1

Grc Jobs in Calgary, AB (NOW HIRING)

Reporting to the Cybersecurity Manager, the ideal candidate will have a solid understanding of GRC principles, experience in compliance activities, and a proactive approach to assessing and managing ...

Internal Auditor

Calgary, AB · On-site

CA$60K - CA$70K/yr

Proficiency with Microsoft Excel, Powerpoint and Word; comfort in learning audit tools (e.g., GRC platforms) and data tools * Strong analytical, written and verbal communication skills, with ...

Grc information

See Calgary, AB salary details

$38K

$125.8K

$192K

How much do grc jobs pay per year?

As of Sep 1, 2026, the average yearly pay for grc in Calgary, AB is $125,770.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,500.00 and $145,500.00 per year, depending on experience, location, and employer.

What is a GRC?

A GRC (Governance, Risk, and Compliance) job involves managing an organization's policies, regulations, and risk management frameworks to ensure compliance with legal and industry standards. Professionals in this role assess risks, implement controls, and develop strategies to mitigate potential threats while aligning business operations with regulatory requirements. They often work with stakeholders across IT, security, and legal departments to maintain compliance and improve risk management processes.

What are the daily responsibilities of a GRC professional?

In a GRC position, your day-to-day tasks often include conducting risk assessments, monitoring compliance with internal policies and external regulations, and collaborating with various departments to implement controls or corrective actions. You may also manage and update policies, prepare reports for management, and respond to regulatory audits or inquiries. Additionally, GRC professionals facilitate training sessions to improve organizational awareness of risks and ensure ongoing adherence to compliance standards. The role is dynamic and involves proactive problem-solving to help keep the organization secure and compliant.

What are the key skills and qualifications needed for a GRC role?

To thrive in a GRC (Governance, Risk, and Compliance) role, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance standards, often supported by a degree in business, information technology, or a related field. Familiarity with GRC software platforms (such as RSA Archer, LogicGate, or MetricStream), and professional certifications like CRISC, CISA, or CISSP, are highly valued. Strong analytical thinking, attention to detail, and clear communication skills are important for interpreting regulations and working with cross-functional teams. These skills ensure that organizations manage risks effectively, meet regulatory requirements, and maintain enterprise-wide compliance.

Are GRC jobs hard to get?

GRC (Governance, Risk, and Compliance) jobs can be competitive, especially for entry-level positions, but having relevant certifications like CISA or CISSP and experience with compliance frameworks can improve your chances. The difficulty of securing a GRC role depends on your skills, education, and the current job market demand for compliance professionals.

Is GRC a good career?

GRC (Governance, Risk, and Compliance) is a growing field within cybersecurity and corporate management, focusing on ensuring organizations meet regulatory requirements and manage risks effectively. It often requires knowledge of compliance standards, risk assessment, and security frameworks, with certifications like CISA or CISSP enhancing job prospects. The career offers opportunities in various industries, with roles typically involving analysis, policy development, and audits.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) roles remain in demand as organizations prioritize cybersecurity, regulatory adherence, and risk management. Professionals with skills in compliance frameworks, audit, and security tools are sought after across various industries, especially in regulated sectors like finance and healthcare.

What are GRC jobs?

GRC jobs refer to roles focused on Governance, Risk Management, and Compliance within organizations. These positions involve developing policies, assessing risks, ensuring regulatory adherence, and often require knowledge of frameworks like ISO, COBIT, or NIST, as well as certifications such as CISA or CISSP.

What are popular job titles related to Grc jobs in Calgary, AB?

For Grc jobs in Calgary, AB, the most frequently searched job titles are:

What job categories do people searching Grc jobs in Calgary, AB look for?

The top searched job categories for Grc jobs in Calgary, AB are:

Infographic showing various Grc job openings in Calgary, AB as of August 2026, with employment types broken down into 1% As Needed, 90% Full Time, 4% Part Time, and 5% Contract. Highlights an 74% Physical, 8% Hybrid, and 18% Remote job distribution, with an average salary of $125,770 per year, or $60.5 per hour.

Security Compliance & Customer Assurance Analyst

Behavox

Calgary, AB • Hybrid

Full-time

Medical

Posted 6 days ago


Job description

About Behavox:

Behavox is shaping the future for how businesses harness their most important raw material - data. Our mission is bold: Organize enterprise data into actionable information that protects and promotes the business growth of multinational companies around the world. 

From managing enterprise risk and compliance to maximizing revenue and value, our data operating platform presents a widespread opportunity to build multilingual, AI/ML-based solutions that activate data for every function within a global enterprise. 

Our approach is unique, and it's validated by our customers who tell us to keep forging ahead because no one else is aggregating, analyzing, and acting on data to uncover opportunities or solve problems quite the way we are.

We are looking for fearless innovators who have an insatiable appetite for building what no one has built before.

This is a hybrid role with 1 day in the office, with an opportunity to work remotely if you reside 100 km away from Toronto or Montreal office. 

About the Role:

The Security Compliance & Customer Assurance Analyst owns the execution of defined compliance, customer assurance, risk management, and audit-support activities. The role maintains the internal risk register and the Drata compliance platform by updating control evidence, tracking remediation activities, maintaining audit records, and preparing documentation for internal and external audits in alignment with established security policies and audit requirements.

The role works closely with Revenue teams to support prospective and existing customer engagements. The analyst coordinates and completes security and compliance sections of RFIs, customer security questionnaires, and annual internal and customer risk assessments using approved policies, certifications, control documentation, and evidence.

The analyst participates in customer calls to clarify the organization's documented security and compliance posture and coordinates follow-up actions with relevant internal owners. The role is expected to be proficient in using Behavox AI tooling to automate and accelerate approved compliance and customer-assurance workflows while ensuring outputs are validated against authoritative internal sources before use.

The candidate must have relevant experience supporting compliance and audit activities and hold, at minimum, a recognized Internal ISO 27001 Lead Auditor certification. This certification is applied to evidence assessment, control testing support, audit preparation, and the documentation of findings under defined audit methodologies

What You'll Bring:

  1. Customer security assurance: Applies knowledge of customer due diligence, RFIs, security questionnaires, and annual risk assessments to determine evidence requirements and prepare complete, supportable responses.
  2. Information security and compliance frameworks: Interprets applicable control requirements and certification evidence, including SOC 2, ISO 27001, and ISO 42001 (optional), when supporting customer assurance and audit activities.
  3. Audit methodology and evidence standards: Applies knowledge supported by a recognized ISO 27001 Lead Auditor certification to evidence assessment, control testing, workpaper preparation, gap documentation, and audit-readiness activities.
  4. Risk and remediation governance: Understands risk identification, risk-register maintenance, control-gap documentation, remediation ownership, status tracking, and closure-evidence requirements.
  5. AI-enabled compliance workflows: Understands how various AI tools can support evidence analysis, questionnaire drafting, content summarization, and workflow automation while maintaining accuracy, confidentiality, and human review.

What You'll Do:

  1. Security RFI and questionnaire completion: Owns assigned security and compliance RFIs and questionnaires from intake through internal review, producing accurate responses supported by approved evidence and documented controls.
  2. Customer risk assessment support: Coordinates annual customer risk assessments, identifies required inputs, resolves evidence gaps with internal owners, and prepares complete response packages within agreed timelines.
  3. Customer assurance call participation: Clarifies documented security controls, certifications, and compliance practices during customer calls and records unresolved questions for follow-up by authorized subject-matter owners.
  4. Risk register and GRC platform maintenance: Maintains risk records, control evidence, remediation status, and audit documentation in GRC platforms and in approved repositories, ensuring accuracy, traceability, and readiness for review.
  5. Workflow AI automation: Uses AI tooling to automate and accelerate approved compliance activities, including initial questionnaire drafting, evidence summarization, and content organization, while validating outputs before internal or customer-facing use.

What We Offer

  • The opportunity to work on a global, mission-critical AI platform alongside the best engineers and technologists across multiple geographies
  • A role with real ownership and impact, building complex systems at scale in an environment that values speed, experimentation, and technical excellence
  • A highly attractive benefits package, including competitive cash compensation, an equity award aligned with long-term value creation, and comprehensive health insurance for employees and their families
  • A generous time-off policy of 30 days annually, plus public holidays and sick leave, recognizing the importance of sustained high performance

About Our Process

We take Talent very seriously and we are building a community of extraordinary individuals working together in very high performing teams. We also know that the best Talent always has options so we believe that the process has to be a two way assessment - the company AND the candidate assessing the business needs alignment, the career next step alignment, and the cultural alignment.

During the process we will begin by exploring the core factors regarding salary and location along with core experience and skills and values alignment. We will then deep dive explore the critical technical competencies we have identified for the role, and then we will deep dive in behavioral competencies.

The most aligned candidate will then be asked to do a practical work task simulation activity so we can make sure that you will enjoy the kind of work the role requires, and this task will typically be presented and discussed with a group of colleagues and managers. Finally we will ask you to meet with a number of our senior leaders to make sure that you are making the most informed call possible.

Please note that:

  • We want to get to know you and have a genuine conversation, so the use of AI tools or assistance during live interviews is strictly prohibited and will result in immediate disqualification from the process. 
  • Interviews may be recorded for internal review purposes to ensure fairness and enable collaborative hiring discussions within the team.