An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Fullscript in Calgary seeks an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature its security compliance program. This hands-on leader directly manages a two-person GRC team and drives governance, risk, and compliance across SOC 2 Type II, PCI DSS, and HITRUST in a fast-growing SaaS environment.
You’ll work with Security, IT, Privacy, Legal, Product, and Engineering to translate regulatory requirements into practical controls, manage audits, and report on compliance
We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.
That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.
We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.
Bring your ideas, your grit, and your care for people.
Join us and shape the future of care.
We're looking for an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature Fullscript's security compliance program. This is a hands‑on leadership role responsible for driving our governance, risk, and compliance strategy while directly managing a team of two GRC professionals.
You’ll own our security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring we remain continuously audit‑ready while scaling our controls alongside the business. You’ll lead internal and external audits, partner closely with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and help translate regulatory and customer requirements into practical, scalable security practices.
This role is ideal for someone who enjoys balancing strategic program ownership with day‑to‑day execution and who thrives in highly collaborative, fast‑growing SaaS environments.
Trust is one of Fullscript's most important products. As our GRC Manager, you'll help ensure that our security and compliance programs scale alongside the business, enabling innovation while maintaining the confidence of our customers, partners, and regulators. You'll have the opportunity to shape the future of our compliance program, mentor a growing team, and influence security strategy across the organization.
Our Wherever You Work Well philosophy means Fullscript teammates get to pick their own office — whether that’s in‑office, at home, or a bit of both
Compensation range
The salary range for this role is between $140,000 and $165,000 CAD. Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only. Additional incentives, perks, and benefits may be available as part of Fullscript’s total rewards package.
Final base salary depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.
Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at accommodations@fullscript.com.
All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.
We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.