Software Risk and Compliance Analyst

BIS Safety Software

Sherwood Park

On-site

CAD 80,000 - 90,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

ESOP
Medical, dental, vision coverage
Life insurance
Disability insurance
Health spending account
Flexible working hours
On-the-job training and growth

Job summary

BIS Safety Software, a Sherwood Park, Alberta-based SaaS company, seeks a Software Risk and Compliance Analyst to embed with product teams and govern data safety and governance across new features. You will assess risks, advise on data handling, and ensure alignment with PCI DSS, SOC 2, GDPR, and client commitments.

You will work closely with developers and product to implement compliant paths, validate controls in software, and participate in audit readiness for SOC 2 and PCI DSS cycles.

Qualifications

  • Background in risk, compliance, privacy, or data governance.
  • Familiarity with control frameworks or privacy regimes (SOC 2, PCI DSS, GDPR, ISO 27001).
  • Strong technical curiosity about how software handles data.

Responsibilities

  • Own risk assessments for new features and data handling changes.
  • Involve in feature mapping and product planning to surface risks early.
  • Track cases from scoping to release and ensure approvals stay valid.
  • Verify in-software behavior aligns with documentation and controls.

Skills

Risk management
Compliance
Privacy
Data governance

Education

Post-secondary education in compliance, information security, CS or engineering

Job description

BIS Safety Software is a SaaS company on a mission to change how organizations manage safety, learning, and compliance. Since 2006 we've been building software in a space where trust and data integrity matter, and we're looking for a Software Risk and Compliance Analyst who will be embedded with our technology and product teams, focused entirely on the software itself.

About the Role

You'll be in the room with product and technology every day, knowing the software as well as the people building it, and making sure that new modules, feature improvements, and changes to how data moves keep us aligned with PCI DSS, SOC 2, GDPR, and the data governance commitments we make to our clients.

Risk gets identified while a feature is still being sketched out, the right requirements land in the case up front, and nothing stalls later because a compliance question surfaced too late. When scope shifts partway through, you're the one who notices that what was approved is no longer what's being built.

You’ll have the autonomy to raise a concern to anyone here, and we'll expect you to use it. We'll also expect you to bring a way forward.The job is enablement, not gatekeeping, and the difference matters to us.

You’ll spend a lot of your time in project tickets and inside the software. The people who love this role are the ones who find that genuinely interesting.

This is an in-person role based out of our Sherwood Park, AB office.

In This Role, You Will Be Expected To:

  • Risk assessments: own the assessments for new features, new modules, and any change to how our software collects, stores, or moves data.
  • Early involvement: join feature mapping and product planning sessions, ask the questions that surface risk before development starts, and get the right requirements written into the case.
  • Ticket to ship: follow cases through their full life, watch for scope creep, and re-review when something changes so approvals stay valid.
  • Hands-on verification: work in the software yourself to confirm it behaves the way our documentation and our controls say it does.
  • AI features: assess how AI capabilities in our product handle personal data, where that data is processed, and whether it stays within the boundaries we've committed to.
  • AI in the build: join the conversations about how we connect AI tools to our data, asking where information gets processed, what a model can reach, and how it stays contained.
  • Audit readiness: review what has changed ahead of our SOC 2 and PCI DSS cycles, confirm our controls still match reality, and close gaps before an auditor finds them.
  • Practical solutions: partner with developers and product to find a compliant path forward so work keeps moving.

You Might Be the Right Fit If You Are:

  • Experienced with a background in risk, compliance, privacy, or data governance
  • Detail-oriented to an unusual degree, the person who reads a case and catches what nobody addressed
  • Experienced in digging until you actually understand it, especially when it comes to how data moves through a system
  • Willing to speak up and stay with it, raising a concern clearly and following through until it’s resolved
  • Able to see the second-order impact, the other module, the other commitment, the thing this quietly touches
  • Following AI and privacy developments on your own, closely enough to spot when a new capability changes the risk picture
  • Drawn to technology and happy spending your days in project tickets and software
  • Curious about how AI works underneath the demo, enough to ask whether a tool is doing what it claims with our data
  • Self-directed, comfortable with autonomy and setting your own priorities
  • Solution-minded, arriving with options rather than only objections

Qualifications we are looking for:

  • A background in risk, compliance, privacy, data governance, or information security.
  • Working familiarity with at least one control framework or privacy regime, such as SOC 2, PCI DSS, GDPR, ISO 27001, or something comparable
  • Strong technical aptitude and real curiosity about how software works under the hood, including how data is stored, transmitted, and shared between systems
  • Experience with the privacy and data governance questions that come with AI features: what data a model can reach, where it's processed, and what leaves our environment.
  • Comfort working day to day in project management and ticketing tools, following a case from scoping through to release

Bonus points if you have:

  • Post-secondary education in a relevant field, such as compliance, information security, computer science, or engineering, or equivalent hands-on experience
  • A background in software engineering or QA/QC
  • Experience with AI governance, or a genuine interest in the privacy and data questions that come with AI features
  • Experience working inside a software or SaaS company

Compensation and benefits:

  • Employee Stock Ownership Plan (ESOP)
  • Full medical, dental, and vision coverage
  • Life insurance and disability insurance
  • Health spending account
  • Flexible working hours
  • On-the-job training and growth opportunities
  • Free on-site parking

$80,000 - $90,000 a year

Salary ranges are based on experience, reflecting the unique skillset each individual brings to the role.

About BIS:

BIS Safety Software has been headquartered in Sherwood Park, Alberta, since 2006. We build software that helps organizations manage safety training, learning, and compliance - and we’re growing!

A few things that make us different: we don’t use job titles internally - we value humility and contribution over hierarchy. We move fast, integrate new ideas quickly, and give people real ownership of their work. And through our Employee Stock Ownership Plan (ESOP), you have the opportunity to own a piece of the company you’re helping build.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Risk and Compliance Analyst
Software Risk and Compliance Analyst

Bis • Sherwood Park

On-site
CAD 90,000 - 120,000
ESOP
Health, dental and vision
Life insurance
+5
Risk and Compliance Team Lead
Risk and Compliance Team Lead

BIS Safety Software • Sherwood Park

On-site
CAD 100,000 - 120,000
ESOP
Full medical, dental, vision
Life insurance
+5
Software Support Representative
Software Support Representative

BIS Safety Software • Toronto

On-site
CAD 52,000 - 76,000
ESOP
Medical, dental, and vision
Life and disability insurance
+3
Office Administrator
Office Administrator

BIS Safety Software • Sherwood Park

On-site
CAD 50,000 - 60,000
ESOP
Medical insurance
Dental coverage
+5
Software Implementation Specialist
Software Implementation Specialist

BIS Safety Software • Toronto

Hybrid
CAD 75,000 - 95,000
ESOP
Medical, dental, and vision coverage
Life insurance and disability
+4
Software Tester (QA/QC)
Software Tester (QA/QC)

BIS Safety Software • Sherwood Park

On-site
CAD 60,000 - 70,000
ESOP
Medical, dental, and vision coverage
Life insurance and disability
+4
Software Tester (QA/QC)
Software Tester (QA/QC)

BIS Safety Software Inc. • Sherwood Park

Hybrid
CAD 60,000 - 70,000
Employee Stock Ownership Plan (ESOP)
Medical, dental, and vision coverage
Life insurance
+4
Office Administrator
Office Administrator

Bis • Sherwood Park

On-site
CAD 42,000 - 60,000
ESOP
Medical, dental, and vision coverage
Life insurance
+4
Software Support Representative
Software Support Representative

BIS Safety Software • Sherwood Park

On-site
CAD 45,000 - 65,000
ESOP
Medical coverage
Dental coverage
+7
Product Requirements Specialist
Product Requirements Specialist

BIS Safety Software • Sherwood Park

Remote
CAD 70,000 - 85,000
ESOP
Health insurance
Dental coverage
+6