About Miovision:
At Miovision, we’re unlocking transportation networks that move you. Our vision and mission is to enable smart, fast, safe communities that simply flow, as we drive the Intelligent Mobility Revolution. Backed by the world’s most advanced traffic AI, Miovision’s innovations in traffic signal planning and operations are making it possible for cities to improve the transportation experience for drivers, cyclists and pedestrians.
Our values drive us. They’re at the core of everything we do. If they align with yours, proceed through the GREEN light!
All in to win: We're driven by a winning mindset, approaching every challenge with intensity, clarity, and speed.
One Miovision: We succeed as one team, uniting diverse talents, building on trust, and putting our shared mission before ego.
Be better every day: We're committed to continuous growth, staying curious, building mastery, and embracing challenges as learning opportunities.
Make it happen: We are proactive and results-driven, taking ownership, acting with urgency, and focusing on solutions that deliver real impact.
Earn the customer: We are deeply customer-centric, focused on earning our customers' partnership every day by delivering exceptional experiences that drive their success.
Position Summary:
At Miovision, we are engineering the future of smart transportation, but keeping our massive data highways safe requires serious guardrails. We are looking for a GRC Specialist to act as our ultimate risk traffic controller. Sitting within the Office of Cybersecurity, you will operationalize our Unified Risk Management Framework, ensuring our products, cloud platforms, and enterprise systems navigate the complex intersections of global industry standards without ever hitting a compliance roadblock. If you are ready to steer our risk registers, keep our audit readiness cruising in the fast lane, and ensure security is a green light for business growth rather than a bottleneck, buckle up and merge into our team!
Objectives and Responsibilities:
Risk & Control Execution
Identify, assess, and track enterprise, cyber, product, and third-party risks, actively expanding our cybersecurity risk universe.
Maintain risk scoring, treatment plans, and evidence in strict alignment with frameworks like ISO 27001, SOC 2, and NIST.
Drive risk remediation and manage risk acceptance workflows, ensuring clear justifications and proper executive approvals.
Governance, Risk & Compliance (GRC) Program Operations
Drive day-to-day GRC operations across ISO 27001, SOC 2, and NIST, intelligently mapping controls to eliminate duplication and boost efficiency.
Collect and validate rock-solid evidence for internal assessments while managing the lifecycle of our security policies and standards.
Proactively research, recommend, and implement high-impact process improvements to streamline compliance efforts.
Audit & Assurance Support
Bridge the gap between theoretical certification requirements and operational reality by building robust audit playbooks and practical controls.
Serve as a key player during critical external audits, coordinating with internal control owners to ensure lightning-fast, highly accurate evidence submission.
Craft accurate, confident responses to customer security questionnaires, RFPs, and due-diligence requests to accelerate sales.
Cross-Functional Enablement
Partner with Engineering, Cloud Ops, IT, and Product to seamlessly embed risk considerations into development, operations, and vendor onboarding.
Act as a key risk gatekeeper for product releases and major delivery milestones, operationalizing highly scalable security controls.
Drive highly engaging security awareness training and clear risk communications across the entire business.
Risk Culture & Cross-Functional Engagement
Champion security best practices and act as an approachable advocate to non-technical, cross-departmental teams.
Spearhead engaging initiatives that build and reinforce a highly resilient, company-wide security culture.
Actively participate in cross-functional risk forums and working groups to keep security top-of-mind across the organization.
Emerging Leadership & Development
Take total ownership of key GRC components (like third-party risk or policy governance) to continuously hone your skills as an independent practitioner.
Drive process automation and program maturity, securely leveraging AI tooling to accelerate and optimize your workflows.
Partner directly with the GRC Manager to support executive reporting and execute high-level strategic initiatives.
The Ideal Profile:
The Compliance Veteran: Experience in GRC, cyber risk, compliance, or information security, ideally within SaaS, cloud, or critical-infrastructure environments.
The Framework Guru: You possess deep, practical working knowledge of at least three major frameworks (ISO 27001, SOC 2, NIST, FedRAMP, FAIR, or COSO).
The Persuasive Diplomat: You know exactly how to explain a control gap to an engineer who passionately disagrees - and successfully get it fixed without causing friction.
The Independent Executor: You are a proactive self-starter who has independently taught yourself new frameworks, tools, or systems just to solve a complex problem you uncovered.
The Auditor's Best Friend: You are highly proficient with modern GRC platforms and have a proven, hands-on ability to build and operate bulletproof risk registers and control frameworks.
The AI Adopter: You are highly effective at using AI to speed up your workflows and ensure accuracy, but you possess the sharp judgment to immediately spot when the machine is wrong.
The Public-Sector Navigator: You bring valuable exposure to the strict, high-stakes requirements of public-sector or highly regulated customers (federal, state, municipal, or transportation agencies).
Your Rewards & Well-being:
We invest in our team with benefits designed for modern life and true work-life balance.
Comprehensive Coverage: Your well-being is covered from day one with comprehensive health benefits, 24/7 virtual healthcare access, and dedicated wellness programs.
Financial Future: Build for tomorrow with our RRSP/401K Matching Plan and share in the company's success through our Variable Incentive Plan.
Time to Recharge: Truly unplug with our unique Mio-Days and flexible vacation policy.
Work & Life Support: We support you with flexible work options, an internet subsidy, a remote work allowance, and enhanced leave for new parents.
Sound like your next adventure? Apply now and let's start building together!
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Please indicate if you require accommodation on your application, and our team will work with you to meet your accessibility needs.
Miovision may use artificial intelligence (AI) to assist in the hiring process for tasks such as helping to identify qualified candidates, taking meeting notes, creating summaries, and streamlining administrative work. These tools are one of several factors considered in the hiring process and do not replace human judgement. We do not use AI to make any final hiring or interview decisions.
PLEASE BE AWARE OF FRAUD: Applicants interested in applying for roles at Miovision should apply directly via the details provided on our careers page. We communicate directly with applicants and will not request banking information, payment, or fees during any point of the recruitment process. We do not conduct interviews via text message. If you suspect that a third party is impersonating Miovision or requesting payment for recruitment on behalf of Miovision, please alert us via recruitment@miovision.com.
To all recruitment agencies: Miovision does not accept agency solicitation or resumes. Please do not forward resumes to our HR alias e-mail address, to any Miovision employee, or to other Miovision e-mail addresses. Miovision will not pay any fees related to unsolicited resumes.