Manager, Security GRC

Nesto

Canada

Hybrid

CAD 130,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Premium benefits
4 weeks vacation
Hybrid work model
Telemedicine access
Mental health services

Job summary

Nesto Cloud is seeking a GRC Lead to own and elevate the governance, risk, and compliance program end-to-end. You will optimize automated systems, refine audit readiness, and strengthen policy governance while scaling vendor assessments.

This role partners with Engineering and Compliance to enable rapid, safe AI feature deployment and enterprise governance. You will transform risk management into a strategic advisor, partnering with business leaders to articulate risk narratives and enable

Qualifications

  • 10+ years of GRC, audit, risk management, or compliance experience in regulated industries.
  • Deep knowledge of SOC1, SOC2, and NIST frameworks and audits.
  • Strong writing and communication skills for policy and control concepts.
  • Experience scaling an automated GRC program and vendor assessments.

Responsibilities

  • Own and mature governance, risk and compliance programs across SOC1/2, ISO 27001 and regulatory frameworks.
  • Scale automated GRC systems and self-service workflows; reduce manual audit prep.
  • Lead external audit programs and expand scope as the business grows.
  • Advance AI governance in collaboration with Engineering and Compliance teams.
  • Translate technical findings into business risk narratives for leadership decisions.
  • Grow vendor and client security assessments and strengthen security posture communications.
  • Build and mentor a high-performing GRC team focused on governance and resilience.
  • Strengthen business continuity and disaster recovery plans to ensure operations during crises.

Skills

GRC expertise
Audit experience
Risk management
Compliance operations
Policy governance
Stakeholder engagement
Project management
Policy writing
English writing

Tools

GRC automation platforms
Audit tooling

Job description

About Us

Nesto Cloud is Canada's cloud-native and AI driven, end-to-end mortgage technology platform, helping financial institutions modernize lending through AI intelligent automation, AI & Cloud proprietary technology, and business process outsourcing (BPO) solutions.

Powered by the Nesto Group ecosystem, we transform decades of mortgage expertise into cutting-edge technology that reduces mortgage operation costs, accelerates lending, strengthens compliance, and delivers exceptional experiences for lenders and borrowers alike.

Nesto Group

Nesto Group is Canada's leading provider of mortgage technology and financing solutions, with more than CAD $80 billion in residential and commercial mortgages under administration. Trusted by many of the country's leading financial institutions, we combine over 50 years of mortgage expertise with proprietary cloud and AI technology to transform the future of lending.

Powered by our proprietary cloud and AI technology, nesto has become one of Canada's fastest-growing mortgage lenders, gaining market share across direct-to-consumer (D2C) residential lending, the broker channel, and multi-family commercial lending. Recognized as one of Deloitte's Fast 50 companies for three consecutive years, we continue to push the industry forward through innovation, technology, and customer-focused solutions.

Operating through our family of brands—CMLS, nesto, and Nesto Cloud—our mission is to build Canada's mortgage ecosystem of the future and create a true Canadian champion in lending technology and financial services. Learn more at: https://nestogroup.ca/

Life at Nesto Cloud

At Nesto Cloud, you'll build the future of lending alongside some of the country's top developers, AI engineers, and mortgage experts. You'll work with a modern tech stack and AI-driven development frameworks designed to help you innovate, grow your skills, and accelerate your career

About the role

The GRC Lead owns nesto's governance, risk, and compliance program end-to-end. We've built strong foundations and automated much of our compliance workflow; your role is to elevate it to world-class execution. You'll optimize our automated systems, refine audit readiness processes, enhance policy governance rigor, strengthen risk management discipline, and scale vendor assessment workflows. You're taking a program that works and making it exceptional, resilient, and repeatable.

What you'd be accomplishing in that role :
  • Own Security policy governance and control mapping across nesto's compliance frameworks (SOC 1/2, ISO 27001, and applicable regulatory frameworks).
  • Mature our automated compliance program to scale sustainably with nesto's growth. Optimize our GRC platform, automation tools for self-service workflows, and progressively eliminate manual audit prep.
  • Elevate nesto's external audit program while continuously expanding scope as the business scales.
  • Evolve nesto's AI governance framework in collaboration with Engineering, and Compliance teams from foundational policies to enterprise-grade controls that enable rapid, safe AI feature deployment and internal usage.
  • Transform risk management into a strategic business advisor. Collaborate with business unit leaders to evolve our risk narratives, connect technical findings to business impact, and enable leadership to make informed trade-offs with confidence.
  • Scale vendor and client security assessments. Evolve intake workflows, mature questionnaire automation, and strengthen how we communicate security posture to enterprise prospects and customers.
  • Lead and develop a GRC team that raises the bar on technical excellence, deepens capability in governance and risk disciplines, and drives accountability across initiatives.
  • Strengthen organizational resilience through evolved, regularly tested Business Continuity and Disaster Recovery frameworks that keep nesto operationally confident during crisis.
What We’re Looking For
  • 10+ years of GRC, audit, risk management, or compliance experience in regulated industries (financial services, SaaS, healthcare)
  • Deep experience across SOC1, SOC2, NIST frameworks and audits.
  • Strong knowledge of risk assessment methodologies and compliance operations.
  • Hands-on experience with GRC automation platforms.
  • Excellent project management, stakeholder engagement, and cross-functional collaboration skills
  • Strong writing skills; ability to communicate policy and control concepts clearly to technical and non-technical audiences
  • Ability to influence leadership through evidence-based risk narratives and business-aligned insights
  • **English is required for writing and documentation. French speaking and reading is a strong plus.*
The Reward
  • The A-Team: Work alongside high-performing talent in the industry.
  • Accelerated Growth: The slope of your learning curve here will be vertical. You will touch more production systems in one year than you would in five years at a bank.
  • Top-Tier Coverage: Premium benefits plan fully paid by nesto, including comprehensive insurance and unlimited access to telemedicine and mental health services for you and your family.
  • Rest & Recharge: 4 weeks of vacation to ensure you stay at peak performance.
  • Best-in-Class Tools: Access to the resources and tech you need to execute without friction.
  • Working framework: The environment that makes you productive and enables teamwork (Hybrid model).
  • Diversity and Inclusion

At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.

#nestocloud

#nestoposition

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Platform Team Lead
Platform Team Lead

Rippling, Inc. • Canada

On-site
CAD 120,000 - 160,000
Hybrid work model
Premium benefits plan
4 weeks vacation
+1
Growth Operations Manager
Growth Operations Manager

Nesto Group • Toronto

On-site
CAD 90,000 - 150,000
Health coverage
Dental coverage
Vision coverage
+3
Senior Security Developer
Senior Security Developer

Nesto Inc. • Canada

Hybrid
CAD 120,000 - 160,000
Top-tier benefits
4 weeks vacation
Hybrid work model
+1
Technical Solutions Architect
Technical Solutions Architect

Nesto Cloud • Montreal (administrative region), Calgary, Toronto, Vancouver

On-site
CAD 110,000 - 150,000
Premium benefits plan
4 weeks vacation
Telemedicine access
+2
Technical Solutions Architect
Technical Solutions Architect

Nesto-Cloud • Canada

On-site
CAD 120,000 - 170,000
Remote work
Competitive compensation
Healthcare plan
Growth Operations Manager
Growth Operations Manager

Nesto • Montreal (administrative region), Calgary, Vancouver

On-site
CAD 120,000 - 135,000
Health coverage
Wellness spending account
Paid time off
+3
Senior Platform Developer
Senior Platform Developer

Rippling, Inc. • Canada

Hybrid
CAD 120,000 - 160,000
Premium benefits
Telemedicine
Mental health support
+4
Senior Project Manager
Senior Project Manager

nesto • Quebec

On-site
CAD 100,000 - 130,000
Comprehensive Health Coverage
Health & Wellness Spending Account
Generous Paid Time Off
+3
Administrator, Commercial Mortgage Operations
Administrator, Commercial Mortgage Operations

nesto • Vancouver

On-site
CAD 50,000 - 70,000
Health & Wellness
Vacation & holidays
RRSP matching
+4
Senior Platform Developer
Senior Platform Developer

Nesto • Canada

Hybrid
CAD 110,000 - 170,000
The A-Team
Accelerated Growth
Top-Tier Coverage
+3