This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
OnePlan is looking for a Senior Governance, Risk & Compliance Lead to own and operate our security, privacy, and compliance programs. This role is responsible for maintaining OnePlan’s existing certifications including SOC 2 Type II, ISO 27001, and ISO 27701, while leading our FedRAMP Moderate readiness initiative as we expand into public sector markets. This is a senior individual contributor role focused on building and operationalizing a scalable governance, risk, and compliance program within a Microsoft based SaaS ecosystem.
Job Responsibility:
Own and manage OnePlan’s governance, risk, and compliance program across security and privacy frameworks
Maintain the company’s compliance certifications including SOC 2 Type II, ISO 27001, and ISO 27701, ensuring ongoing audit readiness and successful surveillance audits and recertifications
Coordinate with external auditors and manage evidence collection, control validation, and supporting documentation
Maintain and update security policies, procedures, and internal documentation supporting compliance frameworks
Maintain the company risk register and drive risk identification, assessment, and remediation activities across the organization
Partner closely with Engineering and IT teams to implement and document security controls across the platform
Lead OnePlan’s FedRAMP Moderate readiness initiative, including NIST 800-53 gap assessments and remediation planning
Develop and maintain the System Security Plan (SSP) and associated FedRAMP documentation
Prepare the organization for 3PAO assessment and establish processes for ongoing continuous monitoring
Manage vendor risk assessments and third party security reviews
Support enterprise and public sector security questionnaires, compliance reviews, and due diligence requests
Ensure privacy and data protection practices align with GDPR and global privacy frameworks
Support the ongoing operation of OnePlan’s ISO 27701 privacy program
Requirements:
6+ years of experience in governance, risk and compliance, information security, or security compliance roles
Direct experience managing SOC 2 Type II and ISO 27001 audits and maintaining ongoing compliance programs
Strong understanding of NIST 800-53 and FedRAMP security requirements
Experience using compliance automation platforms such as Vanta or similar tools
Experience working in a cloud native SaaS environment, ideally within Azure
Strong documentation, audit management, and cross functional coordination skills
Ability to translate security and compliance requirements into practical operational processes
Experience leading or supporting FedRAMP readiness or authorization programs
Nice to have:
Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or CIPP
Experience supporting enterprise security reviews and government compliance requirements
Experience working in high growth SaaS or enterprise software companies
What we offer:
We offer comprehensive health, dental, and vision benefits, with additional insurance options
Employer RRSP and 401K matching programs
A fun, collaborative, and diverse environment with regular health and team challenges to keep things light and enjoyable