jobs Logo
Inovatec logo

Governance, Risk, & Compliance Manager

Inovatec1 day ago
Canada
Senior Level
Full-Time

About the role

Governance, Risk & Compliance Manager

About Inovatec

   Inovatec is an exciting growth company based in Vancouver, BC, established in 2006. We are North America’s leading provider of cloud-based software solutions for the automotive, motorcycle, powersports, and equipment financing industries. Our solutions are used by some of the largest banks, credit unions, and finance companies in Canada and the U.S.  

At Inovatec, we foster a diverse and inclusive environment that encourages collaboration where we grow together and win as a team. It’s important that we live up to our four core values: make sound decisions, get better every day, act like an owner, and we before me. We thrive by challenging the status quo to push the industry forward, and we know when to have fun! With team members across North America and Europe, we’re committed to investing in the development of our team, no matter where they’re located.  

Job Summary

Inovatec is hiring a Governance, Risk & Compliance (GRC) Manager to own the day-to-day execution and continued maturity of our security, privacy, and compliance program. This role is central to our shift from point-in-time audits to continuous, evidence-based control monitoring, anchored in our GRC platform, and to keeping Inovatec audit-ready year-round across various compliance frameworks and providing a high level of assurance to our clients.

You will lead a small, focused team, directly managing our Internal Auditor / GRC Specialist, and the two of you will work shoulder-to-shoulder across all governance, risk, audit, and compliance efforts. You will operationalize governance, run our risk management lifecycle, manage third-party risk, and coordinate internal and external audits. Reporting to the Head of Cybersecurity & Compliance, you will partner closely with Infrastructure, Product Engineering, IT, Legal, Finance, and People & Culture. We are looking for a candidate ideally based in Ontario, Canada. 

What You’ll Do

Leadership, Management & Accountability (LMA)

  • Directly manage the Internal Auditor / GRC Specialist, owning coaching, priorities, development, and day-to-day workload, and partnering closely on every governance, risk, audit, and compliance effort.
  • Set clear expectations and a steady operating cadence (1:1s, planning, quarterly goals) so audit and compliance work is delivered predictably and to a high standard.
  • Champion intent-based leadership, growing the autonomy, judgement, and technical depth of your report while ensuring shared coverage and no single points of failure.
  • Serve as a hands-on working manager who leads by doing, shares the workload, and steps into complex assessments and audits alongside your report.

Governance & Compliance Program

  • Own and continuously mature Inovatec’s GRC program across frameworks like SOC 1 & SOC 2 Type II, ISO 27001, ISO 27018 and TISAX.
  • Drive the transition from point-in-time audits to ongoing control monitoring, completing migration of GRC processes into the GRC platform and maintaining ≥90% of controls under continuous monitoring.
  • Automate evidence collection across active frameworks (targeting ≥80% reduction in manual evidence) and maintain a real-time compliance posture dashboard.
  • Manage the policy lifecycle, covering authoring, review cadence, versioning, and employee policy acknowledgment (≥95% target).
  • Own and mature the privacy, compliance, and security awareness training program, ensuring it remains aligned to company policies, client obligations, and applicable compliance frameworks.
  • Support AI compliance readiness, including CSA AI validation and ISO 42001 (AI Management System) compliance.

Risk Management

  • Operate the enterprise risk lifecycle (identification, scoring, categorization, treatment, and workflows aligned to Inovatec’s approved risk policies), with monthly risk snapshots for historical tracking and audit-ready reporting.
  • Maintain the risk register and support quarterly compliance health reviews and board-level risk reporting.
  • Track remediation against SLAs (e.g., <15-day average remediation for compliance drift alerts) and drive closure of audit findings and nonconformities.
  • Contribute to the fraud risk program and segregation-of-duties controls (prevention, detection, response, deterrence).

Third-Party / Vendor Risk

  • Run the Vendor Risk Management (VRM) program end-to-end, covering onboarding, tiering, security risk assessments, continuous monitoring, SOC report reviews, and offboarding.
  • Automate vendor risk assessments for 100% of critical vendors and publish a vendor risk dashboard showing tier coverage and remediation status.
  • Enforce third-party information security requirements and confidentiality obligations prior to engagement.

Audit & Assurance

  • Coordinate internal and external audits, managing scope, evidence, fieldwork logistics, and corrective actions in close partnership with the Internal Auditor / GRC Specialist.
  • Maintain the Statement of Applicability, control mappings, and audit calendar, ensuring zero missed compliance deadlines for external audits or certifications.
  • Support client due diligence, and security questionnaires and requests with accurate, evidence-backed responses.

What You Bring

  • 6–10+ years in governance, risk, and compliance, information security, or IT audit, ideally in a multi-tenant SaaS or regulated (financial services) environment.
  • Direct people-management or team-lead experience, or clear readiness to manage and develop one direct report.
  • Hands-on experience running or maturing programs across SOC 1/2, and ISO 27001/27018, with familiarity of emerging AI frameworks (ISO 42001, CSA AI).
  • Practical experience with a GRC / continuous-compliance platform (Vanta preferred) and control-monitoring automation.
  • Strong grasp of risk assessment methodology, control frameworks, and third-party / vendor risk management (BitSight or similar a plus).
  • Experience coordinating external audits and managing remediation of findings to closure.
  • Excellent documentation discipline and evidence rigor, able to translate control requirements into clear, defensible artifacts.
  • Strong cross-functional communication, comfortable engaging Engineering, IT, Legal, Finance, executives, clients, and auditors.

Nice to Have

  • Experience working with regulated financial-services clients, SaaS platforms, or enterprise B2B environments is strongly preferred.
  • Relevant certifications (e.g., CISA, CRISC, CISSP, ISO 27001 Lead Auditor / Implementer).
  • Privacy program experience (PIPEDA, Quebec Law 25, ISO 27018).
  • Familiarity with the Microsoft / Azure security stack (Entra ID, Defender, Sentinel) as it relates to control evidence.
  • Experience supporting M&A / investor due diligence.

Our Core Values

  • Act like an owner: no matter the challenge, we overcome hurdles, seek out solutions, and follow through on commitments to consistently exceed expectations.
  • Make sound decisions: we put ourselves in our customer’s shoes, always ensuring we have the right facts and focus on solving the right problems.
  • Get better every day: with our growth mindset and positive attitude, we apply our passion for innovation not just to our products, but also to ourselves.
  • We before me: our collaborative spirit pushes us to act without ego, to communicate openly and honestly, and to win as a team.

About Inovatec

IT Services and IT Consulting
51-200 employees
Founded in 2006

Inovatec Systems is industry leader in cloud‑based software for automotive and powersport lending across the full loan lifecycle. We are one of the few providers who support lease and loans for consumer and commercial Lines of Business.

Our modular platform includes a Loan Origination System (LOS), Loan Management System (LMS), and a configurable dealer or consumer application portal, giving lenders the tools to manage lending workflows from application intake and underwriting through funding and ongoing servicing.

Designed for flexibility, Inovatec enables organizations to configure workflows, business rules, and integrations to fit their lending products and operating models. With open APIs and a broad ecosystem of third‑party integrations, the platform connects seamlessly across credit, compliance, documentation, payments, and servicing systems.

As lending programs evolve, Inovatec helps lenders modernize their technology with a platform built for scalability, configurability, and long‑term stability.

Similar Jobs