
GRC/Compliance Lead
Posted Sep 3

Posted Sep 3
This is a fully remote position, open to applicants in Canada.
• Collaborate with an external software development organization as a member of Inviso’s delivery team.
• Assist in establishing practical governance, risk, and compliance practices that are favorable to engineering for an enterprise AI platform.
• Define, manage, and enhance a compliance program for a multi-tenant enterprise platform that caters to regulated and mission-critical customer environments.
• Concentrate on SOC 2 and ISO readiness, controls, evidence collection, customer security documentation, audit preparation, data handling, and compliance-by-design.
• Collaborate with engineering, security, product teams, auditors, customer security teams, and client stakeholders.
• Mitigate risk, enhance customer trust, and facilitate reliable delivery without introducing unnecessary friction.
• Proven experience in owning or supporting a security, governance, risk, or compliance program within a B2B SaaS, platform, or enterprise software setting.
• Familiarity with SOC 2, ISO 27001, or comparable compliance frameworks.
• Capability to define controls, map requirements, gather evidence, identify gaps, and assist in audit readiness.
• Experience in preparing security documentation for customers, responding to security questionnaires, drafting DPAs, policies, or compliance materials.
• Ability to collaborate with engineering and security teams to ensure that controls are practical, repeatable, and conducive to automation.
• Knowledge in advising on data handling, retention, access control, regulatory obligations, and customer assurance requirements.
• Proficient in preparing for and supporting audits, customer security reviews, and compliance assessments.
• Strong skills in documentation, organization, follow-through, and stakeholder management.
• Excellent communication and collaboration abilities suitable for client-facing consulting roles.
• Pragmatic approach with the capability to support delivery while upholding credible compliance standards.
• Experience guiding a company or product through the SOC 2, ISO 27001, or a similar certification process.
• Background in automating evidence collection or integrating compliance into engineering workflows.
• Understanding of GDPR or other significant data protection and privacy regulations.
• Experience with AI governance, responsible AI practices, model risk, data governance, or compliance for AI-enabled products.
• Background in enterprise-scale B2B SaaS, regulated customer environments, or mission-critical software.
• Relevant certifications in compliance, audit, security, privacy, or risk are advantageous.
• Annual $2,000 training allowance.
• Paid time off.
• Paid holidays.
• Additional benefits.
biBerk Business Insurance
Doppel
PingWind Inc. (SDVOSB)
The Standard
Get handpicked remote jobs straight to your inbox weekly.