11 Sep
|
Fullscript
|
Ottawa
- We’re looking for an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature Fullscript’s security compliance program. This is a hands-on leadership role responsible for driving our governance, risk, and compliance strategy while directly managing a team of two GRC professionals - You’ll own our security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring we remain continuously audit-ready while scaling our controls alongside the business - You’ll lead internal and external audits, partner closely with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and help translate regulatory and customer requirements into practical, scalable security practices - This role is ideal for someone who enjoys balancing strategic program ownership with day-to-day execution and who thrives in highly collaborative, fast-growing SaaS environments - Governance & Compliance:
- Own and evolve Fullscript’s Governance, Risk & Compliance program - Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST - Develop and maintain policies, standards, procedures, and control documentation - Ensure compliance activities are embedded into operational processes rather than point-in-time exercises - Track regulatory, contractual, and customer compliance obligations and ensure appropriate control coverage - Audit & Assurance:
- Lead all external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and successful certification - Manage internal control assessments and readiness activities throughout the year - Coordinate remediation efforts across Engineering, IT, Security, and business teams - Own relationships with external auditors and assessment firms - Develop reporting and dashboards that communicate compliance posture and audit readiness to leadership - Risk Management:
- Partner with Security leadership to mature enterprise security risk management - Maintain risk registers and facilitate risk assessments across technology and business functions - Drive remediation planning and track progress through completion - Support third-party risk management activities as required - Cross-Functional Partnership:
- Build strong partnerships with Privacy and Legal to ensure alignment between security, regulatory, and privacy obligations - Partner with Product, Engineering, Infrastructure, and IT to operationalize security controls - Support customer security reviews, due diligence requests, and compliance questionnaires - Provide practical guidance that enables business growth while maintaining an appropriate risk posture - Leadership:
- Lead, coach, and develop a team of two GRC professionals - Establish team priorities, operating cadence, and professional development plans - Foster a culture of accountability, continuous improvement, and operational excellence - Remain actively involved in execution, serving as a working manager who contributes directly to audits, control implementation, and compliance initiatives - Trust is one of Fullscript’s most important products - As our GRC Manager, you’ll help ensure that our security and compliance programs scale alongside the business, enabling innovation while maintaining the confidence of our customers, partners, and regulators - You’ll have the opportunity to shape the future of our compliance program, mentor a growing team, and influence security strategy across the organization Benefits - Reach your wellness goals with our benefits plan, discount on practitioner-grade supplements, and company-wide health and wellness programs - Our dedicated DEIB Council ensures we advocate for equality and encourage positive change within ourselves and the community. We value the unique qualities and perspectives of our team - You choose your own office with our Wherever You Work Well approach. Whether that’s in-person or at home,
teams aren’t defined by geography. Output, not location, is our success metric so we also offer a flexible approach to your working hours, vacation, and personal days - We empower each other to grow with lunch and learns, lean in circles, show-and-tells, and more. Everyone has something to learn and something to teach so we pride ourselves on growing as a team - We’re not just a company — we’re a community. Team lunches, weekly town halls, birthdays, parties, and clubs are an essential part of our community and culture - The health of our people relies on the health of our planet. We are certified carbon-neutral, taking our first big step in creating a more sustainable future - Hands-on experience owning enterprise compliance programs within SaaS or healthcare technology organizations - Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders - Experience managing control evidence, remediation programs, and continuous compliance activities - Previous people management experience leading small, high-performing teams - Solid understanding of security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST - Strong project management and organizational skills with the ability to manage competing priorities - HITRUSTSOC 2 Type II - Experience partnering closely with Privacy and Legal teams on regulatory compliance initiatives - Demonstrated success leading external audits for:
- PCI DSSFamiliarity with HIPAA and its requirementsExcellent written and verbal communication skills, with the ability to translate complex compliance requirements into practical business guidance7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security ComplianceHealthcare or health technology experienceProfessional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead AuditorExperience with GRC platforms such as Vanta, Drata, OneTrust, or similarExperience supporting customer security reviews and enterprise sales due diligence
📌 Governance, Risk & Compliance Manager (Ottawa)
🏢 Fullscript
📍 Ottawa