Governance, Risk & Compliance (GRC) Manager
$140k - $165k per yearFullscript
About Fullscript
We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.
That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.
We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.
This is your invitation.
Bring your ideas, your grit, and your care for people.
Join us and shape the future of care.
The Opportunity
We're looking for an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature Fullscript's security compliance program. This is a hands-on leadership role responsible for driving our governance, risk, and compliance strategy while directly managing a team of two GRC professionals.
You'll own our security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring we remain continuously audit-ready while scaling our controls alongside the business. You'll lead internal and external audits, partner closely with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and help translate regulatory and customer requirements into practical, scalable security practices.
This role is ideal for someone who enjoys balancing strategic program ownership with day-to-day execution and who thrives in highly collaborative, fast-growing SaaS environments.
What You'll Do
Governance & Compliance
Own and evolve Fullscript's Governance, Risk & Compliance program.
Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST.
Develop and maintain policies, standards, procedures, and control documentation.
Ensure compliance activities are embedded into operational processes rather than point-in-time exercises.
Track regulatory, contractual, and customer compliance obligations and ensure appropriate control coverage.
Audit & Assurance
Lead all external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and successful certification.
Manage internal control assessments and readiness activities throughout the year.
Coordinate remediation efforts across Engineering, IT, Security, and business teams.
Own relationships with external auditors and assessment firms.
Develop reporting and dashboards that communicate compliance posture and audit readiness to leadership.
Risk Management
Partner with Security leadership to mature enterprise security risk management.
Maintain risk registers and facilitate risk assessments across technology and business functions.
Drive remediation planning and track progress through completion.
Support third-party risk management activities as required.
Cross-Functional Partnership
Build strong partnerships with Privacy and Legal to ensure alignment between security, regulatory, and privacy obligations.
Partner with Product, Engineering, Infrastructure, and IT to operationalize security controls.
Support customer security reviews, due diligence requests, and compliance questionnaires.
Provide practical guidance that enables business growth while maintaining an appropriate risk posture.
Leadership
Lead, coach, and develop a team of two GRC professionals.
Establish team priorities, operating cadence, and professional development plans.
Foster a culture of accountability, continuous improvement, and operational excellence.
Remain actively involved in execution, serving as a working manager who contributes directly to audits, control implementation, and compliance initiatives.
What You Bring
7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance.
Previous people management experience leading small, high-performing teams.
Hands-on experience owning enterprise compliance programs within SaaS or healthcare technology organizations.
Demonstrated success leading external audits for:
SOC 2 Type II
PCI DSS
HITRUST
Familiarity with HIPAA and its requirements.
Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders.
Strong understanding of security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST.
Experience partnering closely with Privacy and Legal teams on regulatory compliance initiatives.
Experience managing control evidence, remediation programs, and continuous compliance activities.
Strong project management and organizational skills with the ability to manage competing priorities.
Excellent written and verbal communication skills, with the ability to translate complex compliance requirements into practical business guidance.
Nice to Have
Healthcare or health technology experience.
Experience with GRC platforms such as Vanta, Drata, OneTrust, or similar.
Professional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor.
Experience supporting customer security reviews and enterprise sales due diligence.
Why This Role Matters
Trust is one of Fullscript's most important products. As our GRC Manager, you'll help ensure that our security and compliance programs scale alongside the business, enabling innovation while maintaining the confidence of our customers, partners, and regulators. You'll have the opportunity to shape the future of our compliance program, mentor a growing team, and influence security strategy across the organization.
What We Can Offer You
Generous PTO and competitive pay
Fullscript’s RRSP match program for financial health
Flexible benefits package and workplace wellness program
Training budget and company-wide learning initiatives
Discount on Fullscript catalog of products
Ability to work Wherever You Work Well*
Our Wherever You Work Well philosophy means Fullscript teammates get to pick their own office — whether that’s in-office, at home, or a bit of both
Compensation range
The salary range for this role is between $140,000 and $165,000 CAD. Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only. Additional incentives, perks, and benefits may be available as part of Fullscript’s total rewards package.
Why Fullscript
Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.
What to Know Before You Apply
We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.
A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.
Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected] .
All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.
We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.
Learn More
@fullscriptHQ on instagram
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
- ...learning platform that helps organizations create, deliver, and manage training all in one place. But our real mission goes deeper... ...the way people learn, because learning never stops. The Governance, Risk & Compliance Analyst is a key contributor to Docebo's security and...SuggestedFull timeFor contractorsWork at officeWorldwide3 days per week
$175k - $190k per year
...Perkopolis and participate in our rewards and recognition programs to celebrate your contributions. The Job: Director, Governance, Risk and Compliance (GRC) We’re seeking a Director, Governance, Risk and Compliance (GRC) to lead and operate MFSG’s cybersecurity governance,...SuggestedTemporary workWork at officeRemote work$98k - $139.5k per year
...every stage. Join a firm where your career can make a difference. Our Governance, Risk and Compliance Services (GRCS) professionals provide a range of advisory services to optimize risk management and internal control frameworks, internal audit functions and enterprise...SuggestedFull timeInternship$101k - $169k per year
...coaching -- What will your typical day look like? As a Manager in Governance, Risk and Resilience, you will work collaboratively within a high... ...Risk, we have professionals who specialize in regulatory compliance, business resilience, board governance, corporate...SuggestedPermanent employmentFlexible hoursShift work- ...clients across space, aerospace, defense, government, financial services, and critical... ...resilience. Our advisors shape the governance, risk, and compliance programs that underpin cutting-edge... ...Advisor to lead our most strategic GRC engagements and to help scale our advisory...SuggestedFull timeInternshipRemote work
$135k - $150k per year
...Our client is a large mining company. They are looking for a Manager of Treasury & Risk Management to join their team! Why Work Here ·... ...here and in French here . Residents of countries governed by GDPR may access our policies here . Additionally, submissions...Contract workFor contractorsWork at officeLocal area- ...RSA Archer Solution Architect – GRC, Risk & Compliance • Define enterprise architecture and solution strategy for RSA Archer/GRC platform... ...patterns, data models, security architecture, and platform governance. • Lead architecture reviews, roadmap planning, and modernization...Permanent employment
- ...Systems (GHS) is an enterprise systems, and managed services solutions provider that... ...into positive client experiences. The Risk & Compliance Specialist is responsible for identifying... ...and minimize risk exposure. Risk Management: Conduct comprehensive risk assessments...Full time
- ...Technical Project Manager - GRC, Risk Management Toronto, ON - Hybrid (4 Days WFO) • Key skills include comprehensive project planning... ...This position manages cross functional teams, drives program governance through regular status reporting, RAID management, and...Permanent employment
- ...The Work The Director, Payments Risk & Compliance is the first-line accountability leader... ..., including BIN Sponsorship, program management, and strategic fintech partnerships.... ...and are supported by sound controls and governance. The Risk Manager works closely with second...Hourly payPermanent employmentFull timeInternshipWork at office
$48.96 - $57.11 per hour
We are seeking a highly motivated Compliance and Risk Management Analyst for a contract opportunity based in Toronto. In this role, you will take on... ...primarily on mobile infrastructure security and endpoint governance. As a compliance and risk management analyst, you will...Contract workImmediate start- ...is a requirement for building great products. Join us on our mission and shape the future! Why this role? The Governance, Risk, and Compliance (GRC) team at Cohere operates as a centralized function within the Security organization, leading efforts across governance...Full timeWork at officeRemote workFlexible hours
$78.2k - $105.8k per year
...Senior IT Consultant, IT Audit, Risk and Compliance Richter Toronto Office Overview Richter... ...career with the direct support of your managers and firm partners; A culture that... ...engagements ~ Enterprise Risk Management and governance mandates ~ Cybersecurity assessments...Full timeWork at officeFlexible hours$90k - $111k per year
...Denver, Leeds and Dublin. Overview As Manager, Compliance at Fanatics Betting & Gaming, you will... ...to: i) define and assess compliance risks associated with international... ...Experience communicating with regulators, government authorities, and senior executives ~...Long term contractFull timeSeasonal work- ...being of Canadians. As a leading wealth management organization, we are committed to leadership... ...’re looking for an experienced Security GRC Specialist to join our growing Security... ...Reporting to the Director of Security Governance, Risk & Compliance (GRC), the Security GRC...Full timeInternship
$140k - $150k per year
...seeking a dedicated and experienced Compliance Officer / MLRO to lead these... ...appropriate localized governance to do the same. You will find... ...our Product, Global Payments, Risk, Business, and Operations functions... ...Canadian Compliance & Regulatory Manager will assist the organization...Full timeInternshipLocal areaImmediate startRemote workWorldwide- ...possible. Our Rogers Bank Regulatory Compliance Management (RCM) function supports the business and... ...and reporting of regulatory compliance risks across the bank. As part of the RCM function... ...the day-to-day functionality of the GRC-Resolver system, in relation to the RCM...Full timeContract workBank staffFlexible hoursShift work
$126k - $234k per year
...typical day look like? Shape the future of Operational Risk and Compliance Technology - Advise clients on how to modernize their risk and... ..., process experts, and industry-leading vendors. Manage GRC technology programs and services - Oversee solution assessment...Permanent employmentFlexible hours$88 per hour
Our client, a large enterprise organization, is seeking a Senior Project Manager to lead governance and risk-focused initiatives within a large enterprise environment. This is an 8-month contract (with potential extension), starting ASAP, operating in a hybrid model with 2...Contract workImmediate start- ...Overview Boyd Interactive is seeking an experienced and strategic Compliance Manager to lead and oversee the full compliance product and platform... ..., Responsible Gaming, regulatory compliance frameworks, and risk management principles ~ Demonstrated ability to interpret...Full timeCasual workWork at officeFlexible hours3 days per week
$85k - $156k per year
...Assurance at a world-class organization. As a Technology Risk & Compliance (TRC) Manager within our Global Audit & Assurance (A&A) Digital Products... ...and thought leaders, you will champion technology risk governance across every stage of the Software Development Lifecycle (...Permanent employmentInternshipRemote workFlexible hours- ...billion in combined assets under management and administration, with a... ...The Senior Manager, Risk Transformation Enablement is... ...priorities across transformation, governance, regulatory engagement, and strategy... ...outcomes aligned with Risk & Compliance senior leadership, including...Hourly payPermanent employmentFull timeWork at office
- ...POSITION Overview Boyd Interactive is seeking an experienced Compliance Manager with strong Anti-Money Laundering (AML) and regulatory... ...closely with Regulatory Compliance, Legal, Payments and Fraud, Risk, and other business functions to ensure regulatory obligations...Full timeCasual workWork at officeFlexible hours
$207k - $253k per year
...exciting phase of growth, and we’re hiring an Engineering Manager for the Risk team to help scale what comes next. You’ll be making high-impact... ...Functional Collaboration: Work closely with Product, Risk, Compliance, Operations, and other partners to turn ambiguous risk...Full timeInternship$140k - $170k per year
...Senior Manager Information Compliance AI Governance & Privacy In Canada -Toronto Simon-Kucher is looking for a Senior Manager Information Compliance... ...AI Governance & Privacy to join our Legal Compliance & Risk function as part of the Information Compliance Team....Full timeWork at officeWork from homeFlexible hours$153k - $197k per year
...Lead complex risk assessment design initiatives, bringing together project management discipline, consulting expertise, and effective... ...ll work across business, risk, compliance, operations, and technology... ...management methodologies and governance processes to establish clear delivery...Full timeInternshipImmediate start$120k - $135k per year
...OpenTable's Finance team is looking for a Manager, IT Risk and Controls! The Manager, IT Risk &... ...supporting financial reporting (e.g., SOX compliance). Guide teams in the execution of... ...senior leadership as needed. Policy, Governance & Program Management Develop and...Full timeWork at officeLocal areaFlexible hours2 days per week- ...We can’t wait to get to know you! The Work We are looking for a Senior Manager, Business Compliance who will supervise PC Bank’s Regulatory Compliance Management System (RCMS) in a key risk management role (second line of defense), to serve as a credible business advisor...Hourly payPermanent employmentFull timeInternshipWork at office
$121k per year
...Do you think differently about risk? Are you excited by the idea of building credit risk management from the ground up, AI-native, rather than bolting AI onto an old playbook? Then Jobber might be the place for you. We're looking for a Manager, Credit Risk to join our Fintech...Long term contractFull timeInternshipWork at officeLocal areaRemote work- ...We partner with municipal governments, planning authorities, and property... ...experienced Senior Project Manager, Government Solutions to... ...stakeholder management, project governance, and cross-functional... ...timelines, milestones, budgets, risks, and delivery outcomes Develop...Remote jobFull timeContract workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Manager. Be the first to apply!
- governance manager Toronto, ON
- senior manager risk management Toronto, ON
- operational risk manager Toronto, ON
- group risk manager Toronto, ON
- directeur juridique Toronto, ON
- customs compliance manager Toronto, ON
- regulatory manager Toronto, ON
- regulatory affairs project manager Toronto, ON
- quality compliance manager Toronto, ON
- compliance manager Toronto, ON

