We’re an industry-leading health technology company on a mission to help people get better. Make it easier for practitioners to access the products they trust so they can deliver better care. That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment. We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better. Bring your ideas, your grit, and your care for people. Join us and shape the future of care. We're looking for an experienced Governance, Risk &
• Compliance (GRC) Manager to lead and mature Fullscript's security compliance program. This is a hands-on leadership role responsible for driving our governance, risk, and compliance strategy while directly managing a team of two GRC professionals. You’ll own our security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring we remain continuously audit-ready while scaling our controls alongside the business. You’ll lead internal and external audits, partner closely with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and help translate regulatory and customer requirements into practical, scalable security practices. Governance &
• Compliance Own and evolve Fullscript's Governance, Risk &
• Compliance program. Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST. Develop and maintain policies, standards, procedures, and control documentation. Ensure compliance activities are embedded into operational processes rather than point-in-time exercises. Track regulatory,
contractual, and customer compliance obligations and ensure appropriate control coverage. Audit &
• Assurance Lead all external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and successful certification. Manage internal control assessments and readiness activities throughout the year. Develop reporting and dashboards that communicate compliance posture and audit readiness to leadership.
Risk Management
Partner with Security leadership to mature enterprise security risk management. Maintain risk registers and facilitate risk assessments across technology and business functions. Support third-party risk management activities as required.
Build strong partnerships with Privacy and Legal to ensure alignment between security, regulatory, and privacy obligations. Support customer security reviews, due diligence requests, and compliance questionnaires. Provide practical guidance that enables business growth while maintaining an appropriate risk posture.
Foster a culture of accountability, continuous improvement, and operational excellence. Remain actively involved in execution, serving as a working manager who contributes directly to audits, control implementation, and compliance initiatives. 7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance. ~ Previous people management experience leading small, high-performing teams. ~ Hands‑on experience owning enterprise compliance programs within SaaS or healthcare technology organizations. ~ Demonstrated success leading external audits for:
Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders. Solid understanding of security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST.
Experience partnering closely with Privacy and Legal teams on regulatory compliance initiatives.
Experience managing control evidence, remediation programs, and continuous compliance activities. Strong project management and organizational skills with the ability to manage competing priorities. Excellent written and verbal communication skills, with the ability to translate complex compliance requirements into practical business guidance.
Experience supporting customer security reviews and enterprise sales due diligence. As our GRC Manager, you'll help ensure that our security and compliance programs scale alongside the business, enabling innovation while maintaining the confidence of our customers, partners, and regulators. You'll have the opportunity to shape the future of our compliance program, mentor a growing team, and influence security strategy across the organization.
Generous PTO and competitive pay Flexible benefits package and workplace wellness program Training budget and company-wide learning initiatives Our Wherever You Work Well philosophy means Fullscript teammates get to pick their own office — whether that’s in‑office, at home, or a bit of both The salary range for this role is between $140,000 and $165,000 CAD. Fullscript shares salary ranges to support transparency and help candidates make informed decisions. We review pay regularly to stay aligned with market data and internal equity.
Accommodations are available upon request at
[email protected] offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.
📌 Governance, Risk & Compliance (GRC) Manager (Toronto)
🏢 Fullscript
📍 Toronto