Governance, Risk, & Compliance Manager

Inovatec Systems Corp.

Canada

On-site

CAD 110,000 - 125,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Inovatec is hiring a Governance, Risk & Compliance (GRC) Manager to own the day-to-day execution and continued maturity of our security, privacy, and compliance program.

This role is central to our shift from point-in-time audits to continuous, evidence-based control monitoring, anchored in our GRC platform, and to keeping Inovatec audit-ready year-round across various compliance frameworks and providing a high level of assurance to our clients.

Qualifications

  • 6-10+ years in governance, risk, and compliance, information security, or IT audit.
  • Experience leading or managing a small team or direct report.
  • Hands-on experience with SOC 1/2 and ISO 27001/27018 frameworks.
  • Familiarity with AI compliance frameworks (ISO 42001) is a plus.

Responsibilities

  • Lead a small team including an Internal Auditor / GRC Specialist.
  • Own the GRC program and drive continuous monitoring and evidence collection.
  • Coordinate internal and external audits and remediation efforts.
  • Manage third-party / vendor risk assessments and ongoing monitoring.
  • Develop and maintain policy lifecycle and training programs.

Skills

Leadership
GRC management
SOC 1/2
Vendor risk

Tools

Vanta

Job description

Salary Range: $110,000.00 To $125,000.00 Annually

Governance, Risk & Compliance Manager

About Inovatec

Inovatec is an exciting growth company based in Vancouver, BC, established in 2006. We are North America’s leading provider of cloud-based software solutions for the automotive, motorcycle, powersports, and equipment financing industries. Our solutions are used by some of the largest banks, credit unions, and finance companies in Canada and the U.S.

At Inovatec, we foster a diverse and inclusive environment that encourages collaboration where we grow together and win as a team. It’s important that we live up to our four core values: make sound decisions, get better every day, act like an owner, and we before me. We thrive by challenging the status quo to push the industry forward, and we know when to have fun! With team members across North America and Europe, we’re committed to investing in the development of our team, no matter where they’re located.

Job Summary

Inovatec is hiring a Governance, Risk & Compliance (GRC) Manager to own the day-to-day execution and continued maturity of our security, privacy, and compliance program. This role is central to our shift from point-in-time audits to continuous, evidence-based control monitoring, anchored in our GRC platform, and to keeping Inovatec audit-ready year-round across various compliance frameworks and providing a high level of assurance to our clients.

You will lead a small, focused team, directly managing our Internal Auditor / GRC Specialist, and the two of you will work shoulder-to-shoulder across all governance, risk, audit, and compliance efforts. You will operationalize governance, run our risk management lifecycle, manage third-party risk, and coordinate internal and external audits. Reporting to the Head of Cybersecurity & Compliance, you will partner closely with Infrastructure, Product Engineering, IT, Legal, Finance, and People & Culture. We are looking for a candidate ideally based in Ontario, Canada.

What You’ll Do

Leadership, Management & Accountability (LMA)

  • Directly manage the Internal Auditor / GRC Specialist, owning coaching, priorities, development, and day-to-day workload, and partnering closely on every governance, risk, audit, and compliance effort.
  • Set clear expectations and a steady operating cadence (1:1s, planning, quarterly goals) so audit and compliance work is delivered predictably and to a high standard.
  • Champion intent-based leadership, growing the autonomy, judgement, and technical depth of your report while ensuring shared coverage and no single points of failure.
  • Serve as a hands-on working manager who leads by doing, shares the workload, and steps into complex assessments and audits alongside your report.

Governance & Compliance Program

  • Own and continuously mature Inovatec’s GRC program across frameworks like SOC 1 & SOC 2 Type II, ISO 27001, ISO 27018 and TISAX.
  • Drive the transition from point-in-time audits to ongoing control monitoring, completing migration of GRC processes into the GRC platform and maintaining ≥90% of controls under continuous monitoring.
  • Automate evidence collection across active frameworks (targeting ≥80% reduction in manual evidence) and maintain a real-time compliance posture dashboard.
  • Manage the policy lifecycle, covering authoring, review cadence, versioning, and employee policy acknowledgment (≥95% target).
  • Own and mature the privacy, compliance, and security awareness training program, ensuring it remains aligned to company policies, client obligations, and applicable compliance frameworks.
  • Support AI compliance readiness, including CSA AI validation and ISO 42001 (AI Management System) compliance.
  • Operate the enterprise risk lifecycle (identification, scoring, categorization, treatment, and workflows aligned to Inovatec’s approved risk policies), with monthly risk snapshots for historical tracking and audit-ready reporting.
  • Maintain the risk register and support quarterly compliance health reviews and board-level risk reporting.
  • Track remediation against SLAs (e.g., <15-day average remediation for compliance drift alerts) and drive closure of audit findings and nonconformities.
  • Contribute to the fraud risk program and segregation-of-duties controls (prevention, detection, response, deterrence).

Third-Party / Vendor Risk

  • Run the Vendor Risk Management (VRM) program end-to-end, covering onboarding, tiering, security risk assessments, continuous monitoring, SOC report reviews, and offboarding.
  • Automate vendor risk assessments for 100% of critical vendors and publish a vendor risk dashboard showing tier coverage and remediation status.
  • Enforce third-party information security requirements and confidentiality obligations prior to engagement.

Audit & Assurance

  • Coordinate internal and external audits, managing scope, evidence, fieldwork logistics, and corrective actions in close partnership with the Internal Auditor / GRC Specialist.
  • Maintain the Statement of Applicability, control mappings, and audit calendar, ensuring zero missed compliance deadlines for external audits or certifications.
  • Support client due diligence, and security questionnaires and requests with accurate, evidence-backed responses.
What You Bring
  • 6-10+ years in governance, risk, and compliance, information security, or IT audit, ideally in a multi-tenant SaaS or regulated (financial services) environment.
  • Direct people-management or team-lead experience, or clear readiness to manage and develop one direct report.
  • Hands-on experience running or maturing programs across SOC 1/2, and ISO 27001/27018, with familiarity of emerging AI frameworks (ISO 42001, CSA AI).
  • Practical experience with a GRC / continuous-compliance platform (Vanta preferred) and control-monitoring automation.
  • Strong grasp of risk assessment methodology, control frameworks, and third-party / vendor risk management (BitSight or similar a plus).
  • Experience coordinating external audits and managing remediation of findings to closure.
  • Excellent documentation discipline and evidence rigor, able to translate control requirements into clear, defensible artifacts.
  • Strong cross-functional communication, comfortable engaging Engineering, IT, Legal, Finance, executives, clients, and auditors.
Nice to Have
  • Experience working with regulated financial-services clients, SaaS platforms, or enterprise B2B environments is strongly preferred.
  • Privacy program experience (PIPEDA, Quebec Law 25, ISO 27018).
  • Familiarity with the Microsoft / Azure security stack (Entra ID, Defender, Sentinel) as it relates to control evidence.
Our Core Values
  • Act like an owner: no matter the challenge, we overcome hurdles, seek out solutions, and follow through on commitments to consistently exceed expectations.
  • Make sound decisions: we put ourselves in our customer’s shoes, always ensuring we have the right facts and focus on solving the right problems.
  • Get better every day: with our growth mindset and positive attitude, we apply our passion for innovation not just to our products, but also to ourselves.
  • We before me: our collaborative spirit pushes us to act without ego, to communicate openly and honestly, and to win as a team.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk, & Compliance Manager
Governance, Risk, & Compliance Manager

Inovatec • Vancouver

On-site
CAD 110,000 - 125,000
IT & Security Operations Lead
IT & Security Operations Lead

Software Secured • Ottawa

On-site
CAD 90,000 - 120,000
Profit sharing 8-15%
Monthly Ubereats budget
Work from home stipend
+5
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

Hybrid
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4
Security Compliance & Customer Assurance Analyst
Security Compliance & Customer Assurance Analyst

Behavox • Calgary

Hybrid
CAD 95,000 - 125,000
Health insurance for employees and fam
Equity award
30 days annual leave
Security Compliance & Customer Assurance Analyst
Security Compliance & Customer Assurance Analyst

Behavox • Toronto

Hybrid
CAD 90,000 - 130,000
Equity award
Health insurance
30 days paid time off
+1
Security Compliance & Customer Assurance Analyst
Security Compliance & Customer Assurance Analyst

Behavox • Montreal (administrative region)

Hybrid
CAD 80,000 - 110,000
Equity award
Health insurance
Hybrid/remote option
+1
Security Compliance & Customer Assurance Analyst
Security Compliance & Customer Assurance Analyst

Behavox • Ottawa

Hybrid
CAD 70,000 - 100,000
Health insurance
Equity award
30 days annual leave
Security Compliance & Customer Assurance Analyst
Security Compliance & Customer Assurance Analyst

Behavox • Vancouver

Hybrid
CAD 90,000 - 120,000
Equity award
Health insurance
30 days off
Technology Risk & Security - Functional Consultant
Technology Risk & Security - Functional Consultant

Simon-Kucher • Toronto

On-site
CAD 160,000 - 168,000
Performance bonus
Paid time off
13 paid holidays
+2
Senior Analyst - Enterprise Risk & Internal Controls
Senior Analyst - Enterprise Risk & Internal Controls

Intelcom | Dragonfly • Montreal (administrative region)

On-site
CAD 110,000 - 160,000
On-site gym
Lunch provided
Group insurance
+4