SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Lead

Nesto - Canada - Hybrid - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Nesto Cloud is Canada's cloud-native, AI-driven mortgage technology platform serving financial institutions. The company combines 50+ years of mortgage expertise with proprietary cloud and AI technology, administering over CAD $80 billion in residential and commercial mortgages. Recognized as a Deloitte Fast 50 company for three consecutive years, Nesto operates through CMLS, nesto, and Nesto Cloud brands. The GRC Lead owns Nesto's governance, risk, and compliance program end-to-end. The role involves taking a program with strong foundations and automated compliance workflows and elevating it to world-class execution. Key responsibilities include: • Own security policy governance and control mapping across compliance frameworks (SOC 1/2, ISO 27001, and applicable regulatory frameworks) • Mature the automated compliance program to scale sustainably; optimize GRC platforms and automation tools for self-service workflows • Elevate the external audit program while expanding scope as the business scales • Evolve AI governance framework in collaboration with Engineering and Compliance teams, from foundational policies to enterprise-grade controls enabling rapid, safe AI feature deployment • Transform risk management into strategic business advisory; collaborate with business unit leaders on risk narratives and enable informed trade-offs • Scale vendor and client security assessments; evolve intake workflows and questionnaire automation • Lead and develop a GRC team, raising the bar on technical excellence and driving accountability • Strengthen organizational resilience through evolved, regularly tested Business Continuity and Disaster Recovery frameworks The role is hybrid-based in Canada. Nesto offers premium benefits (fully paid by company), comprehensive insurance, unlimited telemedicine and mental health services, 4 weeks vacation, and access to best-in-class tools. REQUIREMENTS: • 10+ years of GRC, audit, risk management, or compliance experience in regulated industries (financial services, SaaS, healthcare) • Deep experience across SOC1, SOC2, NIST frameworks and audits • Strong knowledge of risk assessment methodologies and compliance operations • Hands-on experience with GRC automation platforms • Excellent project management, stakeholder engagement, and cross-functional collaboration skills • Strong writing skills; ability to communicate policy and control concepts to technical and non-technical audiences • Ability to influence leadership through evidence-based risk narratives and business-aligned insights • English required for writing and documentation; French speaking and reading is a strong plus

Similar roles