Senior GRC Analyst
7 days ago
About KOHO We’re on a mission to make financial services better for every Canadian. That means no hidden fees, no predatory interest rates - just financial products designed to help our users spend smart, save more, and build real wealth. We’re a performance organization with a strong heart: we care deeply about outcomes, and everything ties back to our mission - to financially empower a generation of Canadians. At KOHO, we’re not your average 9-5. We believe real impact comes from people who are trusted, empowered, and supported to do their best work - without sacrificing their lives to do it. We prioritize work-life integration, not just work-life balance. That means asynchronous collaboration, flexible hours, and a remote-first setup built around autonomy and high trust. KOHO is entering its next chapter - leaner, smarter, more AI-integrated. We’re building for impact, not bureaucracy. If you thrive in environments that value clarity, ownership, and bold thinking, you’ll fit right in. About The Role We’re looking for a Senior Governance, Risk and Compliance (GRC) Analyst - Platform Technology and Payments to join our team for a role to work remotely based in Canada. Reporting to our Senior Manager, Product Security, you’re going to be a part of a team that is low-ego, high-agency which values innovation, continuous learning, and high-quality work. What You’ll Be Doing Building up and establishing a compliance program for the KOHO technology team. Compliance standards that you need to be familiar with include RPAA, OSFI B-10, and OSFI B-13. The successful candidate will be responsible for obtaining and preparing evidence packages for submission to auditors while also building a sustainable, systematic, and automated compliance program. Working with the technology team to build KRI’s that align with the relevant compliance obligations. Translate complex technical and regulatory information into clear, concise, and user-friendly documentation, including policies, SOPs, control descriptions, and network diagrams. Prepare and coordinate the review and approval of evidence packages and submission-ready documents for external audits and regulatory examinations. Work collaboratively with engineering, product, and operations teams to embed compliance requirements into the software development lifecycle (SDLC) and ensure payments and technology changes are documented accurately. Advising leadership on risk management strategies, including risk mitigation, risk reduction, compensating controls, and residual risk analysis. Supporting tech compliance requirements as it relates to payments and technology infrastructure. The main regulations, guidelines, and standards include OSFI B-13 and B-10, RPAA, and PCI. Who You Are You are someone that has experience in either technology or payments infrastructure. Both are preferred, but candidates are encouraged to apply if you have only one and interested in learning about the other. For technology, you are well versed in disaster recovery, networking, data, CICD pipelines, change management, ITSM principles (incident, problem, and change management), configuration management, KPI and KRIs. For payments, you have a deep understanding of card and bank transaction lifecycles, financial reconciliation and authorization/settlement processes in modern API-based systems. You are a self starter, determined, and have agency to be willing to learn new domains and systems that you are not familiar with. Bachelor’s degree in computer science, technology management, commerce or related technical or management field. You have excellent communication skills – this is required in order to ensure that you can communicate what the risk posture of the organization is relative to your analysis of vulnerabilities and risk. You are familiar with OSFI B-10, B-13, and RPAA. Familiarity with AWS Inspector, CloudTrail, Config, SCPs, and other AWS native technologies (EKS, RDS, DB, network firewall), Terraform, and Argo CD. Experience leading audits and working with regulators. Experience in building your own automations and scripts in order to pull data to automate evidence retrieval. You have the ability to work cross functionally. This is a role where soft skills are important in order to ensure partnerships within and outside KOHO, to communicate the risk back to the organization in a clear and concise manner. Preferred: Familiar with OSFI guidelines (B-10 and B-13) and RPAA (Retail Payment Activities Act). What’s in it for you? 📈 Opportunity to shape the future of fintech and financially empower a generation of Canadians 💰 Competitive compensation & equity 🤝 Fantastic, Deeply Engaged Team (check out our engagement scores here) 🌴 Generous vacation + Wellness days + Flex Days + holiday closure 💻 Remote-first environment + coworking support + yearly all hands retreat 🧠 Access to coaching & growth programs 👶 Parental top-up & leave policies 🏥 Comprehensive health benefits 💡 Power-up budgets for books, home office setup, phone & internet, AI tools, and professional development KOHO is for builders. If you’re energized by challenge, motivated by mission, and want to be part of a team that punches above its weight - we want to hear from you. The KOHO culture is one of collaboration, creativity, and diverse perspectives. We are committed to building and fostering an inclusive, accessible environment for everyone. If you have any questions, concerns, or requests regarding accessibility needs, please contact peopleaccessibility@koho.ca and the People and Culture team will be happy to help. AI Disclosure: KOHO uses artificial intelligence (AI) in certain aspects of its recruitment process to screen, assess, or select applicants. For any questions or concerns, please contact us at talent@koho.ca. Note: this posting is for an existing vacancy that we are seeking to fill. #LI-Remote #J-18808-Ljbffr
-
SNOW GRC Business Analyst
9 hours ago
Greater London, United Kingdom Natobotics Full timeSNOW GRC Business Analyst – Contract – Hybrid – London We are seeking an experienced ServiceNow GRC Business Analyst for a 6‑month contract in London. This hybrid role requires 2–3 days per week in the office. What You’ll Do Gather, analyze, and document requirements for the ServiceNow GRC suite. Configure and implement GRC IRM modules on the...
-
SNOW GRC Business Analyst
24 hours ago
Greater London, United Kingdom N Consulting Limited Full timeSNOW GRC Business Analyst at N Consulting Ltd SNOW GRC Business Analyst | Contract | Hybrid | London We are seeking an experienced ServiceNow GRC Business Analyst for a 6-month contract in London. This hybrid role requires 2–3 days per week in the office. What You’ll Do: Gather, analyze, and document requirements for the ServiceNow GRC suite. Configure...
-
SNOW GRC Business Analyst
23 hours ago
Greater London, United Kingdom N Consulting Limited Full timeLocationEngland, United Kingdom# SNOW GRC Business Analyst at N Consulting LtdLocationEngland, United KingdomSalary£300 - £320 /dayJob TypeContractDate PostedDecember 4th, 2025Apply Now**SNOW GRC Business Analyst | Contract | Hybrid | London**We are seeking an experienced **ServiceNow GRC Business Analyst** for a **6-month contract** in London. This hybrid...
-
GRC Information Security Analyst
2 weeks ago
Greater London, United Kingdom hireful Full timeJoin the team as a GRC Information Security Analyst at hireful, a global technology company based in the UK. As a GRC Analyst, you will collaborate with internal stakeholders and external auditors to maintain and enhance our security program, ensuring compliance with ISO 27001, PCI DSS, SOC 2, NIST, CIS benchmarks, GDPR and other regulatory...
-
SNOW GRC Business Analyst
5 days ago
London Area, United Kingdom PRIMUS Global Solutions (PRIMUS UK & Europe) Full time £60,000 - £80,000 per yearJob Title: SNOW GRC Business AnalystLocation:LondonWork Mode:Hybrid (2–3 days per week from office)Contract Duration:6 MonthsMinimum Experience:10+ YearsAbout the RoleWe are seeking an experiencedSNOW GRC BA (ServiceNow GRC Business Analyst)with strong expertise in ServiceNow GRC/IRM modules, GRC frameworks, and end-to-end requirements gathering. The ideal...
-
SNOW GRC Business Analyst
3 days ago
Greater Lincoln Area, United Kingdom Natobotics Full time £50,000 - £120,000 per yearSNOW GRC Business Analyst | Contract | Hybrid | LondonWe are seeking an experiencedServiceNow GRC Business Analystfor a6-month contractin London. This hybrid role requires2–3 days per week in the office.What You'll DoGather, analyze, and document requirements for theServiceNow GRC suite.Configure and implementGRC IRM moduleson the ServiceNow...
-
Information Security Grc Analyst
3 days ago
City of London, United Kingdom i3 Resourcing Limited Full time**Information Security GRC Analyst** **£47,000 - £55,000** **2-3 days in a London office / 1-2 days from home** **EXCELLENT full benefits package and bonus** **Information Security GRC Analyst, Governance, Risk, Compliance, Security Risk, Privacy Risk, Management Information, ISO27001, NIST, SOX, Firewalls, IDS/IPS, DLP, Information Security Analyst,...
-
Greater London, United Kingdom N Consulting Limited Full timeA consulting firm is seeking an experienced ServiceNow GRC Business Analyst for a 6-month contract in London. This hybrid role requires 2–3 days per week in the office. Responsibilities include gathering and analyzing requirements, configuring GRC IRM modules, and collaborating with stakeholders to ensure compliance solutions. Candidates must have over 10...
-
ServiceNow GRC Analyst – Hybrid Contract
19 hours ago
Greater London, United Kingdom Natobotics Full timeA leading IT consultancy is seeking an experienced SNOW GRC Business Analyst for a 6-month contract in London. This hybrid role requires 2-3 days per week in the office. The candidate must have 10+ years of relevant experience and strong proficiency with ServiceNow, especially in GRC IRM modules. Responsibilities include gathering and documenting...
-
GRC Information Security Analyst
2 weeks ago
London, United Kingdom hireful. Full timeAre you looking to join a global software technology company, with their main base of operations here, in the UK, as an experienced GRC Information Security Analyst? Do you have experience in the GRC Security space with audits, auditors, ISO27001, PCI DSS, SOC2, NIST & current compliance regulations? If so & you are looking to expand your information...