Jobs › Toronto › Senior GRC Analyst - Central or Eastern time, US or Canada
Senior GRC Analyst - Central or Eastern time, US or Canada
Shift Technology is hiring for the job of Senior GRC Analyst - Central or Eastern time, US or Canada, Toronto, ON (On-site). This is a Compliance job in the governance, risk, and compliance field. Review the full details below and apply directly with Shift Technology.
Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure, empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve.
Your browser does not support the video tag.
Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.
Learn more at www.shift-technology.com
As a Senior GRC Analyst, you will be a cornerstone of Shift’s security program, responsible for developing, maintaining, and assessing our integrated security and privacy management framework. You will manage our compliance with key industry standards, lead risk assessments, oversee our third-party security assurance program, and support TrustOps efforts for customer collateral, questions, contract reviews, and due diligence. This role is critical for ensuring that Shift meets its regulatory obligations and maintains the trust of our customers. As part of the Information Security department, this role reports to the GRC Lead.
RESPONSIBILITIES Governance & Policy Management
- Act as a lead contact to translate Shift’s global information security expectations into actionable policies, standards, and procedures.
- Promote a mind-set of security and compliance across the organization, transferring knowledge of standards and acting as a subject matter expert (SME).
- Contribute to the development and support of the security awareness program to ensure it aligns with policy and compliance requirements.
- Partner with the Data Protection Officer to develop and maintain privacy policies, data handling standards, and public-facing privacy notices in line with privacy laws and global regulations such as GDPR. Risk Management & Security Assurance
- Develop and maintain the security assurance plan, ensuring key controls are effectively designed and implemented to meet Shift policies and standards.
- Improve the third-party information security assurance and continuous assessment process.
- Identify key risk areas in collaboration with engineering and business teams and facilitate security control evaluations and testing.
- Review architectural designs and new initiatives to ensure they align with security policies and effectively mitigate risk.
- Proactively identify potential information security GRC problem areas and execute plans to improve the overall assurance workflow.
- Support and facilitate Data Protection Impact Assessments (DPIAs) for new products and initiatives. Compliance & Audits
- Manage and coordinate internal and external audits for certifications such as ISO 27001 and SOC 2 Type II.
- Perform analysis and compile documentation and evidence to demonstrate the compliance level of systems, services, and controls.
- Work with internal teams to manage the remediation of audit findings and track them to closure.
- Support legal and stakeholder teams in responding to Data Subject Access Requests (DSARs) Third-Party Risk Management
- Develop, execute, and improve the third-party information security assurance and continuous assessment process.
- Communicate with third parties and suppliers to conduct risk assessments, review their security posture, and manage the remediation of identified issues. SKILLS & BACKGROUND Experience & Education
- 7+ years of proven experience in a GRC, IT Audit, Security Assurance, or Information Security role.
- Bachelor’s Degree in a relevant field or equivalent work experience.
- Professional certifications such as CIPP/E, CIPP/US, CIPT CISA, CISM, CRISC, or CISSP are highly desirable.
- Direct experience of delivery in highly regulated industries, i.e financial services, healthcare.
- Direct experience managing or supporting formal audit and certification processes from start to finish. Knowledge & Frameworks
- Deep knowledge of security and privacy frameworks is required (e.g., ISO 27001, ISO27701, SOC 2 Type II, HITRUST, NIST CSF)
- Strong knowledge of global privacy and healthcare regulations (e.g., GDPR, HIPAA)
- Working knowledge of AI regulations, frameworks, and standards (e.g., EU AI Act, ISO 42001)
- Working knowledge of business continuity, disaster recovery, and incident response planning, including plan structure, exercise and test methodologies.
- Hands-on experience with modern GRC management tools, preferably Drata - connecting integrations, tuning automated evidence collection and monitoring tests, and building custom controls and frameworks. Core Competencies
- Exceptional communication and presentation skills, with the ability to translate complex compliance requirements into clear business guidance.
- Strong stakeholder management skills with the ability to influence and align teams without direct authority.
- Highly organized with strong project management skills, capable of managing multiple audits and assessments simultaneously.
- An analytical mindset with the ability to balance regulatory requirements with business objectives and priorities.
RECRUITMENT PROCESS
- First fit call with our Talent Acquisition Manager
- Team fit call with the Hiring Manager
- Tech round with the Team
- A final interview with our CISO
The range listed is for base compensation. Your actual base salary will vary based on factors including location and individual qualifications objectively assessed during the interview process. In addition to base salary, your total rewards package will include additional components such as incentive pay and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the specific details for this position.
B
Certifications this role asks for
Studying for one of these? Try the free CISA practice questions or the free CISM practice questions in our academy. No signup, no cost.
Location and market context
This job is based in Toronto on-site. Local candidates benefit from being close to Shift Technology's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About compliance jobs
Compliance programs turn law, regulation, and policy into controls the business can actually run. Demand is strongest where regulatory change, enforcement risk, and new technology intersect. Jobs like this one are typically evaluated against frameworks such as relevant regulatory frameworks, control libraries, and audit and monitoring practices.
How to position yourself for this compliance job
Strong candidates emphasize building and monitoring controls, regulatory mapping, policy and training, and partnering with the business to make compliance practical. In your resume and outreach, tie your experience to how Shift Technology would apply relevant regulatory frameworks, control libraries, and audit and monitoring practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Senior Manager, Portfolio Compliance · Connor, Clark & Lunn Financial Group · Toronto, ON, Canada
- Security & Compliance Manager · FamilyWell Health · Remote
- General Counsel / VP of Legal & Compliance · Minnesota Cannabis Services · Edina, MN
- Head of Global Regulatory and Quality Affairs · Dozee · Houston, TX
- Global Head Regulatory Science Model Enabled Development Real World Evidence and Novel Endpoints · Sanofi EU · Cambridge, MA
- Director of Regulatory Affairs - Sibley Memorial Hospital · Johns Hopkins Health System · Washington, DC
- Packaging Engineer - Regulatory & Compliance Manager · GE Vernova · Remote
- EMCS Manager & SCADA Compliance Engineer · NASA Jet Propulsion Laboratory (JPL) · JPL Campus
More GRC jobs in Toronto
- Senior Engineering Manager, SDET - Okta Identity Governance (OIG) · Okta · Toronto, Ontario, Canada
- AML Strategy and Governance Senior Manager · FanDuel · Toronto, Ontario, Canada
- Head of Data Governance - Product Line · Sanofi · Toronto, ON
- Staff Software Engineer, Financial Crimes · Stripe · Toronto
- Internal Audit Data Analytics Lead · Stripe · Toronto, New York, San Francisco
- AI Governance Specialist · Mobility · Toronto, Canada
Hiring for Compliance?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Senior GRC Analyst - Central or Eastern time, US or Canada in Toronto, ON open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.