
Security Compliance & Customer Assurance Analyst
About Behavox:
Behavox is shaping the future for how businesses harness their most important raw material - data. Our mission is bold: Organize enterprise data into actionable information that protects and promotes the business growth of multinational companies around the world.
From managing enterprise risk and compliance to maximizing revenue and value, our data operating platform presents a widespread opportunity to build multilingual, AI/ML-based solutions that activate data for every function within a global enterprise.
Our approach is unique, and it’s validated by our customers who tell us to keep forging ahead because no one else is aggregating, analyzing, and acting on data to uncover opportunities or solve problems quite the way we are.
We are looking for fearless innovators who have an insatiable appetite for building what no one has built before.
This is a hybrid role with 1 day in the office, with an opportunity to work remotely if you reside 100 km away from Toronto or Montreal office.
About the Role:
The Security Compliance & Customer Assurance Analyst owns the execution of defined compliance, customer assurance, risk management, and audit-support activities. The role maintains the internal risk register and the Drata compliance platform by updating control evidence, tracking remediation activities, maintaining audit records, and preparing documentation for internal and external audits in alignment with established security policies and audit requirements.
The role works closely with Revenue teams to support prospective and existing customer engagements. The analyst coordinates and completes security and compliance sections of RFIs, customer security questionnaires, and annual internal and customer risk assessments using approved policies, certifications, control documentation, and evidence.
The analyst participates in customer calls to clarify the organization’s documented security and compliance posture and coordinates follow-up actions with relevant internal owners. The role is expected to be proficient in using Behavox AI tooling to automate and accelerate approved compliance and customer-assurance workflows while ensuring outputs are validated against authoritative internal sources before use.
The candidate must have relevant experience supporting compliance and audit activities and hold, at minimum, a recognized Internal ISO 27001 Lead Auditor certification. This certification is applied to evidence assessment, control testing support, audit preparation, and the documentation of findings under defined audit methodologies
What You'll Bring:
- Customer security assurance: Applies knowledge of customer due diligence, RFIs, security questionnaires, and annual risk assessments to determine evidence requirements and prepare complete, supportable responses.
- Information security and compliance frameworks: Interprets applicable control requirements and certification evidence, including SOC 2, ISO 27001, and ISO 42001 (optional), when supporting customer assurance and audit activities.
- Audit methodology and evidence standards: Applies knowledge supported by a recognized ISO 27001 Lead Auditor certification to evidence assessment, control testing, workpaper preparation, gap documentation, and audit-readiness activities.
- Risk and remediation governance: Understands risk identification, risk-register maintenance, control-gap documentation, remediation ownership, status tracking, and closure-evidence requirements.
- AI-enabled compliance workflows: Understands how various AI tools can support evidence analysis, questionnaire drafting, content summarization, and workflow automation while maintaining accuracy, confidentiality, and human review.
What You'll Do:
- Security RFI and questionnaire completion: Owns assigned security and compliance RFIs and questionnaires from intake through internal review, producing accurate responses supported by approved evidence and documented controls.
- Customer risk assessment support: Coordinates annual customer risk assessments, identifies required inputs, resolves evidence gaps with internal owners, and prepares complete response packages within agreed timelines.
- Customer assurance call participation: Clarifies documented security controls, certifications, and compliance practices during customer calls and records unresolved questions for follow-up by authorized subject-matter owners.
- Risk register and GRC platform maintenance: Maintains risk records, control evidence, remediation status, and audit documentation in GRC platforms and in approved repositories, ensuring accuracy, traceability, and readiness for review.
- Workflow AI automation: Uses AI tooling to automate and accelerate approved compliance activities, including initial questionnaire drafting, evidence summarization, and content organization, while validating outputs before internal or customer-facing use.
What We Offer
- The opportunity to work on a global, mission-critical AI platform alongside the best engineers and technologists across multiple geographies
- A role with real ownership and impact, building complex systems at scale in an environment that values speed, experimentation, and technical excellence
- A highly attractive benefits package, including competitive cash compensation, an equity award aligned with long-term value creation, and comprehensive health insurance for employees and their families
- A generous time-off policy of 30 days annually, plus public holidays and sick leave, recognizing the importance of sustained high performance
About Our Process
We take Talent very seriously and we are building a community of extraordinary individuals working together in very high performing teams. We also know that the best Talent always has options so we believe that the process has to be a two way assessment - the company AND the candidate assessing the business needs alignment, the career next step alignment, and the cultural alignment.
During the process we will begin by exploring the core factors regarding salary and location along with core experience and skills and values alignment. We will then deep dive explore the critical technical competencies we have identified for the role, and then we will deep dive in behavioral competencies.
The most aligned candidate will then be asked to do a practical work task simulation activity so we can make sure that you will enjoy the kind of work the role requires, and this task will typically be presented and discussed with a group of colleagues and managers. Finally we will ask you to meet with a number of our senior leaders to make sure that you are making the most informed call possible.
Please note that:
- We want to get to know you and have a genuine conversation, so the use of AI tools or assistance during live interviews is strictly prohibited and will result in immediate disqualification from the process.
- Interviews may be recorded for internal review purposes to ensure fairness and enable collaborative hiring discussions within the team.
Apply for this job
*
indicates a required field