
Governance, Risk & Compliance Analyst
- Toronto, ON
- Permanent
- Temps-plein
- Governance, Policy, and Control Management: Develop, maintain, and enhance cybersecurity and privacy policies, standards, and control frameworks to align with key industry regulations (e.g., PCI DSS, ISO 27001, SOC 2, ISO 42001) and business objectives.
- Risk Management & Assessments: Conduct and coordinate comprehensive cybersecurity risk assessments across the organization to identify, evaluate, and prioritize risks. Develop, monitor, and track risk treatment and remediation plans, providing guidance to stakeholders on mitigation strategies.
- Internal and External Audit Support: Lead and coordinate Docebo's activities for both internal and external audits (e.g., ISO 27001/42001, SOC 2, PCI DSS, SOX), including evidence collection, interfacing with auditors, and managing findings to ensure successful certification and compliance.
- Customer Engagement and Response: Respond to customers' security and privacy related inquiries, compile comprehensive responses (mainly RFI, RFP, and RFQ), and address compliance questionnaires, ensuring timely and accurate information dissemination to actively support the sales process.
- Vendor Risk Assessment and Monitoring: Support the evaluation of company third-party vendor-associated risks, monitor security controls, and maintain risk management reporting dashboards to mitigate risk and effectively qualify company suppliers; in collaboration with the GRC team.
- Cross-functional collaboration: Collaborate across all company departments to embed security controls and align compliance, security, and privacy efforts with business objectives. Consult with departments to assess changes, advise on compliance obligations, and support the evolution of company compliance programs.
- Documentation and Reporting: Maintain comprehensive documentation of compliance activities, including policies, risk assessments, and audit findings. Prepare detailed reports on the status of the GRC program for management and regulatory authorities.
- Typically 4+ years of relevant work experience.
- Working experience IT Risk Management, Governance, or a similar Information Security role.
- Direct, hands-on experience developing security policies, conducting risk assessments, and managing internal/external audit cycles for a SaaS company.
- Working knowledge of information security principles, trends, and best practices, specifically cloud environments and services (eg: AWS, Azure, GCloud).
- Knowledge of GDPR requirements and other data privacy laws (eg: CCPA, PIPEDA).
- Knowledge of ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, ISO 9001, SOX, DORA, NIST CSF, and AICPA/ISAE 3000 SOC 2 & PCI DSS.
- Knowledge of CFR21 Part 11.
- FedRamp framework knowledge.