394,870open jobs
13,845companies
76,904added this week
Browse all
Salary
$89k – $182k per year (Estimated)
Location
In office (Ottawa)
Seniority
Senior · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Our mission is 'helping people get better'. At Fullscript, we are all owners in driving this mission and builders in creating the future of healthcare.

The Opportunity

We're looking for an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature Fullscript's security compliance program. This is a hands-on leadership role responsible for driving our governance, risk, and compliance strategy while directly managing a team of two GRC professionals.

You'll own our security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring we remain continuously audit-ready while scaling our controls alongside the business. You'll lead internal and external audits, partner closely with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and help translate regulatory and customer requirements into practical, scalable security practices.

This role is ideal for someone who enjoys balancing strategic program ownership with day-to-day execution and who thrives in highly collaborative, fast-growing SaaS environments.

What You'll Do

Governance & Compliance

  • Own and evolve Fullscript's Governance, Risk & Compliance program.

  • Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST.

  • Develop and maintain policies, standards, procedures, and control documentation.

  • Ensure compliance activities are embedded into operational processes rather than point-in-time exercises.

  • Track regulatory, contractual, and customer compliance obligations and ensure appropriate control coverage.

Audit & Assurance

  • Lead all external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and successful certification.

  • Manage internal control assessments and readiness activities throughout the year.

  • Coordinate remediation efforts across Engineering, IT, Security, and business teams.

  • Own relationships with external auditors and assessment firms.

  • Develop reporting and dashboards that communicate compliance posture and audit readiness to leadership.

Risk Management

  • Partner with Security leadership to mature enterprise security risk management.

  • Maintain risk registers and facilitate risk assessments across technology and business functions.

  • Drive remediation planning and track progress through completion.

  • Support third-party risk management activities as required.

Cross-Functional Partnership

  • Build strong partnerships with Privacy and Legal to ensure alignment between security, regulatory, and privacy obligations.

  • Partner with Product, Engineering, Infrastructure, and IT to operationalize security controls.

  • Support customer security reviews, due diligence requests, and compliance questionnaires.

  • Provide practical guidance that enables business growth while maintaining an appropriate risk posture.

Leadership

  • Lead, coach, and develop a team of two GRC professionals.

  • Establish team priorities, operating cadence, and professional development plans.

  • Foster a culture of accountability, continuous improvement, and operational excellence.

  • Remain actively involved in execution, serving as a working manager who contributes directly to audits, control implementation, and compliance initiatives.

What You Bring

  • 7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance.

  • Previous people management experience leading small, high-performing teams.

  • Hands-on experience owning enterprise compliance programs within SaaS or healthcare technology organizations.

  • Demonstrated success leading external audits for:

  • SOC 2 Type II

  • PCI DSS

  • HITRUST

  • Familiarity with HIPAA and its requirements.

  • Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders.

  • Strong understanding of security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST.

  • Experience partnering closely with Privacy and Legal teams on regulatory compliance initiatives.

  • Experience managing control evidence, remediation programs, and continuous compliance activities.

  • Strong project management and organizational skills with the ability to manage competing priorities.

  • Excellent written and verbal communication skills, with the ability to translate complex compliance requirements into practical business guidance.

Nice to Have

  • Healthcare or health technology experience.

  • Experience with GRC platforms such as Vanta, Drata, OneTrust, or similar.

  • Professional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor.

  • Experience supporting customer security reviews and enterprise sales due diligence.

Why This Role Matters

Trust is one of Fullscript's most important products. As our GRC Manager, you'll help ensure that our security and compliance programs scale alongside the business, enabling innovation while maintaining the confidence of our customers, partners, and regulators. You'll have the opportunity to shape the future of our compliance program, mentor a growing team, and influence security strategy across the organization.

What We Can Offer You

  • Generous PTO and competitive pay

  • Fullscript’s RRSP match program for financial health

  • Flexible benefits package and workplace wellness program

  • Training budget and company-wide learning initiatives

  • Discount on Fullscript catalog of products

  • Ability to work Wherever You Work Well*

Our Wherever You Work Well philosophy means Fullscript teammates get to pick their own office - whether that’s in-office, at home, or a bit of both

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
394,870 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Ottawa
$180k – $230k per year • Equity 0.2–0.4% • In office • Full-Time • 6+ years exp • San Francisco
Python
Databases
PostgreSQL
DevOps
AWS
Azure
Cybersecurity
FedRAMP
HIPAA
NIST 800-53
SOC 2
Apply
$150k – $250k per year • In office • Full-Time • 6+ years exp • New York
DevOps
AWS
Azure
Cybersecurity
GDPR
ISO 27001
SOC 2
Zero Trust
Apply
Staff IT Engineer 2 days ago
$200k – $240k per year • Equity • Remote/Hybrid • Full-Time • 10+ years exp
Python
SQL
AI/ML
AI Agents
NLP
Frontend
GraphQL
DevOps
Ansible
AWS
Azure
GCP
IAM
Terraform
Cybersecurity
HIPAA
Least Privilege
SOC 2
Management
n8n
Apply
$139k – $345k per year (Estimated) • Equity • In office • 15+ years exp • Master's Degree • Palo Alto
Databases
Databricks
Snowflake
AI/ML
AI Agents
LLM Guardrails
NIST AI RMF
Mobile
Algolia
DevOps
CI/CD
GCP
SLI/SLO/SLA
Cybersecurity
Carbon Black
Crowdstrike
ISO 27001
NIST CSF
Okta
OWASP Top 10
SentinelOne
Management
Obsidian
Marketing
Salesforce
Apply
In office • Full-Time • 6+ years exp • PhD • Philadelphia
Cybersecurity
HIPAA
Apply
$100k – $125k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree
Marketing
Instagram
LinkedIn
YouTube
Apply
Staff Engineer 3 days ago
$134k – $235k per year (Estimated) • Remote • Full-Time • 8+ years exp • Ottawa
Python
Ruby
SQL
TypeScript
Databases
PostgreSQL
Snowflake
AI/ML
AI Agents
AWS Bedrock
Function Calling
Langfuse
LLM
Model Context Protocol
Agentic Workflows
Tool Use
Frontend
GraphQL
DevOps
Amazon EKS
AWS
CI/CD
Cloudflare
GitLab
GitLab CI
Kubernetes
Cybersecurity
HIPAA
SOC 2
Management
n8n
Marketing
Instagram
LinkedIn
YouTube
QA
Sentry
Apply
Remote • Full-Time • Toronto
AI/ML
ChatGPT
Claude
Human-in-the-Loop
Management
n8n
Zapier
Marketing
Instagram
LinkedIn
YouTube
Apply
$120k – $235k per year (Estimated) • In office • Full-Time • Ottawa
JavaScript
Frontend
GraphQL
React.js
Mobile
React Native
Apply
$40k per year • In office • Full-Time • 1+ year exp • High School Diploma • Phoenix
Apply
Remote • Full-Time • 10+ years exp • Calgary • Ottawa • Toronto • Vancouver • Montreal
Management
Asana
Slack
Marketing
Ahrefs
Screaming Frog
Apply
$107k – $217k per year (Estimated) • Remote • Full-Time • 10+ years exp • Calgary • Ottawa • Toronto • Vancouver • Montreal
Management
Asana
Slack
Marketing
Ahrefs
Screaming Frog
Apply
In office • Internship • Ottawa
MATLAB
Python
DevOps
Git
Apply
In office • Internship • Ottawa
AI/ML
LLM
Apply
$56k – $144k per year (Estimated) • Remote/Hybrid • Internship • Bachelor's Degree • Ottawa
C#
C++
Java
Python
DevOps
Ansible
Docker
GitLab
Kubernetes
Windows Server
Management
Confluence
Apply
See all jobs
This is one of many
394,870 more open roles from verified company boards, updated every day.