JobRaahGet matched free

Jobs

Senior GRC Analyst - Central or Eastern time, US or Canada

Shift Technology · Canada - Remote; Canada - Toronto; US - Boston; US - Remote · United States · Remote

Pay: USD 120,000 – 150,000 a year

Posted Sep 22, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure—empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve. Your browser does not support the video tag. Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance. Learn more at www.shift-technology.com As a Senior GRC Analyst, you will be a cornerstone of Shift’s security program, responsible for developing, maintaining, and assessing our integrated security and privacy management framework. You will manage our compliance with key industry standards, lead risk assessments, oversee our third-party security assurance program, and support TrustOps efforts for customer collateral, questions, contract reviews, and due diligence. This role is critical for ensuring that Shift meets its regulatory obligations and maintains the trust of our customers. As part of the Information Security department, this role reports to the GRC Lead. RESPONSIBILITIES Governance & Policy Management Act as a lead contact to translate Shift’s global information security expectations into actionable policies, standards, and procedures. Promote a mind-set of security and compliance across the organization, transferring knowledge of standards and acting as a subject matter expert (SME). Contribute to the development and support of the security awareness program to ensure it aligns with policy and compliance requirements. Partner with the Data Protection Officer to develop and maintain privacy policies, data handling standards, and public-facing privacy notices in line with privacy laws and global regulations such as GDPR. Risk Management & Security Assurance Develop and maintain the security assurance plan, ensuring key controls are effectively designed and implemented to meet Shift policies and standards. Improve the third-party information security assurance and continuous assessment process. Identify key risk areas in collaboration with engineering and business teams and facilitate security control evaluations and testing. Review architectural designs and new initiatives to ensure they align with security policies and effectively mitigate risk. Proactively identify potential information security GRC problem areas and execute plans to improve the overall assurance workflow. Support and facilitate Data Protection Impact Assessments (DPIAs) for new products and initiatives. Compliance & Audits Manage and coordinate internal and external audits for certifications such as ISO 27001 and SOC 2 Type II. Perform…