SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Nesto Cloud is Canada's cloud-native, AI-driven mortgage technology platform serving financial institutions. The company combines 50+ years of mortgage expertise with proprietary cloud and AI technology, administering over CAD $80 billion in residential and commercial mortgages. Recognized as a Deloitte Fast 50 company for three consecutive years, Nesto operates through CMLS, nesto, and Nesto Cloud brands.
The GRC Lead owns Nesto's governance, risk, and compliance program end-to-end. The role involves taking a program with strong foundations and automated compliance workflows and elevating it to world-class execution. Key responsibilities include:
• Own security policy governance and control mapping across compliance frameworks (SOC 1/2, ISO 27001, and applicable regulatory frameworks)
• Mature the automated compliance program to scale sustainably; optimize GRC platforms and automation tools for self-service workflows
• Elevate the external audit program while expanding scope as the business scales
• Evolve AI governance framework in collaboration with Engineering and Compliance teams, from foundational policies to enterprise-grade controls enabling rapid, safe AI feature deployment
• Transform risk management into strategic business advisory; collaborate with business unit leaders on risk narratives and enable informed trade-offs
• Scale vendor and client security assessments; evolve intake workflows and questionnaire automation
• Lead and develop a GRC team, raising the bar on technical excellence and driving accountability
• Strengthen organizational resilience through evolved, regularly tested Business Continuity and Disaster Recovery frameworks
The role is hybrid-based in Canada. Nesto offers premium benefits (fully paid by company), comprehensive insurance, unlimited telemedicine and mental health services, 4 weeks vacation, and access to best-in-class tools.
REQUIREMENTS:
• 10+ years of GRC, audit, risk management, or compliance experience in regulated industries (financial services, SaaS, healthcare)
• Deep experience across SOC1, SOC2, NIST frameworks and audits
• Strong knowledge of risk assessment methodologies and compliance operations
• Hands-on experience with GRC automation platforms
• Excellent project management, stakeholder engagement, and cross-functional collaboration skills
• Strong writing skills; ability to communicate policy and control concepts to technical and non-technical audiences
• Ability to influence leadership through evidence-based risk narratives and business-aligned insights
• English required for writing and documentation; French speaking and reading is a strong plus