About the Role
The Governance, Risk & Compliance Analyst is a key contributor to Docebo's security and compliance program. This role supports the development and maintenance of our security framework, helping to ensure the company meets its regulatory obligations and effectively communicates its compliance standing to both internal and external stakeholders. Working under the guidance of senior team members, this individual will assist in various governance, risk, and compliance activities. The role involves collaboration with teams across the organization, including Sales and Legal, to help address customer inquiries related to security and compliance. This position offers an opportunity to grow and learn within a dynamic security environment, contributing to the continuous improvement of our control environment.
Responsibilities
- Assist in the creation and maintenance of cybersecurity and privacy policies, standards, and control frameworks to align with key industry regulations (e.g., PCI DSS, ISO 27001, SOC 2) and business goals.
- Participate in cybersecurity risk assessments by identifying and documenting potential risks.
- Support the monitoring and tracking of risk treatment plans.
- Provide support for internal and external audits (e.g., ISO 27001, SOC 2, PCI DSS) by gathering evidence, coordinating with internal teams, and managing audit-related tasks.
- Assist in evaluating risks associated with third-party vendors by supporting the monitoring of their security controls and maintaining risk management reports.
- Maintain clear and organized documentation of compliance activities, including risk assessments, risk register, and control inventory and audit evidence.
- Assist in preparing reports on the GRC program's status for management.
- Work with various departments to support the implementation of security controls and align compliance and security efforts with business objectives.
- Respond to customer security and privacy inquiries by completing compliance questionnaires and contributing to RFIs and RFPs.
Requirements
- Foundational understanding of security and compliance concepts.
- Strong desire to learn and grow in the field.
- Detail-oriented and organized approach.
- Good communication skills.
- Proactive mindset and ability to work effectively as part of a team.
Skills
- IT Risk Management
- Governance
- Information Security
- Security Policies
- Risk Assessments
- Internal/External Audits
- SaaS
- Information Security Principles
- Cloud Environments (AWS, Azure, GCloud)
- GDPR
- Data Privacy Laws (CCPA, PIPEDA)
- ISO/IEC 27001
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- ISO 9001
- SOX
- DORA
- NIST CSF
- AICPA/ISAE 3000 SOC 2
- PCI DSS
- FedRamp
Location
- Remote
- Hybrid
Work Type
- Hybrid
Experience Level
- 3+ years of relevant work experience
Salary/Compensations
- Competitive compensation package
Benefits
- Employee Share Purchase Plan (ESPP) at a 15% discount
- Health benefits
- Paid vacation days
- Two company-wide Docebo Days
- Floating holidays
- Birthday off
- Paid parental leave
About the Company
- At Docebo, we create seamless, AI-powered learning experiences for over 3,000 customers worldwide.
- We have successfully achieved two IPOs (TSX: DCBO & NASDAQ: DCBO).
- Recognized as a top SaaS e-learning solution.
- Growing exponentially.
- Global company with offices across North America, EMEA, APAC, and beyond.
- Guided by six core values—Innovation, Simplicity, Accountability, Togetherness, Curiosity, and Impact.
Equal Opportunity
- Docebo is an Equal Employment Opportunity employer.
- We are committed to diversity and inclusion in our workforce.
- All qualified applicants and employees will receive consideration for employment regardless of their race, colour, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, citizenship status, age, disability, genetic information, or any other category protected under applicable law.
- As a federal contractor, Docebo is committed to the principles of affirmative action and equal employment opportunity for protected veterans and individuals with disabilities.
- Docebo does not discriminate because of protected veteran status or on the basis of disability, and Docebo takes affirmative action to employ and advance in employment qualified protected veterans and individuals with disabilities.
- Any individuals requiring a reasonable accommodation or would like to voluntarily disclose a disability or protected veteran status to assist with their employment application should send an e-mail to recruiting_accommodations@docebo.com. The email should also include the position you’re interested in.
