Benevity Logo

Benevity

Senior GRC Analyst

Posted 12 Days Ago
Be an Early Applicant
In-Office or Remote
2 Locations
Senior level
In-Office or Remote
2 Locations
Senior level
The Senior GRC Analyst at Benevity will lead the execution and improvement of the GRC program, conduct risk assessments, support compliance activities, mentor junior staff, and ensure alignment with regulatory standards.
The summary above was generated by AI

Meet Benevity

Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits. We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more!

High-Level Overview

Benevity is seeking a Senior Governance, Risk & Compliance (GRC) Analyst to elevate our security governance, risk, privacy, and regulatory posture. In this senior role, you will drive the execution, innovation, and continuous improvement of Benevity’s GRC program. You will lead compliance activities, conduct risk assessments, contribute to third-party risk management, respond to client due diligence requests, support FINTRAC/AML obligations, and influence policies and controls that strengthen trust with our clients, partners, and stakeholders.

As a trusted advisor across teams, you will help ensure Benevity aligns with leading standards, privacy laws, and regulatory requirements while fostering a culture of security, compliance, and accountability. You’ll also mentor junior members of the team, helping to grow Benevity’s next generation of security and compliance professionals, with a focus on developing proactive and innovative approaches to GRC challenges.

What you'll do:

Governance & Policy

  • Contribute to the development, maintenance, and rollout of security and privacy policies, standards, and control frameworks aligned to ISO 27001, SOC 2, NIST, PCI DSS, GDPR, PIPEDA, FINTRAC, and other global regulations.
  • Support policy approval, exception management, and attestation processes, actively seeking opportunities for process improvement and automation

Risk Management

  • Lead and execute enterprise-wide risk assessments, including vendor and process-level reviews.
  • Maintain and improve the risk register, track remediation activities, and support risk treatment planning.
  • Contribute to Benevity’s Third-Party Risk Management (TPRM) program, including vendor onboarding assessments, ongoing monitoring, and remediation tracking.

Compliance & Audit

  • Lead audit readiness and response efforts for ISO 27001, SOC 2, PCI DSS, GDPR, PIPEDA, FINTRAC, and other frameworks.
  • Coordinate evidence gathering, control validation, and auditor engagement.
  • Leverage GRC platforms to streamline audit, privacy, and compliance workflows.

Client Support & Sales Enablement

  • Support the sales process by responding to client inquiries related to security, privacy, and compliance.
  • Complete customer security questionnaires, RFPs, and third-party risk management (TPRM) requests.
  • Partner with sales and client success teams to provide timely, accurate responses that build client trust.

Privacy and Regulatory

  • Support privacy-related initiatives across jurisdictions (GDPR, PIPEDA, CCPA/CPRA, and others).
  • Collaborate with legal and data governance teams to ensure compliance with data protection and financial crime regulations.
  • Assist with FINTRAC-related compliance requirements, including reporting and risk assessments related to AML/ATF obligations.
  • Monitor regulatory changes (privacy, AML, financial crime) and help align internal processes accordingly.

Advisory, Awareness & Mentorship

  • Partner with business and technical teams to embed risk and compliance into projects and initiatives.
  • Deliver reporting and insights (dashboards, risk metrics, executive summaries) for leadership.
  • Lead Benevity’s Security Awareness & Training program, including the design, delivery, and continuous improvement of awareness campaigns, training modules, and phishing simulations.
  • Contribute to training, documentation, and awareness activities that strengthen Benevity’s security, privacy, and compliance culture.
  • Mentor and coach junior team members, providing guidance, feedback, and knowledge sharing to support their growth and development.

What you'll bring:

  • 5+ years of experience in cybersecurity, governance, risk, compliance, or privacy, ideally in a SaaS or high-growth environment.
  • Strong knowledge of security, privacy, and regulatory frameworks including ISO 27001, NIST, SOC 2, PCI DSS, GDPR, PIPEDA, FINTRAC, and CCPA/CPRA.
  • Hands-on experience with GRC tooling (e.g., OneTrust, Hyperproof, SecurityPal, AuditBoard, Drata) to manage policies, risks, audits, privacy, and vendor risk workflows.
  • Proven success in conducting risk assessments, managing vendor risk/TPRM, maintaining risk registers, and driving remediation.
  • Experience supporting client due diligence processes (security questionnaires, RFPs, TPRM).
  • Ability to clearly communicate risk, security, privacy, and regulatory concepts to both technical and non-technical stakeholders.
  • Strong organizational and project management skills with experience leading cross-functional initiatives.
  • A demonstrated interest and track record in leveraging automation and AI to streamline GRC processes and enhance efficiency.
  • Certifications such as CISM, CRISC, CISSP, CISA, or CIPM/CIPP are highly valued.


Discover your purpose at work

We’re not employees, we’re Benevity-ites. From all locations, backgrounds and walks of life, who deserve more …

Innovative work. Growth opportunities. Caring co-workers. And a chance to do work that fills us with a sense of purpose.

If the idea of working on tech that helps people do good in the world lights you up ... If you want a career where you’re valued for who you are and challenged to see who you can become …

It’s time to join Benevity. We’re so excited to meet you.

Where We Work

At Benevity, we embrace a flexible hybrid approach to where we work that empowers our people in a way that supports great work, strong relationships, and personal well-being. For those located near one of our offices, while there’s no set requirement for in-office time, we do value the moments when coming together in person helps us build connection and collaboration. Whether it’s for onboarding, project work, or a chance to align and bond as a team, we trust our people to make thoughtful decisions about when showing up in person matters most.

Join a company where DEIB isn’t a buzzword
Diversity, equity, inclusion and belonging are part of Benevity’s DNA. You’ll see the impact of our massive investment in DEIB daily — from our well-supported employee resources groups to the exceptional diversity on our leadership and tech teams.

We know that diverse backgrounds, experiences, skills and passions are what move our business and our people forward, so we're committed to creating a culture of belonging with equal opportunities for everyone to shine. 

That starts with a fair and accessible hiring process. If you want to feel seen, heard and celebrated, you belong at Benevity.

Candidates with disabilities who may require accommodations throughout the hiring or assessment process are encouraged to reach out to [email protected].

HQ

Benevity Calgary, Alberta, CAN Office

611 Meredith Rd NE, Calgary, Alberta, Canada, T2E

Similar Jobs

6 Days Ago
Remote
Canada
Senior level
Senior level
Information Technology
The Senior GRC Analyst will manage Docker's risk program, implement risk assessments, oversee compliance initiatives, and ensure AI governance. This role requires collaboration with various departments to create an effective compliance framework and risk management processes.
Top Skills: AWSAzureDockerGCPIso 27001Iso 27701Iso 42001Nist 800-53Soc 2
9 Hours Ago
In-Office or Remote
CA
Junior
Junior
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
As an Inside Sales Account Executive, you will convert inbound leads into customers and proactively build your pipeline through outbound sales efforts. Responsibilities include managing the sales cycle, engaging with prospects, diagnosing business problems, and collaborating across teams to exceed revenue goals.
Top Skills: Salesforce
9 Hours Ago
In-Office or Remote
CA
Senior level
Senior level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
The Senior Solutions Engineer will collaborate with Sales and Account Management to support seller integrations, advise on suitable Square solutions, and offer ongoing support to strategic sellers and partners.
Top Skills: Full-Stack DevelopmentRestful ApisSaaS

What you need to know about the Calgary Tech Scene

Employees can spend up to one-third of their life at work, so choosing the right company is crucial, not just for the job itself but for the company culture as well. While startups often offer dynamic culture and growth opportunities, large corporations provide benefits like career development and networking, especially appealing to recent graduates. Fortunately, Calgary stands out as a hub for both, recognized as one of Startup Genome's Top 100 Emerging Ecosystems, while also playing host to a number of multinational enterprises. In Calgary, job seekers can find a wide range of opportunities.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account