GRC Manager Automation
Job Summary
AtAlayaCareweremore than just a fast-growing SaaS companywerea team of people passionate about transforming home healthcare. Our cloud-based platform empowers care providers around the world to deliver better outcomes for their clients.
With 550 employees across Canada the US Australia and Brazilwereunited by a shared mission and a strong culture of transparency growth and human connection. Whetheryoureearly in your career or a seasoned expertAlayaCareoffers the opportunity to grow your impact your skills and your career.
We are seeking aGRC Managerto join our Security team. Reporting to the Director Information Security and Privacy you will be responsible for leading and evolving AlayaCares security governance risk management privacy and regulatory compliance programs within a modern B2B SaaS environment. This role combines subject-matter expertise with practical experience operating GRC programs at scale ensuring that security and compliance practices effectively support business objectives.
As a key member of the team you will have the chance to collaborate closely with colleagues across Engineering IT Legal Privacy and other internal stakeholders to strengthen the companys governance risk and compliance capabilities. Key areas of focus include supporting security certifications and audits improving risk visibility enhancing vendor assurance practices and building scalable control processes that enable the organization to grow confidently while meeting customer and regulatory requirements.
What makes the role interesting is that it sits at the intersection of engineering and governance. This position will influence how security privacy and compliance enable the companys continued growth and innovation in the healthcare technology space
- Lead the ongoing maturity of the companys compliance programs and certifications (e.g. SOC 1/2 HITRUST HIPAA ISO 27001/27701) ensuring continuous readiness rather than point-in-time audit preparation.
- Contribute to defining and executing the multi-year strategy and roadmap for Governance Risk and Compliance across the organization.
- Serve as the primary point of coordination for external auditors assessors and customer security due diligence activities.
- Partner with Engineering and IT leadership to embed controls directly into cloud and DevOps workflows reducing manual compliance overhead through automation.
- Design scalable control frameworks that align security privacy and engineering practices with regulatory and contractual requirements.
- Establish and maintain a company-wide risk management program including risk assessments risk registers prioritization frameworks and executive reporting.
- Lead third-party and vendor risk management activities including security reviews ongoing monitoring and contractual safeguards.
- Oversee policy governance to ensure policies and standards remain clear actionable and aligned with business realities.
- Develop write and maintain policies procedures and documentation to support compliance initiatives.
- Define and track KPIs and metrics to measure security posture compliance health and risk trends and communicate insights to senior leadership.
- Support Sales and Customer Success by enabling fast accurate responses to RFPs security questionnaires and enterprise trust reviews.
- Encourage a culture of shared ownership by supporting and guiding control owners and stakeholders across departments.
- Continuously identify opportunities to simplify automate and improve the GRC operating model.
- Bachelors or advanced degree in cybersecurity computer science or related fields.
- 8-10 years of hands-on experience leading and scaling GRC or compliance programs in a SaaS or cloud-first environment
- Experience owning external audits and certifications end-to-end (e.g. SOC 1 SOC 2 ISO 27001 HITRUST HIPAA).
- Solid understanding of modern cloud and DevOps environments (AWS preferred) and how security and compliance controls apply to SaaS architectures.
- Experience implementing and optimizing GRC or evidence automation platforms (e.g. Vanta Drata or similar).
- Strong knowledge of risk management methodologies and the ability to translate technical risk into business impact.
- Experience with GRC engineering practices automation or AI-assisted compliance workflows.
- Demonstrated ability to influence cross-functional stakeholders and drive alignment without direct authority.
- Strong program management skills with the ability to manage multiple initiatives in parallel.
- Excellent written and verbal communication skills with the ability to simplify complex security and compliance topics.
- Hands-on mindset comfortable operating across both strategy and execution.
- Familiarity with emerging governance areas such as AI governance data governance or modern regulatory frameworks.
- Comfortable participating in customer-facing security and compliance discussions including audits due diligence calls and trust reviews.
- Interest in evolving traditional compliance practices toward a more automated engineering-driven approach.
- Bilingual in French and English
- Experience working in healthcare or other highly regulated industries.
- Experience with HITRUST (i1 or r2) or similar healthcare-focused compliance frameworks.
- Experience integrating privacy regulations (e.g. PHIPA HIPAA PIPEDA GDPR) into technical and operational controls.
- Experience building or operating Trust Centers or customer-facing security assurance programs.
- Background working in fast-growing SaaS startups or scale-ups.
AtAlayaCareyoullhelp build technology that empowers care providers and improves outcomes for patients and families. Every line of code and every customer interactioncontributesto making care more connected accessible and human.
We believe in transparency feedback and assuming positive intent. Hereyoullfeel safe to share your ideas and career goals and be supported to achieve them through mentorship career mobility and a promote-from-within philosophy.
We value flexibility and well-being. From Wellness Fridays to volunteer time off to flexible vacation we make sure you have the space to recharge contribute to your community and live your best life.
- Equity in a well-funded scaling company.
- Comprehensive health benefits telemedicine and lifestyle spending accounts.
- Parental leave top-up and family support programs.
We celebrate diverse perspectives and foster belonging through our DEIB initiatives. Employee-led events summits and social activities both in-person and virtual create meaningful connections across our global teams.
This role is based in Montreal. At AlayaCare our hybrid model includes 2 set in-office collaboration days/week and it is expected that team members are present in the office on those days to foster connection innovation and teamwork.
Apply today and be part of a company that makes a real difference in the future of home and community care. Not the right role for you Share thispostingwith someone who might be a great fit.
AlayaCareuses AI tools during our hiring process to support fair consistent and objective decision-making. Someinitialscreening steps may be automated to helpidentifyqualified candidates. If your application is declined automatically you may request a human review.
Werecommitted to creating a workplace where everyone belongs. If you require accommodation during the application process please reach out to.
Required Experience:
Manager
About Company
Learn how our cloud-based solution can help you manage your home health or infusion agency more efficiently and effectively.