Governance, Risk & Compliance (GRC) Manager
New
F
FullscriptHealth technology
Ottawa, ON / Toronto, ON / Calgary, ABFull-TimeManager
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years
- Required Skills
- HIPAARisk Management
Requirements
- 7+ years of experience in GRC, Information Security, IT Audit, or Security Compliance.
- Previous people management experience.
- Hands-on experience owning enterprise compliance programs in SaaS or healthcare technology.
- Demonstrated success leading external audits for SOC 2 Type II, PCI DSS, and HITRUST.
- Familiarity with HIPAA requirements.
- Strong understanding of security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST.
- Experience partnering with Privacy and Legal teams on regulatory initiatives.
- Strong project management and organizational skills.
- Excellent communication skills for translating complex requirements into business guidance.
Responsibilities
- Own and evolve the Governance, Risk & Compliance program.
- Maintain and improve compliance across SOC 2 Type II, PCI DSS, and HITRUST.
- Lead all external compliance audits and manage internal control assessments.
- Partner with Security leadership to mature enterprise security risk management and maintain risk registers.
- Collaborate with Privacy, Legal, Product, and Engineering to operationalize security controls.
- Lead, coach, and develop a team of two GRC professionals.
View Full Description & ApplyYou'll be redirected to the employer's site