远程工作雷达

治理、风险与合规(GRC)经理

Governance, Risk & Compliance (GRC) Manager

开发工程未标注地域
公司Fullscript
薪资未公开
工作地点Ottawa, ON
地域资格未标注地域
时区要求无特别要求
用工类型Full Time
发布时间未知
数据来源Lever
前往企业招聘页投递 →

关于Fullscript

我们是一家领先的健康科技公司,致力于帮助人们改善健康。我们于2011年以一个简单的理念起步:让从业者更容易获取他们信任的产品,从而提供更好的护理。

这个简单的理念发展成为了一个全面支持护理各个环节的平台。如今,超过125,000名从业者使用Fullscript进行临床洞察、实验室解读、患者分析、教育以及获取高质量的补充剂。超过1000万名患者依赖Fullscript保持与护理计划的联系并完成治疗。

我们打造了让护理更智能、更人性化的工具。这些工具节省时间、简化决策,并帮助从业者更紧密地与他们关心的人保持联系。当所有所需都在一处时,他们可以专注于最重要的事:帮助人们改善健康。

这是你的邀请。

带来你的想法、毅力和对人们的关怀。
加入我们,共同塑造护理的未来。

机会

我们正在寻找一位经验丰富的治理、风险与合规(GRC)经理,领导并提升Fullscript的安全合规项目。这是一个需要亲力亲为的领导职位,负责推动我们的治理、风险和合规战略,同时直接管理两名GRC专业人员。

你将负责在多个框架下管理我们的安全合规项目,包括SOC 2 Type II、PCI DSS和HITRUST,确保我们在扩展控制措施的同时始终保持审计就绪状态。你将主导内部和外部审计,与安全、工程、基础设施、隐私、法律、产品和IT团队密切合作,并帮助将法规和客户要求转化为实际、可扩展的安全实践。

这个职位适合那些喜欢在战略项目管理与日常执行之间取得平衡,并且在高度协作、快速发展的SaaS环境中茁壮成长的人。

你将做的事情

治理与合规

  • 负责并持续改进Fullscript的治理、风险与合规项目。
  • 维护并持续提升在SOC 2 Type II、PCI DSS和HITRUST方面的合规性。
  • 制定并维护政策、标准、流程和控制文档。
  • 确保合规活动嵌入到运营流程中,而不是临时性的任务。
  • 跟踪法规、合同和客户合规义务,并确保适当的控制覆盖。
查看英文原文

About Fullscript

We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.

That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.

We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.

This is your invitation.

Bring your ideas, your grit, and your care for people.

Join us and shape the future of care.

The Opportunity

We're looking for an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature Fullscript's security compliance program. This is a hands-on leadership role responsible for driving our governance, risk, and compliance strategy while directly managing a team of two GRC professionals.

You'll own our security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring we remain continuously audit-ready while scaling our controls alongside the business. You'll lead internal and external audits, partner closely with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and help translate regulatory and customer requirements into practical, scalable security practices.

This role is ideal for someone who enjoys balancing strategic program ownership with day-to-day execution and who thrives in highly collaborative, fast-growing SaaS environments.

What You'll Do

Governance & Compliance

  • Own and evolve Fullscript's Governance, Risk & Compliance program.
  • Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST.
  • Develop and maintain policies, standards, procedures, and control documentation.
  • Ensure compliance activities are embedded into operational processes rather than point-in-time exercises.
  • Track regulatory, contractual, and customer compliance obligations and ensure appropriate control coverage.

Audit & Assurance

  • Lead all external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and successful certification.
  • Manage internal control assessments and readiness activities throughout the year.
  • Coordinate remediation efforts across Engineering, IT, Security, and business teams.
  • Own relationships with external auditors and assessment firms.
  • Develop reporting and dashboards that communicate compliance posture and audit readiness to leadership.

Risk Management

  • Partner with Security leadership to mature enterprise security risk management.
  • Maintain risk registers and facilitate risk assessments across technology and business functions.
  • Drive remediation planning and track progress through completion.
  • Support third-party risk management activities as required.

Cross-Functional Partnership

  • Build strong partnerships with Privacy and Legal to ensure alignment between security, regulatory, and privacy obligations.
  • Partner with Product, Engineering, Infrastructure, and IT to operationalize security controls.
  • Support customer security reviews, due diligence requests, and compliance questionnaires.
  • Provide practical guidance that enables business growth while maintaining an appropriate risk posture.

Leadership

  • Lead, coach, and develop a team of two GRC professionals.
  • Establish team priorities, operating cadence, and professional development plans.
  • Foster a culture of accountability, continuous improvement, and operational excellence.
  • Remain actively involved in execution, serving as a working manager who contributes directly to audits, control implementation, and compliance initiatives.

What You Bring

  • 7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance.
  • Previous people management experience leading small, high-performing teams.
  • Hands-on experience owning enterprise compliance programs within SaaS or healthcare technology organizations.
  • Demonstrated success leading external audits for:
  • SOC 2 Type II
  • PCI DSS
  • HITRUST
  • GDPR
  • Familiarity with HIPAA and its requirements.
  • Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders.
  • Strong understanding of security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST.
  • Experience partnering closely with Privacy and Legal teams on regulatory compliance initiatives.
  • Experience managing control evidence, remediation programs, and continuous compliance activities.
  • Strong project management and organizational skills with the ability to manage competing priorities.
  • Excellent written and verbal communication skills, with the ability to translate complex compliance requirements into practical business guidance.

Nice to Have

  • Healthcare or health technology experience.
  • Experience with GRC platforms such as Vanta, Drata, OneTrust, or similar.
  • Professional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor.
  • Experience supporting customer security reviews and enterprise sales due diligence.

Why This Role Matters

Trust is one of Fullscript's most important products. As our GRC Manager, you'll help ensure that our security and compliance programs scale alongside the business, enabling innovation while maintaining the confidence of our customers, partners, and regulators. You'll have the opportunity to shape the future of our compliance program, mentor a growing team, and influence security strategy across the organization.

What We Can Offer You

  • Generous PTO and competitive pay
  • Fullscript’s RRSP match program for financial health
  • Flexible benefits package and workplace wellness program
  • Training budget and company-wide learning initiatives
  • Discount on Fullscript catalog of products
  • Ability to work Wherever You Work Well*

Our Wherever You Work Well philosophy means Fullscript teammates get to pick their own office — whether that’s in-office, at home, or a bit of both 🐶🏡

Compensation rangeThe salary range for this role is between $140,000 and $165,000 CAD. Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only. Additional incentives, perks, and benefits may be available as part of Fullscript’s total rewards package.

Final base salary depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Why Fullscript

Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.

What to Know Before You Apply

We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.

A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.

Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at accommodations@fullscript.com.

All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.

We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.

Learn More

www.fullscript.com

@fullscriptHQ on instagram

Let’s make healthcare whole

本页面信息整理自 Lever,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位