personal well‑being. For those located near one of our offices, while there’s no set requirement for in‑office time, we do value the moments when coming together in person helps us build connection and collaboration. Whether it’s for onboarding, project work, or a chance to align and bond as a team, we trust our people to make thoughtful decisions about when showing up in person matters most.Join a company where DEIB isn’t a buzzwordDiversity, equity, inclusion and belonging are part of Benevity’s DNA. You’ll see the impact of our massive investment in DEIB daily — from our well‑supported employee resources groups to the exceptional diversity on our leadership and tech teams.We know that diverse backgrounds, experiences, skills and passions are what move our business and our people forward, so we're committed to creating a culture of belonging with equal opportunities for everyone to shine.That starts with a fair and accessible hiring process. If you want to feel seen, heard and celebrated, you belong at Benevity.Candidates with disabilities who may require accommodations throughout the hiring or assessment process are encouraged to reach out to accommodations@benevity.com. #J-18808-Ljbffr



  • Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada KOHO Full time

    A fintech company is seeking a Senior Governance, Risk and Compliance (GRC) Analyst to develop compliance programs and manage cybersecurity risks. The role is remote and focuses on automation and communication within cross-functional teams. Ideal candidates will have a background in risk management, experience with PCI DSS, and possess strong communication...


  • Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Surrey, Victoria, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Women in Payments Full time

    A financial technology company is seeking a Senior Governance, Risk and Compliance (GRC) Analyst to work remotely in Canada. You will be responsible for establishing a compliance program, documenting policies, and working collaboratively across teams to ensure regulatory requirements are met. The ideal candidate has a Bachelor's degree and experience in...

  • Senior GRC Analyst

    2 weeks ago


    Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Surrey, Victoria, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada KOHO Full time

    Senior GRC Analyst - Platform Technology and PaymentsAbout KOHO We’re on a mission to make financial services better for every Canadian. That means no hidden fees, no predatory interest rates – just financial products designed to help our users spend smart, save more, and build real wealth. We’re a performance organization with a strong heart: we care...


  • Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada 1Password Full time

    Senior Security Engineer, GRC AutomationThis role designs and implements automation, dashboards, and integrations that power Governance, Risk, and Compliance (GRC) operations. It is a remote opportunity within the US or Canada.What You’ll DoLead the implementation and integration of the GRC platform, ensuring it is fully operational across key systems and...


  • Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Vanta Full time

    Join to apply for the Senior Fullstack Software Engineer, GRC role at VantaJoin to apply for the Senior Fullstack Software Engineer, GRC role at VantaAt Vanta, our mission is to secure the internet and protect consumer data. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove...


  • Calgary, Canada Hexagon Full time

    Overview: Hexagon AB is looking for a** Senior Information Security Governance, Risk and Compliance Analyst** for a one year contract. As a member of the Corporate Information Security - Governance, Risk and Compliance team, you will report to Hexagon’s Director of Information Security - Governance, Risk and Compliance. The role will work closely with...


  • Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada D-Wave Quantum Inc. Full time

    A quantum computing leader is seeking a Senior Manager, Governance, Risk, and Compliance (GRC) to lead their global risk strategy. The role requires expertise in multiple regulatory frameworks and strong leadership skills. Responsibilities include defining compliance roadmaps, modernizing through automation, and collaborating with various departments to...

  • Senior GRC Analyst

    3 weeks ago


    Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada KOHO Full time

    About KOHOWe’re on a mission to make financial services better for every Canadian. That means no hidden fees, no predatory interest rates - just financial products designed to help our users spend smart, save more, and build real wealth. We’re a performance organization with a strong heart: we care deeply about outcomes, and everything ties back to our...

  • Senior GRC Analyst

    2 weeks ago


    Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Surrey, Victoria, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Women in Payments Full time

    About KOHO We’re on a mission to make financial services better for every Canadian. That means no hidden fees, no predatory interest rates - just financial products designed to help our users spend smart, save more, and build real wealth. We’re a performance organization with a strong heart: we care deeply about outcomes, and everything ties back to our...


  • Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada WELLSTAR Full time

    Who we are At WELLSTAR, we are committed to reshaping Canadian healthcare by leveraging technology to address the administrative burdens that pull physicians away from their true calling—patient care. Our mission is focused on supporting providers and patients, shifting the emphasis back to quality, time, and positive outcomes. With a comprehensive suite...