
Ivalua · Montreal - Canada
Senior Security Analyst - GRC (Montreal - Canada) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIE...
Senior Security Analyst - GRC
(Montreal - Canada)
Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.
At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply
chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based
spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend
and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower
risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to
create meaningful experiences for our colleagues, customers, partners, and communities.
Learn more at www.ivalua.com [http://www.ivalua.com]. Follow us on LinkedIn [https://www.linkedin.com/company/ivalua]
You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program,
providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong
problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers'
long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company,
allowing you to focus, collaborate, and unleash your creativity.
We are looking for a Senior Security Analyst to join our InfoSec team. This role will help drive various GRC activities which
include supporting prospect and customer security questions, maintaining security policies, supporting security audits and
assessments and driving new security certifications/compliance initiatives.
SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800-53
firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud
security configurations), and translate security requirements into actionable guidance for engineering and infrastructure
teams.
region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance
obligations.
treatment planning, and ongoing monitoring.
effectiveness, generate evidence, and ensure audit readiness.
Recovery testing, security incident response exercises, access reviews, etc.
If you have the below experience and strengths this role could be for you:
analysis)
with technical teams
(network, infrastructure, web applications, cloud environments)
both French and English, including in contractual, regulatory, and technical contexts
If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening
call. Get one step closer to achieving your goals – apply today!
Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to
support you!
Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal
stakeholders relevant to the role.
Interviews will be conducted virtually via video or on-site with face-to-face meetings.
Best Company for Diversity 2025 (Large Companies)
Company for Women 2025 (Large Companies)
Company Culture 2024 (Large Companies)
Leadership Teams 2024 (Large Companies)
Engineering Teams 2024
Powered by People - Powered by You!
United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our
customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds,
skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of
inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans.
https://www.linkedin.com/company/ivalua/about/ [https://www.linkedin.com/company/ivalua/about/]
Experience life at Ivalua - check out our captivating video [https://www.youtube.com/watch?v=irkygoq3kCc&t=4s]! Gain insight into
our unique company culture and get a glimpse of what it's like to work with us.
Senior Security Analyst - GRC (Massy - France) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. Learn more at www.ivalua.com. Follow us on LinkedIn THE OPPORTUNITY CONTEXT: You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity. ROLE: We are looking for a Senior Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives. WHAT YOU WILL DO WITH US * Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800-53 * Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams. * Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations. * Attend prospect and customer meetings and effectively present Ivalua’s security architecture and control information to them. * Lead or support internal and third party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring. * Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness. * Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, access reviews, etc. YOUR PROFILE If you have the below experience and strengths this role could be for you: Skills and Experience: * At least 4 years of experience as Security Analyst GRC * Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR) * Direct experience managing audits, self-assessments, or risk assessments against one or more InfoSec frameworks listed above * Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis) * Familiarity with continuous compliance and monitoring platforms * Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams * Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments) * Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800-39) * Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired * Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus Soft Skills: * Excellent interpersonal, communication, and organizational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts * Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators. * Strong organizational skills and attention to detail; able to manage multiple competing priorities in a fast-paced environment * High degree of initiative, self-motivation, and ability to work independently with limited supervision WHAT HAPPENS NEXT If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today! Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you! Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role. Interviews will be conducted virtually via video or on-site with face-to-face meetings. LIFE AT IVALUA * Hybrid working model (3 days in the office per week) * We're a team dedicated to pushing the boundaries of product innovation and technology * Sustainable Growth, Privately Held * A stable and cash-flow positive Company since 10 years * Snacks and weekly lunches in the office * Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity * Unlock and unleash your full professional potential with our exceptional training and career development program * Join a dynamic and international team of top-notch professionals who are experts in their respective fields * Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work * Experience a truly diverse and inclusive work environment where your unique contributions are highly valued * Regular social events, competitive outings, team running events, and musical activities * Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua): Powered by People - Powered by You! United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/ Experience life at Ivalua - check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it's like to work with us. #LI-MV1 #LI-HYBRID
We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. About the Team: * The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. * Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. * We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. * The Security Contracts workstream is a core part of our Security Assurance and Trust Enablement program — ensuring Plaid's contractual security obligations with customers and data partners are defensible, consistent, and never a bottleneck to deal velocity, all while building trust. About the Role * You will own Plaid’s Security Contracts workstream end-to-end—the DRI for how security contract reviews get done, how fast they move, and how the program improves over time. * You will review security provisions in customer MSAs, DPAs, and security addenda, identify unacceptable clauses, and provide Legal and GTM with the actionable security feedback they need to move deals forward. * You will build the playbooks, processes, and program infrastructure that make the Security Contracts workstream scalable — so the team moves faster on every deal that follows. * You will use pattern analysis and data to proactively reduce deal friction over time, own program metrics and reporting, and operate as an AI power user to maximize throughput. * You will also support broader security trust enablement activities — responding to customer security questionnaires and joining external audit calls with customers and data partners — with the same rigor and responsiveness you bring to the contracts workstream. Responsibilities * Lead Security Contract Reviews: Review security provisions in customer MSAs, DPAs, security addenda, and security exhibits — identifying unacceptable clauses, forming a clear security position, and providing Legal with actionable feedback they can take directly into negotiations. Your positions will give Legal and GTM a consistent, defensible security voice at the table and directly reduce deal cycle times. * Shape the Security Contract Review Strategy: Design and own the end-to-end program infrastructure — intake process, tiered SLAs, security positions runbooks, and handoff protocols with Legal and GTM. Your work will transform security reviews from an ad-hoc bottleneck into a predictable, scalable function that the business can rely on. * Drive Strategic Intelligence: Track security contract asks across deals, identify recurring patterns, and determine whether they reflect a gap in Plaid's program or a non-standard customer request. For identified gaps, assess feasibility and propose recommendations to leadership. For existing capabilities, codify them in the standard security addendum to eliminate future negotiation cycles. * Accelerate Deals: Join customer and data partner calls as Plaid's security subject matter expert — comfortable navigating the formality and pace of traditional financial institutions, building trust through patience and clear, collaborative communication. Your involvement will shorten security contract review cycles from weeks to days and directly unblock revenue. * Own Program Health: Define the KPIs, build the dashboards, and deliver regular reporting on program health to Security and GTM leadership. Your reporting will give leadership clear visibility into deal friction, SLA adherence, and where the program needs to improve. * Scale Through AI and Tooling: Build and scale AI-assisted workflows for security assurance, pattern analysis, and reporting — and share what works across the team. Your approach will set the standard for how the Security GRC team leverages AI to increase productivity. * Support Security Trust Activities: Respond to customer security questionnaires and support external audit calls with customers and data partners — serving as Plaid's security subject matter expert across all customer-facing assurance activities. Your involvement ensures Plaid presents a consistent, credible security posture across every customer touchpoint, not just at the contract stage. Qualifications * Security contract review and negotiation: * Experience reviewing security provisions in MSAs, DPAs, and security addenda — and translating that expertise into clear positions Legal can take directly into negotiations. * Deep familiarity with common security clause types: e.g. incident notification windows, audit rights, encryption requirements, subprocessor obligations, data retention, and penetration testing provisions. * Ability to translate a company's security posture and risk appetite into clear, defensible contract positions and hold those positions through multiple negotiation cycles. * Experience representing a company's security program directly to customers and financial institution partners on calls — fielding questions about security controls, compliance posture, and contractual obligations. * Security Compliance and regulatory knowledge: * Working knowledge of SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR/CCPA, NIST 800-53, etc. * Deep understanding of what "standard" security contract language looks like in fintech and banking agreements * Prior experience in fintech, payments, or financial services — you understand the security expectations of data partners and regulated entities, and know how to navigate those relationships with the patience and credibility they require. * Program design and operational maturity: * Experience building security trust enablement programs — designing intake processes, tiered SLAs, escalation paths, and runbooks, not just executing within existing ones. * Strong analytical skills: ability to identify patterns across a high volume of security contract asks, track pushback rates and cycle counts, and translate findings into process improvements. * Experience with metrics ownership: defining KPIs, building tracking infrastructure, and reporting on program health to cross-functional stakeholders. * Communication and cross-functional effectiveness: * Exceptional written and verbal communication skills — precise enough for Legal to use your positions to draft language, clear enough for a Sales rep to use in a customer call. * Experience working directly with Legal and GTM teams as a security subject matter expert. * Experience driving customer and data partner calls involving security. * AI fluency and tooling: * Demonstrated ability to build and scale AI-assisted workflows — applies AI tooling to Security Assurance activities like contract review, questionnaire completion, clause library maintenance, pattern analysis, and reporting to materially increase throughput. * Shares what works with the broader team; approaches AI as a force multiplier for the function, not just a personal productivity tool. Nice to have: * Experience redlining security contract language directly, beyond providing advisory feedback. Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid! Plaid is proud to be an equal opportunity employer and values diversity at our company. We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws. Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com. Please review our Candidate Privacy Notice here. Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.
Discord has a highly engaged community of millions of daily active users who use the platform for many different reasons, but there’s one thing that nearly everyone does: play video games. Discord plays a uniquely important role in the future of gaming, and we are focused on making it easier and more fun for people to hang out before, during, and after playing games. Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it. You'll own the day-to-day engine of the program: the questionnaires, risk tracking, analyses, tooling, and documentation that keep compliance moving. As we build, that's a mix of hands-on work today and the systems that shrink it over time, because we'd rather automate a control than babysit it. We care about the right level of compliance for Discord, our users, and our customers. You'll partner across Security, Engineering, IT, and Legal to make compliance feel friction-free, even invisible, rather than something teams have to fight. WHAT YOU'LL BE DOING * Run the customer security questionnaire program end-to-end, from intake through response, and grow a reusable answer library that turns repeat questions into fast, near-self-service answers. * Operate risk and control workflows: triage incoming risks, track gap closure and risk treatment through to completion, and keep the risk register accurate and current. You'll be the first point of contact for partner teams, resolving routine questions and escalating the ones that need senior judgment. * Run GRC analyses that turn into decisions: how standards, procedures, and controls align to our policies and framework requirements; where the gaps are; and how mature and effective our controls actually are. * Build and maintain the GRC toolchain and its automation: administer our GRC platform, ticketing, and knowledge bases, and design the integrations and workflows that collect evidence and check controls by default rather than by hand. * Create the documentation that makes the program usable: internal guidance and updates to our policies, standards, and procedures; company-wide GRC communications; and security training delivered in plain language that people outside the field can follow. WHAT YOU SHOULD HAVE * 4+ years in security compliance, GRC, or a closely related field (security operations, IT risk, audit). * Working familiarity with common frameworks (ISO 27001/27002, SOC 2, PCI DSS, GDPR/CPRA) and a sense of how their requirements turn into day-to-day controls. * Hands-on experience operating compliance processes: evidence collection, control tracking, risk register upkeep, or security questionnaire response. * An automation-first instinct. You reach for tooling, integrations, and repeatable workflows to replace manual, repetitive compliance work, not box-checking. * Comfort living across tools (GRC platforms, ticketing, docs and wikis) and a habit of keeping data clean and organized. * Clear writing, with a knack for turning dense requirements into guidance people actually use. * Ability to work across teams and influence without authority in a fast-moving environment with competing priorities. BONUS POINTS * Hands-on experience with a GRC platform. * Exposure to ISO 27701, ISO 42001, or emerging AI compliance work. * Background in consumer technology, gaming, or online community platforms. Candidates must reside in or be willing to relocate to the San Francisco Bay Area (Alameda, Contra Costa, Marin, Napa, San Francisco, San Mateo, Santa Clara, Solano, and Sonoma counties). Relocation assistance may be available. For this role, the Hiring Manager would like folks to be in the office 2 days a week. The US base salary range for this full-time position is $144,000 to $162,000 + equity + benefits. Our salary ranges are determined by role and level. Within the range, individual pay is determined by additional factors, including job-related skills, experience, and relevant education or training. Please note that the compensation details listed in US role postings reflect the base salary only, and do not include equity, or benefits. Why Discord? Discord plays a uniquely important role in the future of gaming. We're a multiplatform, multigenerational and multiplayer platform that helps people deepen their friendships around games and shared interests, and helps developers build and grow their businesses. We believe games give us a way to have fun with our favorite people, whether listening to music together or grinding in competitive matches for diamond rank. Join us in our mission! Your future is just a click away! Discord is committed to inclusion and providing reasonable accommodations during the interview process. We want you to feel set up for success, so if you are in need of reasonable accommodations, please let your recruiter know. Please see our Applicant and Candidate Privacy Policy for details regarding Discord’s collection and usage of personal information relating to the application and recruitment process by clicking HERE. [https://discord.com/terms/applicant-candidate-privacy-policy]