GRC Lead
Full-time
Canada
About Us
Nesto Cloud is Canada's cloud-native and AI driven, end-to-end mortgage technology platform, helping financial institutions modernize lending through AI intelligent automation, AI & Cloud proprietary technology, and business process outsourcing (BPO) solutions.
Powered by the Nesto Group ecosystem, we transform decades of mortgage expertise into cutting-edge technology that reduces mortgage operation costs, accelerates lending, strengthens compliance, and delivers exceptional experiences for lenders and borrowers alike.
Nesto Group
Nesto Group is Canada's leading provider of mortgage technology and financing solutions, with more than CAD $80 billion in residential and commercial mortgages under administration. Trusted by many of the country's leading financial institutions, we combine over 50 years of mortgage expertise with proprietary cloud and AI technology to transform the future of lending.
Powered by our proprietary cloud and AI technology, nesto has become one of Canada's fastest-growing mortgage lenders, gaining market share across direct-to-consumer (D2C) residential lending, the broker channel, and multi-family commercial lending. Recognized as one of Deloitte's Fast 50 companies for three consecutive years, we continue to push the industry forward through innovation, technology, and customer-focused solutions.
Operating through our family of brands—CMLS, nesto, and Nesto Cloud—our mission is to build Canada's mortgage ecosystem of the future and create a true Canadian champion in lending technology and financial services. Learn more at: https://nestogroup.ca/
Life at Nesto Cloud
At Nesto Cloud, you'll build the future of lending alongside some of the country's top developers, AI engineers, and mortgage experts. You'll work with a modern tech stack and AI-driven development frameworks designed to help you innovate, grow your skills, and accelerate your career
About the role
The GRC Lead owns nesto's governance, risk, and compliance program end-to-end. We've built strong foundations and automated much of our compliance workflow; your role is to elevate it to world-class execution. You'll optimize our automated systems, refine audit readiness processes, enhance policy governance rigor, strengthen risk management discipline, and scale vendor assessment workflows. You're taking a program that works and making it exceptional, resilient, and repeatable.
What you'd be accomplishing in that role :
- Own Security policy governance and control mapping across nesto's compliance frameworks (SOC 1/2, ISO 27001, and applicable regulatory frameworks).
- Mature our automated compliance program to scale sustainably with nesto's growth. Optimize our GRC platform, automation tools for self-service workflows, and progressively eliminate manual audit prep.
- Elevate nesto's external audit program while continuously expanding scope as the business scales.
- Evolve nesto's AI governance framework in collaboration with Engineering, and Compliance teams from foundational policies to enterprise-grade controls that enable rapid, safe AI feature deployment and internal usage.
- Transform risk management into a strategic business advisor. Collaborate with business unit leaders to evolve our risk narratives, connect technical findings to business impact, and enable leadership to make informed trade-offs with confidence.
- Scale vendor and client security assessments. Evolve intake workflows, mature questionnaire automation, and strengthen how we communicate security posture to enterprise prospects and customers.
- Lead and develop a GRC team that raises the bar on technical excellence, deepens capability in governance and risk disciplines, and drives accountability across initiatives.
- Strengthen organizational resilience through evolved, regularly tested Business Continuity and Disaster Recovery frameworks that keep nesto operationally confident during crisis.
What We’re Looking For
- 10+ years of GRC, audit, risk management, or compliance experience in regulated industries (financial services, SaaS, healthcare)
- Deep experience across SOC1, SOC2, NIST frameworks and audits.
- Strong knowledge of risk assessment methodologies and compliance operations.
- Hands-on experience with GRC automation platforms.
- Excellent project management, stakeholder engagement, and cross-functional collaboration skills
- Strong writing skills; ability to communicate policy and control concepts clearly to technical and non-technical audiences
- Ability to influence leadership through evidence-based risk narratives and business-aligned insights
- **English is required for writing and documentation. French speaking and reading is a strong plus.*
The Reward
- The A-Team: Work alongside high-performing talent in the industry.
- Accelerated Growth: The slope of your learning curve here will be vertical. You will touch more production systems in one year than you would in five years at a bank.
- Top-Tier Coverage: Premium benefits plan fully paid by nesto, including comprehensive insurance and unlimited access to telemedicine and mental health services for you and your family.
- Rest & Recharge: 4 weeks of vacation to ensure you stay at peak performance.
- Best-in-Class Tools: Access to the resources and tech you need to execute without friction.
- Working framework: The environment that makes you productive and enables teamwork (Hybrid model).
- Diversity and Inclusion
At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.
#nestocloud
#nestoposition