SlipstreamJobsFresh Startup & VC-Backed Jobs

Chef d'équipe GRC

Nesto - Remote - Remote - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Nesto Cloud is Canada's end-to-end cloud-native mortgage technology platform powered by AI. The company helps financial institutions modernize lending through intelligent AI automation, proprietary AI and cloud technology, and business process outsourcing (BPO) solutions. Nesto Group manages over CAD 80 billion in residential and commercial mortgage loans and is recognized as one of Canada's fastest-growing mortgage lenders, having won the Canadian Lenders Association Lender of the Year award in 2023, 2024, and 2025. The GRC (Governance, Risk & Compliance) Team Lead holds end-to-end responsibility for Nesto's governance, risk management, and compliance program. The company has built solid foundations and automated much of its compliance workflows; this role will elevate the program to world-class execution. Key responsibilities include: • Assume governance of security policies and control mapping across Nesto's compliance frameworks (SOC 1/2, ISO 27001, and applicable regulatory frameworks). • Mature the automated compliance program to scale sustainably with Nesto's growth. Optimize the GRC platform and automation tools for self-service workflows while progressively eliminating manual audit preparation. • Elevate the quality of Nesto's external audit program while continuously expanding its scope as the enterprise expands. • Evolve Nesto's AI governance framework in collaboration with engineering and compliance teams, moving from foundational policies to enterprise-level controls enabling rapid and secure internal deployment and use of AI-based features. • Transform risk management into a strategic business advisor. Collaborate with business unit leaders to evolve risk analyses, connect technical findings to business impacts, and enable leadership to make informed trade-offs with confidence. • Scale vendor and customer security assessments. Evolve onboarding workflows, refine questionnaire automation, and strengthen how Nesto communicates its security posture to enterprise prospects and customers. • Lead and develop a GRC team that elevates technical excellence standards, deepens expertise in governance and risk management disciplines, and fosters accountability across all initiatives. • Strengthen organizational resilience through advanced and regularly tested business continuity and disaster recovery frameworks, ensuring Nesto's operational confidence during crises. The role offers flexible work arrangements (fully remote or from offices in Montreal, Quebec, Toronto, etc.), comprehensive health coverage (medical, dental, vision with 100% drug coverage), RRSP/RPDB retirement savings with competitive employer matching, telemedicine and family support programs, and exclusive employee mortgage rates. REQUIREMENTS: • More than 10 years of experience in GRC, audit, risk management, or compliance in regulated industries (financial services, SaaS, healthcare). • Excellent mastery of SOC 1, SOC 2, and NIST frameworks and audits. • Solid knowledge of risk assessment methodologies and compliance operations. • Hands-on experience with GRC automation platforms. • Excellent project management, stakeholder engagement, and cross-functional collaboration skills. • Strong writing capabilities; ability to clearly communicate policy and control concepts to technical and non-technical audiences. • Ability to influence leadership through evidence-based risk analysis and perspectives aligned with business objectives. • English required for writing and documentation. French proficiency (spoken and read) is a major asset.

Similar roles