JobTarget Logo

GRC Principal - Data Privacy and Security in Canada Creek, Nova Scotia at Jobgether

NewJob Function: Safety
Jobgether
Canada Creek, Nova Scotia, B0P 1V0, Canada
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

GRC Principal - Data Privacy and Security

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Principal - Data Privacy and Security based in Canada.

This is a senior individual-contributor role responsible for shaping and advancing enterprise security, privacy, and governance programs.
You will provide strategic direction while remaining deeply involved in the execution, measurement, and continuous improvement of GRC initiatives.
The role spans security compliance, privacy governance, third-party risk, customer assurance, and emerging AI governance.
You will help evolve audit readiness from a periodic exercise into a durable, evidence-driven operating discipline.
Working across Legal, Security, Business, and executive stakeholders, you will translate complex regulatory and technical risks into actionable business decisions.
The environment is highly autonomous and fast-paced, requiring strong judgment, systems thinking, and a focus on measurable outcomes.
This opportunity is particularly suited to a GRC leader who can combine deep technical expertise with strategic influence and responsible adoption of AI.

Accountabilities
  • Lead the end-to-end annual SOC 1 and SOC 2 Type II audit lifecycle, including control readiness, evidence collection, auditor coordination, reporting, and remediation.
  • Own and continuously evolve the Information Security Management System (ISMS), policies, and control framework, with consideration for additional standards such as ISO compliance.
  • Develop and mature vendor and third-party risk management programs, including frameworks, prioritization, stakeholder engagement, and performance measurement.
  • Lead customer assurance activities, including enterprise security reviews, customer and prospect questionnaires, and cyber-insurance assessments.
  • Scale security and privacy documentation, processes, and mechanisms to support enterprise growth and customer trust.
  • Build and evolve data governance practices across the complete data lifecycle, including collection, storage, access, retention, classification, and deletion.
  • Own the privacy compliance program across GDPR and CCPA, including data mapping, DSAR operations, retention practices, and privacy governance.
  • Partner with Legal on Data Processing Agreements (DPAs), subprocessor obligations, and privacy-by-design practices within products and services.
  • Establish and advance enterprise AI data governance policies, standards, and controls across the AI/ML lifecycle for internally developed and third-party AI solutions.
  • Monitor emerging regulatory and industry frameworks, including NIST AI RMF, ISO 42001, and the EU AI Act, and translate developments into practical organizational requirements.
  • Serve as a trusted subject-matter authority for security, privacy, risk, governance, and compliance matters across the organization.
  • Translate technical, regulatory, and operational risks into clear business implications and recommendations for executives and senior stakeholders.
  • Manage cross-functional GRC initiatives, establishing priorities, tracking progress, measuring outcomes, communicating risks, and escalating decisions when necessary.
  • Mentor cross-functional partners and team members while establishing high standards for governance and compliance practices.
  • Identify opportunities to use AI to automate GRC activities, improve efficiency, and increase the measurable impact of governance programs.
Requirements
  • 10+ years of experience across GRC, information security, privacy, and compliance, with a proven history of building, scaling, and operating rigorous programs; fintech, payments, SaaS, or startup experience is highly desirable.
  • Deep hands-on expertise with security frameworks and standards such as SOC 2, ISO 27001, and PCI DSS.
  • Strong privacy compliance experience covering GDPR, CCPA, DSAR operations, data mapping, data governance, and privacy controls.
  • Demonstrated ownership of SOC audit lifecycles, enterprise risk management, and third-party/vendor risk programs.
  • Proven ability to leverage AI to automate GRC workloads, improve operational efficiency, and deliver measurable outcomes.
  • Working knowledge of AI/ML governance and emerging regulatory requirements, with the ability to establish practical policies and controls in evolving areas.
  • Exceptional project and program management skills, including prioritization, measurement, risk management, stakeholder communication, and executive reporting.
  • Excellent judgment, integrity, discretion, and confidentiality when handling sensitive information and making complex risk trade-offs.
  • Strong cross-functional influence and communication skills, with the ability to work effectively with executives, technical teams, auditors, legal stakeholders, and enterprise customers without direct authority.
  • Strong strategic thinking and systems-thinking capabilities, with a focus on outcomes, risk appetite, business priorities, and long-term program maturity.
  • Relevant professional certifications are an advantage, including CISSP, CISA, CISM, CRISC, CIPP, CIPM, CIPT, and/or AIGP.
  • Comfortable working autonomously in a high-ambiguity, rapidly evolving environment.
Benefits
  • Compensation: CA$143,000–CA$197,000 annually for Canada-based employees, depending on geographic market zone and relevant factors; compensation may be supplemented by bonus, equity, and other benefits where applicable.
  • Remote flexibility: Work from anywhere in Canada or the United States.
  • Unlimited paid time off.
  • Health and dental benefits.
  • Up to CA$2,025 toward home IT setup.
  • Up to 2% matching RRSP / 401(k) contributions.
  • Learning and development opportunities.
  • Up to CA$67.50 toward internet or cell phone service.
  • Opportunity to work on high-impact security, privacy, compliance, and AI governance initiatives.
  • High-autonomy environment with significant influence over long-term GRC strategy and program maturity.
  • Collaborative culture focused on creativity, continuous improvement, and meaningful business impact.
  • Commitment to an inclusive, respectful, and discrimination-free workplace.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Job Location

Canada Creek, Nova Scotia, B0P 1V0, Canada

Frequently asked questions about this position

Similar Jobs In Canada Creek, Nova Scotia

New

Head of Creative Strategy

Jobgether
Canada Creek, Nova Scotia
Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.