Carta Logo

Carta

Senior GRC Analyst

Job Posted 15 Days Ago Reposted 15 Days Ago
Be an Early Applicant
Hybrid
Waterloo, ON
Mid level
Hybrid
Waterloo, ON
Mid level
As a GRC Analyst at Carta, you will assess regulatory requirements and establish governance and risk frameworks, build security compliance programs, manage policies and standards, and collaborate with cross-functional teams to ensure adherence to compliance standards and improve risk management practices.
The summary above was generated by AI
The Company You’ll Join

Carta develops purpose-built software that transforms traditional accounting into a powerful growth engine.

Carta’s world-class fund administration platform supports nearly 7,000 funds and SPVs, and represents nearly $130B in assets under management in venture capital and private equity.

Trusted by more than 40,000 companies, Carta also helps private businesses in over 160 countries manage their cap tables, valuations, taxes, equity programs, compensation, and more.

Together, Carta is setting a new standard as the end-to-end platform for private markets. Our best-in-class solution for fund management seamlessly integrates investor and portfolio company insights via a suite of tools designed ground-up to support the strategic impact of the fund CFO.

For more information about our offices and culture, check out our Carta careers page.

The Problems You'll Solve

At Carta, our employees set out on a mission to unlock the power of equity ownership for more people in more places. We believe that the problems we solve today unlock the opportunities of tomorrow.

As a Senior GRC Analyst,  you’ll work to assess regulatory requirements and accordingly establish and maintain  governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance metrics, and build and manage policies and standards.

Here are some problems we’d love for you to help us solve: 

  • Manage and continually improve the Carta Governance, Risk, and Compliance  program, ensuring it is aligned with our security strategy and business objectives.
  • Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements.
  • Lead and coordinate internal and external security audits.
  • Perform security assessments of vendors, third parties, and applications.
  • Partner with cross functional teams to review initiatives that could impact compliance requirements
  • Manage risk program activities including risk identification, tracking, and prioritization.
  • Collaborate with engineering and product teams to assess risk posture and compliance status, and support remediation activities.

The Team You'll Work With

You will be part of a security-minded team that believes in progress over perfection and where security culture and mindset is key. Our team is rethinking how GRC activities can be accomplished in innovative ways. We do not focus on building processes, but instead how to solve business problems while minimizing and managing risk exposure for Carta.

About You

We are looking for candidates who have:

  • A strong understanding and working knowledge of information security and compliance frameworks, such as SOC 1  and 2, ISO 27001, NIST CSF, GDPR, CCPA, FINRA, SOX and SEC cybersecurity requirements.
  • Excellent judgment and the ability to make balanced  decisions when working with complex situations.
  • Proven understanding of public cloud infrastructure and services in AWS and GCP including knowledge of cloud-native security protection measures, tools, and techniques
  • Proven  ability to collaborate with cross-functional teams and affect change to accomplish goals.
  • Excellent written and verbal communication skills, including the ability to effectively communicate business and cybersecurity risk.
  • 5+ years of experience in developing  and executing governance, risk and compliance functions.

Disclosures:

  • We are an equal opportunity employer and are committed to providing a positive interview experience for every candidate. If accommodations due to a disability or medical condition are needed, please connect with the talent partner via email. 

  • Carta uses E-Verify in the United States for employment authorization. See the E-Verify and Department of Justice websites for more details.
  • Interested in data privacy? Check out our policies on Privacy and CA Candidate Privacy.

  • Please note that all official communications from us will come from an @carta.com or @carta-external.com domain. Report any contact from unapproved domains to security@carta.com.

Similar Jobs

Yesterday
Hybrid
Toronto, ON, CAN
Senior level
Senior level
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
The Manager of Shopper Insights will analyze consumer data, develop strategies, and deliver actionable insights to drive growth and influence marketing plans.
Top Skills: ExcelIriNielsenNumeratorPowerPointTableau
2 Days Ago
Hybrid
Toronto, ON, CAN
Junior
Junior
Fintech • Machine Learning • Payments • Software • Financial Services
As a Senior Data Analyst, you'll handle data reporting, analysis, and visualization, collaborating with business partners to ensure data-driven strategies.
Top Skills: AWSGitMatplotlibPythonQuicksightSQLTableauUnix
2 Days Ago
Remote
Hybrid
10 Locations
Senior level
Senior level
Fintech • HR Tech
The Principal Applied AI Scientist will design, build, and evaluate AI products, collaborating closely with product engineers and managing the AI development lifecycle.
Top Skills: Agentic Ai FrameworksLlmsMulti-Agent FrameworksPython

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account