Senior GRC Analyst at Benevity managing privacy compliance across multiple frameworks and jurisdictions. Responsible for ROPAs, DSAR workflows and collaboration with various teams.
Responsibilities
Own and maintain Benevity’s Records of Processing Activities (ROPA) under both controller and processor regimes.
Develop and maintain privacy policies, notices, standards, and control frameworks aligned with GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, CASL, and emerging global laws.
Build and manage DSAR intake, triage, and response workflows in compliance with statutory deadlines.
Design, operationalize, and continuously improve the Data Protection Impact Assessment (DPIA) process.
Review and support the negotiation of Data Processing Agreements and data transfer mechanisms in collaboration with Legal.
Maintain and enhance privacy workflows in GRC platforms to automate compliance operations at scale.
Design and deliver privacy awareness and training programs to build a culture of data protection.
Requirements
5+ years of experience in privacy, data protection, GRC, or a closely related field, ideally within a SaaS or high-growth technology environment.
Deep, practical knowledge of global privacy frameworks, including GDPR, UK-GDPR, CPRA/CCPA, PIPEDA, and CASL, with working familiarity of emerging regimes (India DPDP, Swiss FADP, AU Privacy Act reforms).
Hands-on experience building and maintaining ROPAs under both controller and processor regimes, managing DSAR workflows, conducting DPIAs, and maintaining subprocessor inventories.
Experience supporting or operating within a DPO function, including regulatory interface and breach notification processes.
Proven ability to review and support the negotiation of Data Processing Agreements and data transfer mechanisms in collaboration with Legal.
Hands-on experience with privacy or GRC tooling (e.g., OneTrust Privacy module, Hyperproof, or equivalent) to operationalize compliance workflows at scale.
Ability to communicate complex privacy and regulatory concepts clearly to technical, legal, and business audiences.
A demonstrated interest and track record in leveraging AI and automation as a force multiplier, streamlining privacy operations, accelerating routine workflows, and expanding program capacity without proportional headcount growth.
Certifications such as CIPP/E, CIPP/US, or CIPM are highly valued; CIPT, CISM, or CRISC are also welcomed.
Contracts and Compliance Manager overseeing client and supplier agreements for Spiria, a Canadian custom software firm. Leading SOC 2, privacy, and government - contract compliance programs.
Sun Life Canada compliance executive overseeing regulatory risk across insurance and wealth businesses. Advising executives and boards while leading compliance programs and teams.
Senior Compliance Advisor guiding insurance and savings regulation at iA Financial Group, a Canadian insurance, savings, and wealth management company. Advising Sales teams and partners on regulatory risks, frameworks, and training.
Senior Regulatory Specialist leading mining permitting and environmental compliance projects for Ensero, an environmental consulting and remediation business. Providing regulatory direction, stakeholder engagement, and technical mentorship.
Senior GRC Analyst evaluating cybersecurity controls, privacy, and enterprise risk for Arctic Wolf’s security operations platform. Leading assurance reviews and compliance improvements across global cross - functional teams.
Compliance coordinator managing regulatory filings, audits, and consultations for AltaLink, an Alberta electricity transmission company. Maintaining compliance systems, deadlines, evidence, reporting, and regulatory risk processes.
Compliance Testing Manager evaluating controls, regulations, and risks for Sun Life Financial Canada. Developing test plans, reports, recommendations, and AI - enabled compliance improvements.
Director leading first - line risk and compliance for EQ Bank’s B2B payments, BIN sponsorship, and fintech partnerships. Building governance, controls, and teams for safe Canadian banking innovation.
Director of Compliance building consumer regulatory, privacy, and security programs for Yomali, a global e - commerce conglomerate. Leading compliance operations and advising portfolio businesses across multiple jurisdictions.