or apply directly on Fullscript's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 14 days Fullscript's roles stay open a median of 30 days
- Reposted
- No
- Salary listed
- No 9% of Fullscript's roles list one
- Ghost-job risk at Fullscript
- low 0 stale, 0 reposted of 23 open
- Hiring momentum
- 39 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from Fullscript's own lever board since 2026-08-04. Full hiring picture for Fullscript.
About this role
The Governance, Risk & Compliance (GRC) Manager at Fullscript will lead the security compliance program, managing a team of two GRC professionals. This role involves overseeing compliance across frameworks like SOC 2 Type II, PCI DSS, and HITRUST, leading audits, and collaborating with various departments to implement security practices. The ideal candidate will balance strategic oversight with hands-on execution in a fast-paced SaaS environment.
- benefits
- 3/5
- freshness
- 4/5
- career value
- 4/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of Fullscript as an employer.
What you need
- 7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance
- Previous people management experience leading small, high-performing teams
- Hands-on experience owning enterprise compliance programs within SaaS or healthcare technology organizations
- Demonstrated success leading external audits for SOC 2 Type II, PCI DSS, HITRUST, and GDPR
- Familiarity with HIPAA and its requirements
- Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders
Nice to have
- Healthcare or health technology experience
- Experience with GRC platforms such as Vanta, Drata, OneTrust, or similar
- Professional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor
- Experience supporting customer security reviews and enterprise sales due diligence
What you get
- Generous PTO and competitive pay
- Fullscript's RRSP match program for financial health
- Flexible benefits package and workplace wellness program
- Training budget and company-wide learning initiatives
- Discount on Fullscript catalog of products
- Ability to work Wherever You Work Well
Worth weighing
- No specific mention of remote work policies beyond flexibility
- The role requires balancing strategic and hands-on tasks, which may lead to a demanding workload
- The salary range is provided, but final compensation depends on experience, skills, and location
- The company uses AI tools in the hiring process, which may affect candidate experience
Summarised from Fullscript's posting. Read the full original.
Listed by Fullscript on their lever job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.
More roles at Fullscript
- Senior Developer, Fullstack - Warehouse Management Systems (WMS)Ottawa, ON
- Financial Planning & Analysis ManagerOttawa, ON
- Sr Lead, BenefitsOttawa, ON
- Accounts Payable ManagerOttawa, ON
- Engineering Manager, EcommerceOttawa, ON
- Warehouse Associate (Ashland, VA)Ashland, VA
- Warehouse Associate (Phoenix, AZ)Phoenix, AZ
- Engineering Manager, Patient ExperienceOttawa, ON