About The Position

Fullscript is seeking an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature its security compliance program. This is a hands-on leadership role responsible for driving the company's governance, risk, and compliance strategy while directly managing a team of two GRC professionals. The role involves owning the security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring continuous audit readiness and scaling controls alongside business growth. The GRC Manager will lead internal and external audits, collaborate with various departments such as Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and translate regulatory and customer requirements into practical, scalable security practices. This position is suited for individuals who enjoy balancing strategic program ownership with day-to-day execution in a fast-growing SaaS environment.

Requirements

  • 7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance.
  • Previous people management experience leading small, high-performing teams.
  • Hands-on experience owning enterprise compliance programs within SaaS or healthcare technology organizations.
  • Demonstrated success leading external audits for: SOC 2 Type II, PCI DSS, HITRUST.
  • Familiarity with HIPAA and its requirements.
  • Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders.
  • Strong understanding of security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST.
  • Experience partnering closely with Privacy and Legal teams on regulatory compliance initiatives.
  • Experience managing control evidence, remediation programs, and continuous compliance activities.
  • Strong project management and organizational skills with the ability to manage competing priorities.
  • Excellent written and verbal communication skills, with the ability to translate complex compliance requirements into practical business guidance.

Nice To Haves

  • Healthcare or health technology experience.
  • Experience with GRC platforms such as Vanta, Drata, OneTrust, or similar.
  • Professional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor.
  • Experience supporting customer security reviews and enterprise sales due diligence.

Responsibilities

  • Own and evolve Fullscript's Governance, Risk & Compliance program.
  • Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST.
  • Develop and maintain policies, standards, procedures, and control documentation.
  • Ensure compliance activities are embedded into operational processes.
  • Track regulatory, contractual, and customer compliance obligations and ensure appropriate control coverage.
  • Lead all external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and successful certification.
  • Manage internal control assessments and readiness activities.
  • Coordinate remediation efforts across Engineering, IT, Security, and business teams.
  • Own relationships with external auditors and assessment firms.
  • Develop reporting and dashboards that communicate compliance posture and audit readiness to leadership.
  • Partner with Security leadership to mature enterprise security risk management.
  • Maintain risk registers and facilitate risk assessments across technology and business functions.
  • Drive remediation planning and track progress through completion.
  • Support third-party risk management activities.
  • Build strong partnerships with Privacy and Legal to ensure alignment between security, regulatory, and privacy obligations.
  • Partner with Product, Engineering, Infrastructure, and IT to operationalize security controls.
  • Support customer security reviews, due diligence requests, and compliance questionnaires.
  • Provide practical guidance that enables business growth while maintaining an appropriate risk posture.
  • Lead, coach, and develop a team of two GRC professionals.
  • Establish team priorities, operating cadence, and professional development plans.
  • Foster a culture of accountability, continuous improvement, and operational excellence.
  • Remain actively involved in execution, serving as a working manager who contributes directly to audits, control implementation, and compliance initiatives.

Benefits

  • Generous PTO and competitive pay
  • Fullscript’s RRSP match program for financial health
  • Flexible benefits package and workplace wellness program
  • Training budget and company-wide learning initiatives
  • Discount on Fullscript catalog of products
  • Ability to work Wherever You Work Well (in-office, at home, or a hybrid)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service