Governance, Risk & Compliance (GRC) Manager

🏢 Fullscript · all Fullscript jobs (13)
📍 Canada
💰 CAD 140,000 - 165,000 / annual
📅 Posted 2026-09-04 · via Himalayas
🏷 GRC-Manager,Security-Compliance-Manager,Compliance-Manager,Risk-Management,Information-Security-Manager,Governance-Risk-And-Compliance-Manager,Governance-And-Risk-Manager,Risk-and-Governance-Manager,Risk-And-Compliance-Manager,Cybersecurity-Governance-Risk-and-Compliance-Manager
Apply on original site ↗

About Fullscript

We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.
That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.
We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.

This is your invitation.
Bring your ideas, your grit, and your care for people.
Join us and shape the future of care.

The Opportunity

We're looking for an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature Fullscript 's security compliance program. This is a hands-on leadership role responsible for driving our governance, risk, and compliance strategy while directly managing a team of two GRC professionals.

You'll own our security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring we remain continuously audit-ready while scaling our controls alongside the business. You'll lead internal and external audits, partner closely with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and help translate regulatory and customer requirements into practical, scalable security practices.

This role is ideal for someone who enjoys balancing strategic program ownership with day-to-day execution and who thrives in highly collaborative, fast-growing SaaS environments.

What You'll Do

Governance & Compliance

-
Own and evolve Fullscript 's Governance, Risk & Compliance program.

-
Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST.

-
Develop and maintain policies, standards, procedures, and control documentation.

-
Ensure compliance activities are embedded into operational processes rather than point-in-time exercises.

-
Track regulatory, contractual, and customer compliance obligations and ensure appropriate control coverage.

Audit & Assurance

-
Lead all external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and successful certification.

-
Manage internal control assessments and readiness activities throughout the year.

-
Coordinate remediation efforts across Engineering, IT, Security, and business teams.

-
Own relationships with external auditors and assessment firms.

-
Develop reporting and dashboards that communicate compliance posture and audit readiness to leadership.

Risk Management

-
Partner with Security leadership to mature enterprise security risk management.

-
Maintain risk registers and facilitate risk assessments across technology and business functions.

-
Drive remediation planning and track progress through completion.

-
Support third-party risk management activities as required.

Cross-Functional Partnership

-
Build strong partnerships with Privacy and Legal to ensure alignment between security, regulatory, and privacy obligations.

-
Partner with Product, Engineering, Infrastructure, and IT to operationalize security controls.

-
Support customer security reviews, due diligence requests, and compliance questionnaires.

-
Provide practical guidance that enables business growth while maintaining an appropriate risk posture.

Leadership

-
Lead, coach, and develop a team of two GRC professionals.

-
Establish team priorities, operating cadence, and professional development plans.

-
Foster a culture of accountability, contin

← All remote jobs

Get remote legal jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you