Governance, Risk & Compliance Manager

Monachus Solutions

Vancouver

Hybrid

CAD 120,000 - 150,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Monachus Solutions is seeking a GRC Manager to lead audits (SOC 2, ISO 27001) and guide clients through security questionnaires with precision. You’ll partner with startups and internal teams to build scalable, compliant processes in a fast-paced environment.

The role requires 5+ years of audit leadership, strong communication across technical and non-technical audiences, and a disciplined, strategic approach to risk. Vancouver-based hybrid role offering ownership and impact.

Qualifications

  • 5+ years leading compliance audits (SOC 2, ISO 27001, etc.).
  • Experience with US-based clients and cybersecurity frameworks.
  • Experience responding to vendor assessments and security questionnaires.
  • Clear communication with technical and non-technical audiences.
  • Strategic thinking with ability to explain the rationale behind recommendations.
  • Startup environments require adaptability and pragmatic approaches.
  • Bachelor's degree in business/tech or related field; Master's preferred.

Responsibilities

  • Lead audits from start to finish across SOC 2, ISO 27001, and related projects.
  • Communicate clearly and proactively with clients.
  • Own timelines, evidence collection, remediation validation, and project momentum.
  • Assess risk and advise on compliance posture.
  • Respond to vendor requests, complete RFPs and questionnaires accurately.
  • Draft SOPs and frameworks reflecting real operations.
  • Train and guide teams on tailored compliance education.
  • Identify opportunities to streamline processes and improve efficiency.
  • Collaborate with auditors, founders, and technical stakeholders.

Skills

5+ years leading audits
Clear technical/non-technical comms
Strategic reasoning
Startup adaptability
Process improvement
Vendor assessments & security qs

Education

Bachelor's degree in business/tech
Master's preferred

Tools

Task trackers
Cloud infrastructure
SDLC
Compliance tooling

Job description

Monachus helps early-stage startups build scalable systems for compliance, security, and operations. Without the chaos. We're a small, high-trust team based in Vancouver, BC, and our clients are spread across North America. We work closely with founders and technical teams who are moving fast and need security and compliance done right, not just done.

"Monachus" is Latin for monk, meaning diligent, dedicated, wise. If you care about doing high-quality work, being hands-on in the world of compliance, learning constantly, and having real ownership over outcomes, this is the kind of place where that actually happens.

The Role

We're hiring a GRC Manager who brings structure, precision, and strategic thinking to every client engagement. You'll be the person startups turn to when they need to navigate SOC 2, ISO 27001, and vendor assessments with confidence, and the person internally who helps us run tighter, smarter processes.

This is a full-time, hybrid role based in Vancouver. At six months, success looks like: clients trust you, and timelines are moving in an environment where the pace is real and clients' expectations are high. If you do your best work with structure and autonomy in equal measure, this is the right environment for you.

What You'll Do
  • Lead audits from start to finish. Manage SOC 2, ISO 27001, and related projects.
  • Act as a trusted partner. Communicate clearly and proactively with clients.
  • Own the details. Track timelines, gather evidence, validate remediations, and keep things moving.
  • Make informed decisions. Assess risk and advise on compliance posture.
  • Respond to vendor requests. Complete RFPs and questionnaires with accuracy and speed.
  • Write meaningful policies. Draft SOPs and frameworks that reflect real operations.
  • Train and guide. Deliver tailored compliance education for teams.
  • Streamline where possible. Spot opportunities to improve processes and make things more efficient without overcomplicating.
  • Collaborate across teams. Work with auditors, founders, and technical stakeholders.
  • Stay informed. Track regulatory changes and help clients stay ahead.
What We're Looking For
Experience & Background
  • Have 5+ years leading compliance audits (SOC 2, ISO 27001, etc.)
  • Have worked with US-based clients and understand industry-standard cybersecurity frameworks
  • Have experience responding to vendor assessments and security questionnaires
  • Communicate clearly with both technical and non-technical audiences
  • Think strategically and can explain the "why" behind your recommendations
  • Understand startup environments and can adapt your approach accordingly
  • Have a bachelor's degree in business, tech, or a related field (Master's preferred)
  • Enjoy improving processes and finding leaner ways to get things done
Tools & Systems
  • Are comfortable using structured systems like task trackers to manage work
  • Know your way around cloud infrastructure, SDLC, and compliance tooling
Culture Fit Matters at Monachus
You’ll Thrive Here If You
  • Constantly look for ways to improve systems, workflows, and delivery quality
  • Collaborate well and prioritize alignment over ego
  • Can take direction, follow operating systems, and improve them instead of fighting them
  • Move fast without sacrificing quality
  • Take ownership and operate with high accountability
  • Enjoy building scalable processes and improving how work gets done
  • Are curious about new tools and technologies and actively experiment with AI to improve how work gets done
  • Direct impact with startup founders and leadership teams
  • Small, high-trust team with autonomy
  • Strong focus on quality, structure, and continuous improvement
  • Work that values originality, depth, and thoughtful execution over templates or audit checklists

Applications are reviewed on a rolling basis.

We review every application. If you're a fit, someone from our team will reach out within 5 business days to introduce themselves and share next steps.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk, & Compliance Manager
Governance, Risk, & Compliance Manager

Inovatec Systems Corp. • Canada

On-site
CAD 110,000 - 125,000
Governance, Risk, & Compliance Manager
Governance, Risk, & Compliance Manager

Inovatec • Vancouver

On-site
CAD 110,000 - 125,000
Senior GRC Consultant
Senior GRC Consultant

Scale Up Recruiting Partners • Edmonton

Remote
CAD 90,000 - 130,000
Special Projects Analyst
Special Projects Analyst

Meroka Inc. • Montreal (administrative region)

Hybrid
CAD 80,000 - 110,000
Meaningful equity
Benefits package
Software Engineering Team Lead
Software Engineering Team Lead

Monks • Toronto

On-site
CAD 130,000 - 160,000
Group Finance Manager
Group Finance Manager

Socket.dev • Montreal (administrative region)

Hybrid
CAD 110,000 - 140,000
Hybrid work environment
Paid Time Off
Healthcare benefits
+1
Analyst III, Security Business Advisory & Consulting
Analyst III, Security Business Advisory & Consulting

moneris • Toronto

Hybrid
CAD 85,000 - 119,000
Hybrid work model
Wellness program
RRSP matching
Senior Software Engineer
Senior Software Engineer

EviSmart • Vancouver

On-site
CAD 140,000 - 190,000
Senior Security Technical Program Manager
Senior Security Technical Program Manager

United States Digital Space LLC • Vancouver

Hybrid
CAD 150,000 - 170,000
Mental health benefits
Career coaching
Family building benefits
+2
Cloud & DevOps Specialist
Cloud & DevOps Specialist

Montrium Canada • Montreal (administrative region)

On-site
CAD 95,000 - 140,000
Hybrid work environment
Paid Time Off
Healthcare benefits
+3