
GRC/Compliance Lead
Posted Sep 2

Posted Sep 2
This is a fully remote position, open to applicants in Canada.
• Assist an external software development organization as a member of Inviso’s delivery team.
• Aid in the establishment of practical, engineering-oriented governance, risk, and compliance practices for an enterprise AI platform.
• Develop, implement, and enhance a compliance program for a multi-tenant enterprise platform catering to regulated and mission-critical customer environments.
• Provide support for SOC 2 and ISO readiness initiatives.
• Oversee controls, evidence gathering, customer security documentation, audit preparation, data management, and ensure compliance-by-design principles.
• Collaborate with engineering, security, product teams, auditors, customer security personnel, and client stakeholders.
• Minimize risk, enhance customer trust, and facilitate credible delivery without introducing unnecessary friction.
• Proven experience in owning or assisting with a security, governance, risk, or compliance program within a B2B SaaS, platform, or enterprise software context.
• Familiarity with SOC 2, ISO 27001, or comparable compliance frameworks.
• Proficiency in defining controls, mapping requirements, collecting evidence, identifying gaps, and ensuring audit readiness.
• Experience in creating customer-facing security documentation, security questionnaires, Data Processing Agreements (DPAs), policies, or compliance materials.
• Capability to work alongside engineering and security teams to make controls practical, repeatable, and conducive to automation.
• Expertise in advising on data handling, retention, access control, regulatory obligations, and customer assurance requirements.
• Competence in preparing for and supporting audits, customer security evaluations, and compliance assessments.
• Strong skills in documentation, organization, follow-through, and stakeholder management.
• Excellent communication and collaboration skills suited for client-facing consulting roles.
• A pragmatic approach with the ability to support delivery while upholding credible compliance standards.
• Experience in guiding a company or product through SOC 2, ISO 27001, or a similar certification process.
• Background in automating evidence collection or integrating compliance within engineering workflows.
• Knowledge of GDPR or other significant data protection and privacy regulations.
• Experience in AI governance, responsible AI practices, model risk management, data governance, or compliance for AI-enabled products.
• Familiarity with enterprise-scale B2B SaaS, regulated customer environments, or mission-critical software.
• Relevant certifications in compliance, audit, security, privacy, or risk are advantageous.
• Annual training allowance of $2,000.
• Paid time off.
• Paid holidays.
• Additional benefits.
RTX
EnergyHub
Johnson & Johnson
Johnson & Johnson
Get handpicked remote jobs straight to your inbox weekly.