
201 - 500 employees
Founded 2016
🏥 Healthcare
📦 Logistics
🏭 Manufacturing
💰 $240M Private Equity Round on 2021-11
Healthcare • Logistics • Manufacturing
Fullscript is a comprehensive platform that facilitates whole person care for healthcare providers. It integrates industry-leading lab testing, high-quality supplements, and a suite of tools designed to enhance patient adherence and outcomes. Fullscript offers features like personalized patient plans, evidence-based templates, patient engagement tools, and seamless wholesale ordering of supplements. The platform also integrates with top EHR systems to streamline workflows for healthcare practitioners, making it easier for them to provide effective care. With Fullscript, patients can manage their health routines more conveniently, and providers can create personalized care plans with the support of clinical evidence and insights.
🔥 12 hours ago
Improve your chances of getting an interview by checking your resume score before you apply.

201 - 500 employees
Founded 2016
🏥 Healthcare
📦 Logistics
🏭 Manufacturing
💰 $240M Private Equity Round on 2021-11
Healthcare • Logistics • Manufacturing
Fullscript is a comprehensive platform that facilitates whole person care for healthcare providers. It integrates industry-leading lab testing, high-quality supplements, and a suite of tools designed to enhance patient adherence and outcomes. Fullscript offers features like personalized patient plans, evidence-based templates, patient engagement tools, and seamless wholesale ordering of supplements. The platform also integrates with top EHR systems to streamline workflows for healthcare practitioners, making it easier for them to provide effective care. With Fullscript, patients can manage their health routines more conveniently, and providers can create personalized care plans with the support of clinical evidence and insights.
• Own and evolve Fullscript's Governance, Risk & Compliance program • Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST • Develop and maintain policies, standards, procedures, and control documentation • Embed compliance activities into operational processes • Track regulatory, contractual, and customer compliance obligations and ensure appropriate control coverage • Lead external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and certification • Manage internal control assessments and readiness activities • Coordinate remediation efforts across Engineering, IT, Security, and business teams • Own relationships with external auditors and assessment firms • Develop reporting and dashboards communicating compliance posture and audit readiness to leadership • Partner with Security leadership to mature enterprise security risk management • Maintain risk registers and facilitate risk assessments • Drive remediation planning and track progress through completion • Support third-party risk management activities • Partner with Privacy, Legal, Product, Engineering, Infrastructure, and IT to align obligations and operationalize security controls • Support customer security reviews, due diligence requests, and compliance questionnaires • Lead, coach, and develop a team of two GRC professionals • Establish team priorities, operating cadence, and professional development plans • Remain actively involved in audits, control implementation, and compliance initiatives
• 7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance • Previous people management experience leading small, high-performing teams • Hands-on experience owning enterprise compliance programs within SaaS or healthcare technology organizations • Demonstrated success leading external audits for SOC 2 Type II, PCI DSS, and HITRUST • Familiarity with HIPAA and its requirements • Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders • Strong understanding of NIST CSF, CIS Controls, ISO 27001, and HITRUST • Experience partnering closely with Privacy and Legal teams on regulatory compliance initiatives • Experience managing control evidence, remediation programs, and continuous compliance activities • Strong project management and organizational skills with the ability to manage competing priorities • Excellent written and verbal communication skills, with the ability to translate complex compliance requirements into practical business guidance • Healthcare or health technology experience, GRC platforms such as Vanta, Drata, OneTrust, or similar, professional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor, and experience supporting customer security reviews and enterprise sales due diligence are nice to have
• Generous PTO and competitive pay • Fullscript’s RRSP match program for financial health • Flexible benefits package and workplace wellness program • Training budget and company-wide learning initiatives • Discount on Fullscript catalog of products • Ability to work Wherever You Work Well — in-office, at home, or a bit of both
Apply Now🕒 Yesterday
Senior Compliance Analyst maintaining Canadian securities and crypto compliance programs at Crypto.com. Translating CSA and CIRO requirements into policies, controls, training, and operational practices.
🕒 Yesterday
GRC/Compliance Lead guiding SOC 2, ISO, and customer assurance for enterprise AI platforms. Building practical compliance into regulated, mission-critical software delivery.
🕒 2 days ago
Senior GRC sales executive expanding Workiva’s AI-powered platform for finance, risk, and sustainability. Driving enterprise customer acquisition and complex solution sales across Western Canada.
🕒 5 days ago
Senior GRC solution sales executive driving enterprise growth for Workiva’s AI-powered finance, risk, and sustainability platform. Building executive relationships and closing complex Central Canada sales.
🕒 August 21
Regulatory submissions manager helping Parexel advance global therapies through compliant health-authority filings. Planning, coordinating, and quality-checking complex IND, DMF, and global submissions.