Senior GRC Consultant

Scale Up Recruiting Partners

Edmonton

Remote

CAD 90,000 - 130,000

Full time

43 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Scale Up Recruiting Partners is seeking a Senior GRC Consultant for a fully remote, long-term contractor role with a Pacific Time alignment. The role centers on leading audit readiness, developing compliance programs, and managing risk across multiple client engagements for a fast-growing cybersecurity startup.

You will own end-to-end compliance across SOC 2, ISO 27001, HIPAA, GDPR, and related frameworks, collaborating with executive stakeholders and external auditors while delivering

Qualifications

  • 5–7+ years of hands-on experience in GRC, compliance, or information security audits.
  • Experience managing multiple client engagements.
  • Strong expertise with SOC 2 Type I & II and ISO 27001 / ISO 27002.
  • Experience with GDPR, CCPA/CPRA, or HIPAA.
  • Experience building compliance programs from the ground up.
  • Ability to map controls across multiple compliance frameworks.
  • Technical understanding of cloud security, IAM, CI/CD pipelines, and security controls.
  • Excellent documentation and technical writing skills.
  • Professional-level English with confidence leading meetings with U.S.-based clients.

Responsibilities

  • Lead compliance readiness engagements including SOC 2 Type I/II, ISO 27001, HIPAA, U.S. state privacy regulations, and UK/EU GDPR.
  • Own GRC platforms such as Vanta, Drata, or similar tools, ensuring compliance monitoring remains fully operational and evidence is continuously maintained.
  • Conduct formal risk assessments using frameworks such as NIST 800-30, translating technical findings into business and compliance risks.
  • Design and implement complete GRC programs, including policies, control frameworks, risk management processes, and evidence collection.
  • Perform internal audits, evaluating both control design and operational effectiveness while preparing audit-ready findings.
  • Manage vendor security questionnaires, coordinating with internal subject matter experts and maintaining reusable knowledge bases.
  • Build strong relationships with client leadership, lead recurring meetings, provide status updates, and manage expectations throughout each engagement.
  • Produce high-quality client deliverables including policies, procedures, risk registers, control matrices, evidence packages, and assessment reports.

Skills

GRC
Compliance
Audits
Consulting
Client management
Documentation
Cloud security
IAM

Tools

Vanta
Drata

Job description

Hey! We’re Scale Up, and our client is looking to hire a Senior GRC Consultant

Type of Employment

Contractor (Long-term)

Work Modality

100% Remote

Work Schedule

Full-time

Time Zone

Pacific Time (PT)

About Our Client

Our client is a fast-growing U.S.-based cybersecurity and compliance consulting startup that partners with technology companies to build, strengthen, and scale their security and compliance programs. Rather than acting as an external vendor, they work as an extension of their clients' teams, providing embedded security leadership, compliance expertise, and operational support across frameworks such as SOC 2, ISO 27001, HIPAA, GDPR, and more.

This is an opportunity to join a small, highly technical team where you'll have significant ownership, direct client exposure, and the chance to shape security programs for innovative startups.

About The Role

As a Senior GRC Consultant, you will lead audit readiness, compliance program development, and risk management across multiple client engagements. You'll own compliance frameworks end-to-end—from scoping and evidence collection to gap analysis, remediation guidance, and audit support.

This is a senior, client-facing position where you'll independently manage your own engagements while working directly with executive stakeholders and external auditors.

Key Responsibilities
  • Lead compliance readiness engagements including SOC 2 Type I/II, ISO 27001, HIPAA, U.S. state privacy regulations, and UK/EU GDPR.
  • Own GRC platforms such as Vanta, Drata, or similar tools, ensuring compliance monitoring remains fully operational and evidence is continuously maintained.
  • Conduct formal risk assessments using frameworks such as NIST 800-30, translating technical findings into business and compliance risks.
  • Design and implement complete GRC programs, including policies, control frameworks, risk management processes, and evidence collection.
  • Perform internal audits, evaluating both control design and operational effectiveness while preparing audit-ready findings.
  • Manage vendor security questionnaires, coordinating with internal subject matter experts and maintaining reusable knowledge bases.
  • Build strong relationships with client leadership, lead recurring meetings, provide status updates, and manage expectations throughout each engagement.
  • Produce high-quality client deliverables including policies, procedures, risk registers, control matrices, evidence packages, and assessment reports.
What We're Looking For
  • 5–7+ years of hands-on experience in GRC, compliance, or information security audits.
  • Previous consulting or professional services experience managing multiple client engagements.
  • Strong expertise with both:
    • SOC 2 Type I & II
    • ISO 27001 / ISO 27002
  • Experience with one or more additional frameworks such as GDPR, CCPA/CPRA, or HIPAA.
  • Experience building compliance programs from the ground up.
  • Ability to map controls across multiple compliance frameworks.
  • Solid technical understanding of cloud security, IAM, CI/CD pipelines, and security controls.
  • Excellent documentation and technical writing skills.
  • Professional-level English with confidence leading meetings with U.S.-based clients.
Nice to Have
  • Experience working directly with external auditors.
  • Hands-on experience implementing GDPR or U.S. privacy compliance programs.
  • Knowledge of ISO 42001 (AI Management Systems).
  • Certifications such as:
    • CISA
    • CISM
    • CRISC
    • ISO 27001 Lead Auditor
    • ISO 27001 Lead Implementer
    • or equivalent.
Why Join?
  • Join an early-stage, fast-growing cybersecurity startup.
  • Work directly with founders and client leadership.
  • Own high-impact client engagements from start to finish.
  • Help innovative technology companies mature their security and compliance programs.
  • Enjoy long-term remote work with significant autonomy, ownership, and career growth.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Consultant
Senior Security Consultant

Control Gap Inc. • Toronto

On-site
CAD 90,000 - 120,000
Senior Cyber Security Analyst - GRC
Senior Cyber Security Analyst - GRC

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

Hybrid
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4
Governance, Risk & Compliance Manager
Governance, Risk & Compliance Manager

Monachus Solutions • Vancouver

Hybrid
CAD 120,000 - 150,000
Governance, Risk & Compliance (GRC) Manager
Governance, Risk & Compliance (GRC) Manager

Fullscript • Ottawa

Hybrid
CAD 140,000 - 165,000
RRSP match program
Flexible benefits package
Training budget and learning
+2
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Alignerr • Vancouver

On-site
CAD 48,000 - 90,000
Autonomy
Global collaboration
Flexible schedule
Governance, Risk & Compliance Consultant
Governance, Risk & Compliance Consultant

Malleum • Montreal

Remote
CAD 70,000 - 90,000
Flexible work environment
Cyber Security Compliance Analyst
Cyber Security Compliance Analyst

Jobtailor • Edmonton

On-site
CAD 70,000 - 100,000
Senior Specialist, Risk Management
Senior Specialist, Risk Management

Tundra Technical Solutions • Toronto

On-site
CAD 120,000 - 180,000
Sr. Compliance Officer
Sr. Compliance Officer

Raise • Ottawa

Hybrid
CAD 61,000 - 81,000