Governance, Risk, & Compliance Manager

Inovatec CA,
CA$110,000 - CA$125,000Remote

About The Position

Inovatec is hiring a Governance, Risk & Compliance (GRC) Manager to own the day-to-day execution and continued maturity of our security, privacy, and compliance program. This role is central to our shift from point-in-time audits to continuous, evidence-based control monitoring, anchored in our GRC platform, and to keeping Inovatec audit-ready year-round across various compliance frameworks and providing a high level of assurance to our clients. You will lead a small, focused team, directly managing our Internal Auditor / GRC Specialist, and the two of you will work shoulder-to-shoulder across all governance, risk, audit, and compliance efforts. You will operationalize governance, run our risk management lifecycle, manage third-party risk, and coordinate internal and external audits. Reporting to the Head of Cybersecurity & Compliance, you will partner closely with Infrastructure, Product Engineering, IT, Legal, Finance, and People & Culture. We are looking for a candidate ideally based in Ontario, Canada.

Requirements

  • 6–10+ years in governance, risk, and compliance, information security, or IT audit, ideally in a multi-tenant SaaS or regulated (financial services) environment.
  • Direct people-management or team-lead experience, or clear readiness to manage and develop one direct report.
  • Hands-on experience running or maturing programs across SOC 1/2, and ISO 27001/27018, with familiarity of emerging AI frameworks (ISO 42001, CSA AI).
  • Practical experience with a GRC / continuous-compliance platform (Vanta preferred) and control-monitoring automation.
  • Strong grasp of risk assessment methodology, control frameworks, and third-party / vendor risk management (BitSight or similar a plus).
  • Experience coordinating external audits and managing remediation of findings to closure.
  • Excellent documentation discipline and evidence rigor, able to translate control requirements into clear, defensible artifacts.
  • Strong cross-functional communication, comfortable engaging Engineering, IT, Legal, Finance, executives, clients, and auditors.

Nice To Haves

  • Experience working with regulated financial-services clients, SaaS platforms, or enterprise B2B environments is strongly preferred.
  • Relevant certifications (e.g., CISA, CRISC, CISSP, ISO 27001 Lead Auditor / Implementer).
  • Privacy program experience (PIPEDA, Quebec Law 25, ISO 27018).
  • Familiarity with the Microsoft / Azure security stack (Entra ID, Defender, Sentinel) as it relates to control evidence.
  • Experience supporting M&A / investor due diligence.

Responsibilities

  • Directly manage the Internal Auditor / GRC Specialist, owning coaching, priorities, development, and day-to-day workload, and partnering closely on every governance, risk, audit, and compliance effort.
  • Set clear expectations and a steady operating cadence (1:1s, planning, quarterly goals) so audit and compliance work is delivered predictably and to a high standard.
  • Champion intent-based leadership, growing the autonomy, judgement, and technical depth of your report while ensuring shared coverage and no single points of failure.
  • Serve as a hands-on working manager who leads by doing, shares the workload, and steps into complex assessments and audits alongside your report.
  • Own and continuously mature Inovatec’s GRC program across frameworks like SOC 1 & SOC 2 Type II, ISO 27001, ISO 27018 and TISAX.
  • Drive the transition from point-in-time audits to ongoing control monitoring, completing migration of GRC processes into the GRC platform and maintaining ≥90% of controls under continuous monitoring.
  • Automate evidence collection across active frameworks (targeting ≥80% reduction in manual evidence) and maintain a real-time compliance posture dashboard.
  • Manage the policy lifecycle, covering authoring, review cadence, versioning, and employee policy acknowledgment (≥95% target).
  • Own and mature the privacy, compliance, and security awareness training program, ensuring it remains aligned to company policies, client obligations, and applicable compliance frameworks.
  • Support AI compliance readiness, including CSA AI validation and ISO 42001 (AI Management System) compliance.
  • Operate the enterprise risk lifecycle (identification, scoring, categorization, treatment, and workflows aligned to Inovatec’s approved risk policies), with monthly risk snapshots for historical tracking and audit-ready reporting.
  • Maintain the risk register and support quarterly compliance health reviews and board-level risk reporting.
  • Track remediation against SLAs (e.g., <15-day average remediation for compliance drift alerts) and drive closure of audit findings and nonconformities.
  • Contribute to the fraud risk program and segregation-of-duties controls (prevention, detection, response, deterrence).
  • Run the Vendor Risk Management (VRM) program end-to-end, covering onboarding, tiering, security risk assessments, continuous monitoring, SOC report reviews, and offboarding.
  • Automate vendor risk assessments for 100% of critical vendors and publish a vendor risk dashboard showing tier coverage and remediation status.
  • Enforce third-party information security requirements and confidentiality obligations prior to engagement.
  • Coordinate internal and external audits, managing scope, evidence, fieldwork logistics, and corrective actions in close partnership with the Internal Auditor / GRC Specialist.
  • Maintain the Statement of Applicability, control mappings, and audit calendar, ensuring zero missed compliance deadlines for external audits or certifications.
  • Support client due diligence, and security questionnaires and requests with accurate, evidence-backed responses.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service