Enable job alerts via email!

Senior GRC Analyst II New Waterloo, Ontario, Canada

Carta, Inc.

Waterloo

Remote

CAD 268,000 - 316,000

Full time

3 days ago
Be an early applicant

Job summary

A leading firm in private market infrastructure is seeking a Senior GRC Analyst II to oversee governance, risk, and compliance programs. This role requires you to manage security compliance efforts, conduct audits, and collaborate with various teams to ensure adherence to regulatory requirements. The ideal candidate has over 5 years of experience in the field, with strong knowledge of information security frameworks and cloud infrastructure. Competitive salary and equity options available.

Benefits

Market competitive salary
Equity for all full-time roles
Exceptional benefits

Qualifications

  • Excellent judgment with complex situations.
  • 5+ years of governance, risk, and compliance experience.
  • Proven understanding of cloud-native security measures.

Responsibilities

  • Manage and improve the Governance, Risk, and Compliance program.
  • Develop and lead security policies and compliance audits.
  • Collaborate with engineering teams to assess risk posture.

Skills

Information security frameworks
Compliance requirements
Public cloud infrastructure
Cross-functional collaboration
Communication skills
Job description
Overview

Carta connects founders, investors, and limited partners through world-class software, purpose-built for everyone in venture capital, private equity and private credit. Carta’s platform of software and services lays the groundwork so you can build, invest, and scale with confidence. Carta’s Fund Administration platform supports 9,000+ funds and SPVs, representing nearly $185B in assets under management, with tools designed to enhance the strategic impact of fund CFOs. Recognized by Fortune, Forbes, Fast Company, Inc. and Great Places to Work, Carta is shaping the future of private market infrastructure.

Together, Carta is creating the end-to-end ERP platform for private markets. Private capital markets need a comprehensive software solution to replace outdated spreadsheets and fragmented service providers. Carta’s software for the Office of the Fund CFO does just that – it’s a new category of software to make private markets look more like public markets - a connected ERP for private capital.

The Role

As a Senior GRC Analyst II, you’ll work to assess regulatory requirements and accordingly establish and maintain governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance metrics, and build and manage policies and standards.

Responsibilities
  • Manage and continually improve the Carta Governance, Risk, and Compliance program, ensuring it is aligned with our security strategy and business objectives.
  • Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements.
  • Lead and coordinate internal and external security audits.
  • Perform security assessments of vendors, third parties, and applications.
  • Partner with cross functional teams to review initiatives that could impact compliance requirements.
  • Manage risk program activities including risk identification, tracking, and prioritization.
  • Collaborate with engineering and product teams to assess risk posture and compliance status, and support remediation activities.
Qualifications
  • A strong understanding and working knowledge of information security and compliance frameworks, such as SOC 1 and 2, ISO 27001, NIST CSF, GDPR, CCPA, FINRA, SOX and SEC cybersecurity requirements.
  • Excellent judgment and the ability to make balanced decisions when working with complex situations.
  • Proven understanding of public cloud infrastructure and services in AWS and GCP including knowledge of cloud-native security protection measures, tools, and techniques.
  • Proven ability to collaborate with cross-functional teams and affect change to accomplish goals.
  • Excellent written and verbal communication skills, including the ability to effectively communicate business and cybersecurity risk.
  • 5+ years of experience in developing and executing governance, risk and compliance functions.
Compensation and Location

Carta’s compensation package includes a market competitive salary, equity for all full time roles, exceptional benefits, and, for applicable roles, commissions plans. Our minimum cash compensation (salary + commission if applicable) range for this role is :

  • San Francisco, CA; Santa Clara, CA; New York City, NY : $193,800 - $228,000
  • Seattle, WA : $184,110 - $216,600

Final offers may vary from the amount listed based on geography, candidate experience and expertise, and other factors.

Disclosures

We are an equal opportunity employer and are committed to providing a positive interview experience for every candidate. If accommodations due to a disability or medical condition are needed, please connect with the talent partner via email.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.