Analyste GRC / GRC Analyst

ExploranceMontreal, QC
Onsite

About The Position

The Governance, Risk and Compliance Analyst coordinates and executes the day-to-day activities of Explorance's governance, risk, compliance, information security assurance, and operational privacy programs. The role maintains compliance documentation, coordinates control testing and audits, administers risk and remediation records, manages customer assurance requests, supports third-party risk reviews, and produces reliable GRC reporting and evidence. The analyst works across Product, Engineering, Information Technology, Security, Human Resources, Sales, Support, Finance, and other teams. The role is central to maintaining continuous audit readiness, customer trust, security and privacy compliance maturity, and operational resilience. The analyst exercises independent judgment within approved policies and frameworks and escalates material risks, nonstandard commitments, regulatory interpretations, significant exceptions, and time-sensitive concerns promptly.

Requirements

  • Three to five years of relevant experience in governance, risk and compliance, information security compliance, technology risk, IT audit, privacy operations, security assurance, or a related field.
  • Post-secondary education in cybersecurity, information technology, audit, risk management, privacy, business, law, or a related discipline, or an equivalent combination of education and relevant professional experience.
  • Practical experience with control testing, audit evidence, compliance monitoring, risk registers, issue management, remediation tracking, customer assurance, or vendor reviews.
  • Working knowledge of one or more recognized frameworks, such as ISO 27001, SOC 2, NIST Cybersecurity Framework, HIPAA, or a comparable framework and its control and evidence requirements.
  • Experience drafting or maintaining policies, standards, procedures, control descriptions, audit documentation, and reusable response materials.
  • Strong analytical, documentation, organizational, prioritization, and follow-up skills.
  • Ability to manage multiple concurrent activities, deadlines, and stakeholders with limited supervision.
  • Ability to distinguish matters that can be handled operationally from those requiring escalation, regulatory interpretation, legal review, or material-risk approval.
  • Professional proficiency in French and English, spoken and written, to support global customers, auditors, and business stakeholders.
  • High integrity, discretion, sound judgment, and respect for confidential information.

Nice To Haves

  • Experience in a SaaS, cloud software, technology, education technology, or data-intensive organization.
  • Direct experience supporting a SOC 2 audit or comparable assurance program.
  • Familiarity with PIPEDA, GDPR, Quebec Law 25, privacy impact assessments, and data-protection requirements.
  • Experience with third-party risk management, penetration-test remediation, vulnerability governance, business continuity, disaster recovery, or incident-response exercises.
  • Experience with GRC platforms, compliance automation tools, privacy-management tools, Jira, or structured workflow systems.
  • Exposure to AI governance, data residency, responsible AI assessments, or governance of AI-enabled SaaS services.
  • Professional proficiency in French, spoken and written.
  • A relevant certification or progress toward one, such as CISA, CRISC, CISM, Security+, ISO 27001 Lead Implementer, or a comparable credential.

Responsibilities

  • Governance and GRC Program Operations
  • Risk Management
  • Control Validation, Internal Audit, and Compliance Monitoring
  • External Audit and Assurance
  • Customer Trust and Sales Support
  • Third-Party Risk Management
  • Privacy and Regulatory Support
  • Security Awareness and Operational Resilience
  • Metrics, Reporting, and Stakeholder Coordination
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service