Enable job alerts via email!

Senior GRC Analyst Waterloo, Ontario, Canada

Carta, Inc.

Waterloo

On-site

CAD 80,000 - 120,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a Senior GRC Analyst to enhance their governance, risk, and compliance frameworks. The role involves managing compliance programs, conducting audits, and collaborating with teams to mitigate risks. Ideal candidates will have extensive experience in security frameworks and excellent communication skills.

Qualifications

  • 5+ years of experience in GRC functions.
  • Strong understanding of SOC 1 and 2, ISO 27001, NIST CSF.

Responsibilities

  • Manage and improve the GRC program aligned with security strategy.
  • Lead internal and external security audits.
  • Collaborate with teams to assess risk posture.

Skills

Information Security
Compliance Frameworks
Communication

Tools

AWS
GCP

Job description

Carta develops purpose-built software that transforms traditional accounting into a powerful growth engine.

Carta’s world-class fund administration platform supports nearly 7,000 funds and SPVs, and represents nearly $130B in assets under management in venture capital and private equity.

Trusted by more than 40,000 companies, Carta also helps private businesses in over 160 countries manage their cap tables, valuations, taxes, equity programs, compensation, and more.

Together, Carta is setting a new standard as the end-to-end platform for private markets. Our best-in-class solution for fund management seamlessly integrates investor and portfolio company insights via a suite of tools designed ground-up to support the strategic impact of the fund CFO.

At Carta, our employees set out on a mission to unlock the power of equity ownership for more people in more places. We believe that the problems we solve today unlock the opportunities of tomorrow.

As a Senior GRC Analyst , you’ll work to assess regulatory requirements and accordingly establish and maintain governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance metrics, and build and manage policies and standards.

Here are some problems we’d love for you to help us solve :

  • Manage and continually improve the Carta Governance, Risk, and Compliance program, ensuring it is aligned with our security strategy and business objectives.
  • Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements.
  • Lead and coordinate internal and external security audits.
  • Perform security assessments of vendors, third parties, and applications.
  • Partner with cross functional teams to review initiatives that could impact compliance requirements.
  • Manage risk program activities including risk identification, tracking, and prioritization.
  • Collaborate with engineering and product teams to assess risk posture and compliance status, and support remediation activities.

The Team You'll Work With

You will be part of a security-minded team that believes in progress over perfection and where security culture and mindset is key. Our team is rethinking how GRC activities can be accomplished in innovative ways. We do not focus on building processes, but instead how to solve business problems while minimizing and managing risk exposure for Carta.

About You

We are looking for candidates who have :

  • A strong understanding and working knowledge of information security and compliance frameworks, such as SOC 1 and 2, ISO 27001, NIST CSF, GDPR, CCPA, FINRA, SOX and SEC cybersecurity requirements.
  • Excellent judgment and the ability to make balanced decisions when working with complex situations.
  • Proven understanding of public cloud infrastructure and services in AWS and GCP including knowledge of cloud-native security protection measures, tools, and techniques.
  • Proven ability to collaborate with cross-functional teams and affect change to accomplish goals.
  • Excellent written and verbal communication skills, including the ability to effectively communicate business and cybersecurity risk.
  • 5+ years of experience in developing and executing governance, risk and compliance functions.

Disclosures :

  • We are an equal opportunity employer and are committed to providing a positive interview experience for every candidate. If accommodations due to a disability or medical condition are needed, please connect with the talent partner via email.
  • Please note that all official communications from us will come from an @carta.com or @carta-external.com domain.

Apply for this job

First Name

Last Name

Email

Phone

Location (City)

Resume / CV

Are you currently eligible to work in the country where this position is located for any employer?

  • Select...

Do you now or in the future require visa sponsorship to continue working in the country where this position is located?

  • Select...

LinkedIn Profile

Website

Which is your preferred office location(s)?

  • Select...

Have you worked for Carta at any other time previously?

  • Select...

AI Policy for Application & Interviewing :

  • Select...

While we encourage people to use AI systems during their role to help them work faster and more effectively, please do not use AI assistants during the application and interviewing process. We want to understand your personal interest in Carta without mediation through an AI system, and we also want to evaluate your non-AI-assisted communication skills. Please indicate 'Yes' if you have read and agree.

J-18808-Ljbffr

Create a job alert for this search

Grc Analyst • Waterloo, Region of Waterloo, Canada

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.