GRC Analyst

Explorance

Montreal (administrative region)

On-site

CAD 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Explorance seeks a Governance, Risk and Compliance Analyst to coordinate and execute day-to-day GRC and information security assurance programs across Product, Engineering, IT, Security, HR, Sales, Support, and Finance. The role ensures audit readiness, regulatory alignment, and operational resilience with independent judgment within approved policies.

The analyst will maintain documentation, lead control testing and audits, support third-party reviews, and produce reliable GRC reporting and

Qualifications

  • 3–5 years in governance, risk and compliance, or related fields.
  • Post-secondary education in cybersecurity, IT, audit, risk management, privacy, or related discipline.
  • Experience with control testing, audit evidence, risk registers, remediation tracking, or vendor reviews.
  • Familiarity with ISO 27001, SOC 2, NIST CSF, HIPAA, or comparable frameworks.
  • Experience drafting policies, standards, procedures, audit documentation, or reusable response materials.
  • Strong analytical, documentation, organizational, prioritization, and follow-up skills.
  • Ability to manage multiple concurrent activities, deadlines, and stakeholders with limited supervision.
  • Ability to distinguish operational items from regulatory/legal escalation items.

Responsibilities

  • Governance and GRC program operations across the organization.
  • Control validation, internal audits, and compliance monitoring.
  • External audits and assurance activities.
  • Customer trust support and sales assist.
  • Third-party risk management coordination.
  • Privacy and regulatory support.
  • Security awareness and operational resilience initiatives.
  • Metrics, reporting, and stakeholder coordination.

Skills

GRC knowledge
Audit experience
Policy drafting
ISO 27001 knowledge
Bilingual FR/EN
Stakeholder management
Regulatory compliance
Risk assessment
Documentation

Education

Cybersecurity/IT degree

Tools

GRC platforms
Jira

Job description

The Governance, Risk and Compliance Analyst coordinates and executes the day-to-day activities of Explorance's governance, risk, compliance, information security assurance, and operational privacy programs. The role maintains compliance documentation, coordinates control testing and audits, administers risk and remediation records, manages customer assurance requests, supports third-party risk reviews, and produces reliable GRC reporting and evidence.

The analyst works across Product, Engineering, Information Technology, Security, Human Resources, Sales, Support, Finance, and other teams. The role is central to maintaining continuous audit readiness, customer trust, security and privacy compliance maturity, and operational resilience. The analyst exercises independent judgment within approved policies and frameworks and escalates material risks, nonstandard commitments, regulatory interpretations, significant exceptions, and time-sensitive concerns promptly.

Primary Responsibilities
  • Governance and GRC Program Operations
  • Control Validation, Internal Audit, and Compliance Monitoring
  • External Audit and Assurance
  • Customer Trust and Sales Support
  • Third-Party Risk Management
  • Privacy and Regulatory Support
  • Security Awareness and Operational Resilience
  • Metrics, Reporting, and Stakeholder Coordination
Required Qualifications
  • Three to five years of relevant experience in governance, risk and compliance, information security compliance, technology risk, IT audit, privacy operations, security assurance, or a related field.
  • Post-secondary education in cybersecurity, information technology, audit, risk management, privacy, business, law, or a related discipline, or an equivalent combination of education and relevant professional experience.
  • Practical experience with control testing, audit evidence, compliance monitoring, risk registers, issue management, remediation tracking, customer assurance, or vendor reviews.
  • Working knowledge of one or more recognized frameworks, such as ISO 27001, SOC 2, NIST Cybersecurity Framework, HIPAA, or a comparable framework and its control and evidence requirements.
  • Experience drafting or maintaining policies, standards, procedures, control descriptions, audit documentation, and reusable response materials.
  • Strong analytical, documentation, organizational, prioritization, and follow-up skills.
  • Ability to manage multiple concurrent activities, deadlines, and stakeholders with limited supervision.
  • Ability to distinguish matters that can be handled operationally from those requiring escalation, regulatory interpretation, legal review, or material-risk approval.
  • Professional proficiency in French and English, spoken and written, to support global customers, auditors, and business stakeholders.
  • High integrity, discretion, sound judgment, and respect for confidential information.
Core Behavioural Competencies
  • Influence without authority
  • Constructive conflict management
  • Timely communication and escalation
  • Decision-ready reporting
  • Pragmatic judgment
  • Ownership and follow-through
  • Hands-on orientation
Preferred Qualifications
  • Experience in a SaaS, cloud software, technology, education technology, or data-intensive organization.
  • Direct experience supporting a SOC 2 audit or comparable assurance program.
  • Familiarity with PIPEDA, GDPR, Quebec Law 25, privacy impact assessments, and data-protection requirements.
  • Experience with third-party risk management, penetration-test remediation, vulnerability governance, business continuity, disaster recovery, or incident-response exercises.
  • Experience with GRC platforms, compliance automation tools, privacy-management tools, Jira, or structured workflow systems.
  • Exposure to AI governance, data residency, responsible AI assessments, or governance of AI-enabled SaaS services.
  • Professional proficiency in French, spoken and written.
  • A relevant certification or progress toward one, such as CISA, CRISC, CISM, Security+, ISO 27001 Lead Implementer, or a comparable credential.
Other Requirements:

Only apply if you are a Montreal (or surroundings) resident that is interested in being part of a vibrant and highly engaged at-the-office culture.

At Explorance, we take inclusion to heart and live it each day. We put the ‘human’ first in everything we do and take pride in our authenticity and culture of inclusion. We therefore encourage persons of any race, religion, ethnicity, gender identity, sexual orientation, age, immigration status, disability or other applicable legally protected characteristics to apply. We make employment-related decisions without regard to any of these characteristics. And to ensure a safe workspace for all our employees, all employment is contingent upon receipt of a satisfactory background and reference check.

About Explorance

Explorance empowers organizations with next-generation feedback analytics to accelerate the insight-to-action cycle, encouraging the philosophy of “Feedback for the brave” to drive purpose, impact, and growth.

Bringing 20 years of expertise, Explorance, a member of the World Economic Forum and a trusted partner for 35% of Fortune 100 companies and 25% of the world’s top higher education institutions, has influenced over 25 million individuals with award-winning solutions like Blue, Metrics That Matter, and MLY.

Consistently among the top employers by the Great Places to Work Institute®, Explorance, a Brandon Hall AI award winner, is also a two-time Global Leader in the 360-degree feedback market by Fortune Business Insights.

  • Visit explorance.com or connect on LinkedIn, Facebook, and X.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Analyste GRC / GRC Analyst
Analyste GRC / GRC Analyst

Explorance • Montreal (administrative region)

On-site
CAD 80,000 - 110,000
Coordonnateur(trice) des services de bureau et de la réception / Office Services & Reception Coordinator
Coordonnateur(trice) des services de bureau et de la réception / Office Services & Reception Coordinator

Explorance • Montreal (administrative region)

On-site
CAD 36,000 - 48,000
Implementation Consultant
Implementation Consultant

Explorance • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Back End Developer
Back End Developer

Explorance • Montreal (administrative region)

On-site
CAD 110,000 - 140,000
Administrateur(trice) de bases de données (intermédiaire) – PostgreSQL / Database Administrator (Intermediate) – PostgreSQL
Administrateur(trice) de bases de données (intermédiaire) – PostgreSQL / Database Administrator (Intermediate) – PostgreSQL

Explorance Inc. • Montreal (administrative region)

On-site
CAD 95,000 - 130,000
Associate, Research & Delivery (English)
Associate, Research & Delivery (English)

Exiger • Toronto

Hybrid
CAD 50,000 - 60,000
Discretionary Time Off
Health, vision, and dental benefits
Parental leave (16 weeks)
+2
Technical Security Analyst
Technical Security Analyst

Coveo • Quebec

On-site
CAD 110,000 - 130,000
Sr Compliance Analyst - Privacy
Sr Compliance Analyst - Privacy

Peoples Group • Toronto

Hybrid
CAD 85,000 - 95,000
Hybrid work environment
Profit sharing
RRSP matching
+2
Sr Compliance Analyst - Privacy
Sr Compliance Analyst - Privacy

Peoples Group • Vancouver

Hybrid
CAD 85,000 - 95,000
Hybrid work
Profit sharing
RRSP matching
+3
Customer Success Manager
Customer Success Manager

Exiger • Vancouver

Hybrid
CAD 110,000 - 135,000