
Governance, Risk & Compliance Manager
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Canada.
• Take ownership of and enhance Fullscript's Governance, Risk & Compliance program.
• Ensure ongoing compliance improvement across SOC 2 Type II, PCI DSS, and HITRUST.
• Create and maintain policies, standards, procedures, and control documentation.
• Integrate compliance activities into operational workflows.
• Monitor regulatory, contractual, and customer compliance obligations while ensuring adequate control coverage.
• Oversee external compliance audits, including planning, evidence gathering, auditor coordination, issue resolution, and certification.
• Manage internal control assessments and preparation activities.
• Coordinate remediation efforts with Engineering, IT, Security, and business teams.
• Cultivate relationships with external auditors and assessment firms.
• Develop reports and dashboards that communicate compliance status and audit readiness to leadership.
• Collaborate with Security leadership to advance enterprise security risk management.
• Maintain risk registers and facilitate risk assessments.
• Lead remediation planning and monitor progress until completion.
• Assist with third-party risk management activities.
• Partner with Privacy, Legal, Product, Engineering, Infrastructure, and IT to align obligations and operationalize security controls.
• Aid in customer security reviews, due diligence requests, and compliance questionnaires.
• Lead, mentor, and develop a team of two GRC professionals.
• Set team priorities, establish operating rhythms, and create professional development plans.
• Stay actively engaged in audits, control implementation, and compliance initiatives.
• Over 7 years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance.
• Prior experience managing small, high-performing teams.
• Practical experience managing enterprise compliance programs within SaaS or healthcare technology sectors.
• Proven track record in leading external audits for SOC 2 Type II, PCI DSS, and HITRUST.
• Knowledge of HIPAA and its associated requirements.
• Experience in coordinating multiple simultaneous compliance initiatives involving engineering and business stakeholders.
• Strong grasp of NIST CSF, CIS Controls, ISO 27001, and HITRUST.
• Experience collaborating closely with Privacy and Legal teams on regulatory compliance efforts.
• Background in managing control evidence, remediation programs, and ongoing compliance activities.
• Excellent project management and organizational skills, capable of handling competing priorities.
• Exceptional written and verbal communication skills, with the ability to convert complex compliance requirements into actionable business guidance.
• Experience in healthcare or health technology, familiarity with GRC platforms like Vanta, Drata, OneTrust, or similar, professional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor, as well as experience supporting customer security reviews and enterprise sales due diligence are beneficial.
• Generous PTO and competitive salary.
• Fullscript’s RRSP matching program for financial wellness.
• Flexible benefits package and workplace wellness initiatives.
• Training budget and organization-wide learning programs.
• Discounts on Fullscript's catalog of products.
• Option to work Wherever You Work Well — whether in-office, at home, or a combination of both.
Elfonze Technologies
Plooto
Eli Lilly and Company
Get handpicked remote jobs straight to your inbox weekly.