New

Senior GRC Analyst - Central or Eastern time, US or Canada

Canada - Remote; Canada - Toronto; US - Boston; US - Remote

Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure—empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve.

 

Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.

Learn more at www.shift-technology.com

 

As a Senior GRC Analyst, you will be a cornerstone of Shift’s security program, responsible for developing, maintaining, and assessing our integrated security and privacy management framework. You will manage our compliance with key industry standards, lead risk assessments, oversee our third-party security assurance program, and support TrustOps efforts for customer collateral, questions, contract reviews, and due diligence. This role is critical for ensuring that Shift meets its regulatory obligations and maintains the trust of our customers. As part of the Information Security department, this role reports to the GRC Lead.

RESPONSIBILITIES

Governance & Policy Management

  • Act as a lead contact to translate Shift’s global information security expectations into actionable policies, standards, and procedures.
  • Promote a mind-set of security and compliance across the organization, transferring knowledge of standards and acting as a subject matter expert (SME).
  • Contribute to the development and support of the security awareness program to ensure it aligns with policy and compliance requirements.
  • Partner with the Data Protection Officer to develop and maintain privacy policies, data handling standards, and public-facing privacy notices in line with privacy laws and global regulations such as GDPR.

Risk Management & Security Assurance

  • Develop and maintain the security assurance plan, ensuring key controls are effectively designed and implemented to meet Shift policies and standards.
  • Improve the third-party information security assurance and continuous assessment process.
  • Identify key risk areas in collaboration with engineering and business teams and facilitate security control evaluations and testing.
  • Review architectural designs and new initiatives to ensure they align with security policies and effectively mitigate risk.
  • Proactively identify potential information security GRC problem areas and execute plans to improve the overall assurance workflow.
  • Support and facilitate Data Protection Impact Assessments (DPIAs) for new products and initiatives.

Compliance & Audits

  • Manage and coordinate internal and external audits for certifications such as ISO 27001 and SOC 2 Type II.
  • Perform analysis and compile documentation and evidence to demonstrate the compliance level of systems, services, and controls.
  • Work with internal teams to manage the remediation of audit findings and track them to closure.
  • Support legal and stakeholder teams in responding to Data Subject Access Requests (DSARs)

Third-Party Risk Management

  • Develop, execute, and improve the third-party information security assurance and continuous assessment process.
  • Communicate with third parties and suppliers to conduct risk assessments, review their security posture, and manage the remediation of identified issues.

SKILLS & BACKGROUND

Experience & Education

  • 7+ years of proven experience in a GRC, IT Audit, Security Assurance, or Information Security role.
  • Bachelor’s Degree in a relevant field or equivalent work experience.
  • Professional certifications such as CIPP/E, CIPP/US, CIPT CISA, CISM, CRISC, or CISSP are highly desirable.
  • Direct experience of delivery in highly regulated industries, i.e financial services, healthcare.
  • Direct experience managing or supporting formal audit and certification processes from start to finish.

Knowledge & Frameworks

  • Deep knowledge of security and privacy frameworks is required (e.g., ISO 27001, ISO27701, SOC 2 Type II, HITRUST, NIST CSF)
  • Strong knowledge of global privacy and healthcare regulations (e.g., GDPR, HIPAA)
  • Working knowledge of AI regulations, frameworks, and standards (e.g., EU AI Act, ISO 42001)
  • Working knowledge of business continuity, disaster recovery, and incident response planning,  including plan structure, exercise and test methodologies.
  • Hands-on experience with modern GRC management tools, preferably Drata - connecting integrations, tuning automated evidence collection and monitoring tests, and building custom controls and frameworks.

Core Competencies

  • Exceptional communication and presentation skills, with the ability to translate complex compliance requirements into clear business guidance.
  • Strong stakeholder management skills with the ability to influence and align teams without direct authority.
  • Highly organized with strong project management skills, capable of managing multiple audits and assessments simultaneously.
  • An analytical mindset with the ability to balance regulatory requirements with business objectives and priorities.

 

RECRUITMENT PROCESS

  • First fit call with our Talent Acquisition Manager
  • Team fit call with the Hiring Manager
  • Tech round with the Team
  • A final interview with our CISO

#LI-RH1 #LI-HYBRID 

 

The range listed is for base compensation.  Your actual base salary will vary based on factors including location and individual qualifications objectively assessed during the interview process. 

In addition to base salary, your total rewards package will include additional components such as incentive pay and benefits.  If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the specific details for this position.

Base Salary Pay Range

$120,000 - $150,000 USD

To support our permanent, full time employees at every stage of their careers and lives, we provide a competitive total rewards and benefits package. Here are the global benefits we’d like to highlight:

  • Flexible remote and hybrid working options
  • Competitive Salary and a variable component tied to personal and company performance
  • Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
  • Generous PTO and paid holidays
  • Mental health benefits 
  • 2 MAD Days per year (Make A Difference Days for paid volunteering)

Additional benefits may be offered by country, based on your eligibility - ask your recruiter for more information. Intern and Apprentice positions may receive some of these benefits - ask your recruiter for more details.

AI tools are used to help review applications for this role. Read our AI in Recruitment Notice for what the AI considers, how to request a human review, and our most recent bias audit.

At Shift we strive to be a diverse and inclusive workforce. We welcome applications from and hire people who will contribute to the diversity of our company, without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria. Shift Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email accommodation@shift-technology.com and we will work with you to meet your accessibility needs.

Please be aware of scammers and only trust correspondence that comes from emails ending in "shift-technology.com". We will never do initial outreach to you via Whatsapp/Text/SMS, never ask for banking information or personal identification numbers (ex. Social Security Number) as part of our recruitment process.

Shift Technology does not accept unsolicited CVs from recruiters or employment agencies in response to the Shift Technology Careers page or a Shift Technology social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Shift Technology.

Create a Job Alert

Interested in building your career at Shift Technology? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf


Select...

Please share any relevant details on your passport, current work visa, expiration dates, etc.

Select...
 
Your personal data is collected by Greenhouse on behalf of Shift Technology to review your application and contact you. The processing of your data is necessary to take steps prior to entering into an employment contract with Shift Technology. 
Your information will be stored in Shift Technology candidate pool for one year from the date of your last contact with us and will be accessible by our recruitment and HR teams, as well as by the team offering the position. It may be transferred to non-European countries that ensure an adequate level of protection according to the European Commission or within the frameworks of the EU-US Privacy Shield or of standard contractual clauses adopted by the European Commission. 
You can request a copy of your data, its deletion or rectification, object to the processing of your data, request the restriction of its processing, and receive your information in portable form by contacting Shift Technology’s data protection officer here: dpo@shift-technology.com
After contacting us, if you are not satisfied with the way we handled your request, you may address a complaint to the supervisory authority of your country. 
By checking this box, you will declare that you read and agree to Shift Technology’s Privacy Policy and therefore authorize us to contact you about future job opportunities for up to 1 year after your last contact with us. 
-----
Greenhouse collecte vos données personnelles pour le compte de Shift Technology pour étudier votre candidature et vous contacter. Le traitement de vos données est nécessaire pour prendre les dispositions préalables à la conclusion d’un contrat de travail avec Shift Technology. 
Vos informations seront conservées dans le vivier de candidats de Shift Technology pendant 1 an à compter de la date de votre dernier contact avec nous. Elles seront accessibles par nos équipes de recrutement et RH ainsi que par l’équipe proposant le poste. 
Elles peuvent être transférées vers des pays tiers à l’Union européenne qui assurent un niveau de protection adéquat reconnu par la Commission européenne ou dans le cadre du « EU-US Privacy Shield » ou encore dans le cadre de clauses contractuelles types adoptées par la Commission européenne. Vous pouvez exercer vos droits d’accès, de rectification, d’opposition, d’effacement, de limitation du traitement et de portabilité pour toutes les données personnelles vous concernant en contactant le Data Protection Officer de Shift Technology à l’adresse suivante: dpo@shift-technology.com
Si vous estimez, après nous avoir contacté, que vos droits sur vos données n’ont pas été respectés, vous pouvez adresser une réclamation à l’autorité de votre pays. 
En cochant cette case, vous déclarez avoir lu et agréé à la Politique de Confidentialité de Shift Technology, nous autorisant ainsi à vous contacter pour de futures opportunités professionnelles pour une durée pouvant aller jusqu’à 1 an après notre dernier contact.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Shift Technology’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...


We use Greenhouse’s AI-powered Talent Matching tool to compare your application against our job requirements. Read our AI in Recruitment Notice for what the AI considers, how to request a human review, and our most recent bias audit.

Learn more