CapGRC
CapGRC
Careers

Join the CapGRC Team

Build the leading Canadian GRC platform

CAPTOSEC Inc. is a fast-growing Quebec cybersecurity firm. We are looking for passionate professionals who want to have a real impact on the security of Canadian organizations.

8
Open positions
4
Immediate hires
Hybride
Work model
Québec
Headquarters

Why join CapGRC?

🇨🇦
Canadian Impact
Protect millions of Canadians
🚀
Fast Growth
Fast-growing startup
🏡
Hybrid / Remote
Flexibility and work-life balance
🧠
Deep Expertise
Team of recognized experts

🔴 Priority Positions — Immediate Hiring

(4 positions)
High priorityFull-time📍 Quebec City / Hybrid

Customer Success Manager

Champion of client satisfaction, retention, and growth

Client RelationsOnboardingRetentionGRC

The CSM bridges the gap between the CapGRC team and clients after contract signing. They ensure every client meets their compliance goals, fully adopts the platform, and renews their subscription.

Expected Missions

  • Lead structured onboarding sessions (Day 1, 7, 30, 90)
  • Track adoption metrics and intervene when stagnation occurs
  • Hold quarterly business reviews to measure value delivered
  • Identify upsell opportunities and report to the sales team
  • Collect client feedback and relay it structurally to the product team

Critical role for Enterprise and Government clients.

High priorityFull-time📍 Quebec City / Remote

Senior Full Stack Developer

Accelerate feature delivery and maintain code quality

Next.jsTypeScriptReactREST API

As the product roadmap accelerates, a Senior Full Stack Developer is essential to deliver expected features without technical debt, in a modern and demanding engineering environment.

Expected Missions

  • Develop new platform features (Next.js / TypeScript / Tailwind)
  • Implement and test integration APIs (JIRA, Azure AD, Slack, Webhooks)
  • Contribute to code reviews and maintain DevSecOps standards
  • Write unit (Vitest) and end-to-end (Playwright) tests
  • Participate in feature architecture with the CTO

Proficiency in Next.js App Router, strict TypeScript, and Server Actions required.

High priorityFull-time📍 Quebec City / Hybrid

Growth & Digital Marketing Manager

Generate qualified leads and build CapGRC brand awareness in Canada

SEOLead GenerationB2B MarketingContent

CapGRC has a solid marketing foundation but needs a dedicated manager to turn this into a commercial pipeline. This role drives acquisition, nurtures leads, and measures ROI across every channel.

Expected Missions

  • Define and execute the acquisition strategy (SEO, LinkedIn Ads, partnerships)
  • Lead the editorial calendar (articles, webinars, guides) to generate leads
  • Manage email marketing and automation campaigns
  • Analyze acquisition metrics and continuously optimize
  • Coordinate relations with industry associations (ISACA, ASIS)

Experience in B2B SaaS software or cybersecurity marketing strongly preferred.

High priorityFull-time📍 Quebec City / Hybrid

Account Executive

Head of sales and business development

B2B SaaS SalesDemosNegotiationPublic Sector

CapGRC has the ability to convert demos into contracts. This role manages the prospect pipeline from demo request to contract signing, with a strong understanding of the Quebec public sector sales cycle.

Expected Missions

  • Manage the commercial pipeline: lead qualification, follow-ups, and outreach
  • Deliver customized demos based on the prospect's sector and challenges
  • Write commercial proposals and negotiate contracts
  • Develop partnerships with integrators and consulting firms
  • Hit quarterly revenue targets (ARR, new clients, account expansion)

Knowledge of the Quebec public sector procurement process (SEAO) is a strong asset.

🟠 Important Positions — Medium-term Hiring

(3 positions)
Medium priorityFull-time📍 Quebec City / Hybrid

Third-Party Risk Management Expert

Specialist in vendor risk management (CapTRISK module)

Third-Party RiskTPRMSecurity QuestionnairesContracts

With growing adoption of the CapTRISK module, a TPRM expert is needed to enrich questionnaires, lead training, and support clients in building their vendor risk programs.

Expected Missions

  • Enrich the vendor security questionnaire library (CAIQ, SIG, sector-specific)
  • Develop the third-party risk scoring methodology within CapTRISK
  • Support clients in deploying their TPRM program
  • Monitor supply chain incidents (SolarWinds, Log4j, etc.)
  • Write practical guides on third-party risk management

CTPRA certification or equivalent appreciated.

Medium priorityFull-time📍 Quebec City

Legal Counsel & Data Protection Officer (DPO)

Guardian of CapGRC legal compliance and legal advisor for clients

Digital LawDPOLaw 25Privacy

As a compliance platform, CapGRC must be legally impeccable. This counsel validates client contracts, oversees data processing practices, and answers clients legal questions.

Expected Missions

  • Ensure CAPTOSEC Inc. legal compliance: contracts, ToS, privacy policy
  • Act as DPO for CapGRC and advise clients on their legal obligations
  • Validate the regulatory content of frameworks integrated in the platform
  • Help clients draft their internal data protection policies
  • Monitor legislative changes (CAI, OPC, EU directives with Canadian impact)

Quebec Bar member. Law 25, PIPEDA, and GDPR knowledge required.

Medium priorityFull-time📍 Quebec City / Hybrid

Technical Support Manager

First point of contact for technical questions and client incidents

L1/L2 SupportIntegrationsDocumentationSLA

As the client base grows, a dedicated technical support manager is essential for handling tickets, documenting solutions, and maintaining SLAs. This role also owns end-user technical documentation.

Expected Missions

  • Handle support tickets (L1 and L2) through the incident management system
  • Document solutions and enrich the internal and public knowledge base
  • Assist clients during technical integrations (SSO, API, data exports)
  • Ensure SLA compliance and escalate critical incidents to the CTO
  • Monitor the platform and alert the engineering team

Fully bilingual FR/EN is essential for English-speaking client support.

⚪ Future Positions — Long-term Growth

(1 position)
Low priorityFull-time📍 Quebec City / Hybrid

Internal Audit & GRC Programs Expert

Specialist in CapAUDIT and GRC Programs modules — advanced client support

Internal AuditIIAGRC ProgramsGovernance

As mature clients use CapAUDIT intensively, this expert enriches templates, trains client audit teams, and produces reference content on best practices.

Expected Missions

  • Develop audit templates in CapAUDIT (public sector, finance, healthcare)
  • Train clients internal audit teams in advanced CapAUDIT usage
  • Produce guides on internal audit best practices in the Canadian context
  • Participate in client pilot audit committees to validate features
  • Contribute to the CapAUDIT module roadmap

CIA (Certified Internal Auditor) or IIA Canada CRMA certification strongly preferred.

Your profile is not listed?

We are always looking for exceptional talent. Send us an open application and tell us how you can contribute to the CapGRC mission.

Send My Application

info@captosec.com