1

Governance Risk And Compliance Jobs in Calgary, AB

Governance, Risk & Compliance (GRC) experience. * Cyber security advisory or consulting experience. * Change Management and communications expertise. * Energy industry experience. * PMP or related ...

You Bring * 3-6 years in IT governance, risk, compliance, service management, or IT security in an operational role * Hands-on experience building or substantially rebuilding a CMDB or asset ...

Advisor, Ethics & Compliance

Calgary, AB · On-site

CA$82K - CA$105K/yr

We are looking for an Advisor, Ethics & Compliance to support the execution and continuous ... governance, risk management, or related functions, preferably within the pipeline, energy, or ...

Governance, Risk & Compliance * Ensure all real estate activity meets TC Energy's internal governance standards, ethics, and compliance requirements. * Maintain strong documentation and audit ...

Job Summary We are looking for a Senior Analyst - IT Security with a strong focus on Governance, Risk, and Compliance (GRC) to support our efforts in maintaining ISO 27001 certification and other ...

... governance structures * Previous experience interacting and/or collaborating with the AESO, MSA, AUC, and/or NERC, including familiarity with the AESO's Alberta Risk-Based Compliance Monitoring ...

GOVERNANCE, RISK MANAGEMENT & COMPLIANCE (Weightage 30%) Policy, Process & Commercial Governance * Ensure category strategies and sourcing activities align with Startec's procurement policies ...

next page

Showing results 1-20

Governance Risk And Compliance information

What are governance risk and compliance roles?

Governance, Risk, and Compliance (GRC) roles are positions within organizations focused on ensuring that business operations align with legal standards, manage risk effectively, and follow internal policies. Professionals in GRC help organizations set up frameworks to oversee compliance with laws and regulations, identify and mitigate potential risks, and establish governance structures to guide decision-making. These roles are essential for protecting organizations from financial, legal, and reputational harm while promoting ethical practices and efficient processes.

What are the key skills and qualifications needed to thrive as a governance risk and compliance professional?

To thrive as a Governance, Risk, and Compliance (GRC) professional, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in business, finance, or a related field. Familiarity with GRC platforms (like RSA Archer or MetricStream), audit management tools, and relevant certifications such as CISA, CRISC, or CISSP is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These skills are crucial for identifying risks, ensuring organizational compliance, and supporting informed decision-making to protect the business.

What are some common challenges faced by professionals in governance risk and compliance roles, and how can they be addressed?

Professionals in Governance, Risk, and Compliance (GRC) roles often face challenges such as staying updated with changing regulations, ensuring company-wide adherence to policies, and managing cross-functional collaboration. To address these, GRC specialists must develop strong communication skills to educate and train staff, leverage technology to automate compliance tracking, and build effective relationships with departments such as IT, legal, and operations. Regular professional development and proactive engagement with regulatory updates are also key to overcoming these challenges and maintaining effective governance.

What is the difference between Governance Risk And Compliance vs Compliance Analyst?

AspectGovernance Risk And ComplianceCompliance Analyst
CertificationsISO 31000, ISO 27001, Certified Risk Management ProfessionalCertified Compliance & Ethics Professional (CCEP), ISO 19600
Work EnvironmentCorporate, regulated industries, risk management departmentsLegal, audit, compliance departments within organizations
Employer & Industry UsageFinancial services, healthcare, energy, governmentFinancial institutions, healthcare, manufacturing, retail

Governance Risk And Compliance professionals focus on establishing frameworks, managing risks, and ensuring overall compliance strategies across organizations. Compliance Analysts primarily focus on implementing and monitoring specific compliance policies, often within legal or audit teams. While both roles require understanding regulations and certifications, Governance Risk And Compliance roles have a broader scope involving risk management and governance structures.

Is governance risk and compliance a good career?

Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in industries such as finance, healthcare, and technology. It involves developing policies, managing risks, and ensuring regulatory adherence, often requiring certifications like CISA or CRISC. The role typically offers stable employment, competitive salaries, and the chance to work in a dynamic regulatory environment.

What is the work of governance risk and compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks effectively, and maintain ethical standards. They often use tools like risk assessments, audits, and compliance frameworks to identify vulnerabilities and ensure organizational integrity. This role requires strong analytical skills and knowledge of industry regulations.

What job categories do people searching Governance Risk And Compliance jobs in Calgary, AB look for?

The top searched job categories for Governance Risk And Compliance jobs in Calgary, AB are:

What cities near Calgary, AB are hiring for Governance Risk And Compliance jobs?

Cities near Calgary, AB with the most Governance Risk And Compliance job openings:

Infographic showing various Governance Risk And Compliance job openings in Calgary, AB as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

Governance, Risk & Compliance (GRC) Manager

Fullscript

Calgary, AB

Full-time

Medical, PTO

Posted 4 days ago


Job description

About Fullscript
 
We're an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.
 
That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.
 
We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.
 
This is your invitation.
 
Bring your ideas, your grit, and your care for people.
Join us and shape the future of care.

The Opportunity

We're looking for an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature Fullscript's security compliance program. This is a hands-on leadership role responsible for driving our governance, risk, and compliance strategy while directly managing a team of two GRC professionals.

You'll own our security compliance program across multiple frameworks, including SOC 2 Type II, PCI DSS, and HITRUST, ensuring we remain continuously audit-ready while scaling our controls alongside the business. You'll lead internal and external audits, partner closely with Security, Engineering, Infrastructure, Privacy, Legal, Product, and IT, and help translate regulatory and customer requirements into practical, scalable security practices.

This role is ideal for someone who enjoys balancing strategic program ownership with day-to-day execution and who thrives in highly collaborative, fast-growing SaaS environments.

What You'll Do Governance & Compliance
  • Own and evolve Fullscript's Governance, Risk & Compliance program.

  • Maintain and continuously improve compliance across SOC 2 Type II, PCI DSS, and HITRUST.

  • Develop and maintain policies, standards, procedures, and control documentation.

  • Ensure compliance activities are embedded into operational processes rather than point-in-time exercises.

  • Track regulatory, contractual, and customer compliance obligations and ensure appropriate control coverage.

Audit & Assurance
  • Lead all external compliance audits, including planning, evidence collection, auditor coordination, issue resolution, and successful certification.

  • Manage internal control assessments and readiness activities throughout the year.

  • Coordinate remediation efforts across Engineering, IT, Security, and business teams.

  • Own relationships with external auditors and assessment firms.

  • Develop reporting and dashboards that communicate compliance posture and audit readiness to leadership.

Risk Management
  • Partner with Security leadership to mature enterprise security risk management.

  • Maintain risk registers and facilitate risk assessments across technology and business functions.

  • Drive remediation planning and track progress through completion.

  • Support third-party risk management activities as required.

Cross-Functional Partnership
  • Build strong partnerships with Privacy and Legal to ensure alignment between security, regulatory, and privacy obligations.

  • Partner with Product, Engineering, Infrastructure, and IT to operationalize security controls.

  • Support customer security reviews, due diligence requests, and compliance questionnaires.

  • Provide practical guidance that enables business growth while maintaining an appropriate risk posture.

Leadership
  • Lead, coach, and develop a team of two GRC professionals.

  • Establish team priorities, operating cadence, and professional development plans.

  • Foster a culture of accountability, continuous improvement, and operational excellence.

  • Remain actively involved in execution, serving as a working manager who contributes directly to audits, control implementation, and compliance initiatives.

What You Bring
  • 7+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Security Compliance.

  • Previous people management experience leading small, high-performing teams.

  • Hands-on experience owning enterprise compliance programs within SaaS or healthcare technology organizations.

  • Demonstrated success leading external audits for:

  • SOC 2 Type II

  • PCI DSS

  • HITRUST 

  • Familiarity with HIPAA and its requirements.

  • Experience coordinating multiple concurrent compliance initiatives across engineering and business stakeholders.

  • Strong understanding of security frameworks including NIST CSF, CIS Controls, ISO 27001, and HITRUST.

  • Experience partnering closely with Privacy and Legal teams on regulatory compliance initiatives.

  • Experience managing control evidence, remediation programs, and continuous compliance activities.

  • Strong project management and organizational skills with the ability to manage competing priorities.

  • Excellent written and verbal communication skills, with the ability to translate complex compliance requirements into practical business guidance.

Nice to Have
  • Healthcare or health technology experience.

  • Experience with GRC platforms such as Vanta, Drata, OneTrust, or similar.

  • Professional certifications such as CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, or ISO 27001 Lead Auditor.

  • Experience supporting customer security reviews and enterprise sales due diligence.

Why This Role Matters

Trust is one of Fullscript's most important products. As our GRC Manager, you'll help ensure that our security and compliance programs scale alongside the business, enabling innovation while maintaining the confidence of our customers, partners, and regulators. You'll have the opportunity to shape the future of our compliance program, mentor a growing team, and influence security strategy across the organization.

What We Can Offer You
  • Generous PTO and competitive pay

  • Fullscript's RRSP match program for financial health

  • Flexible benefits package and workplace wellness program

  • Training budget and company-wide learning initiatives

  • Discount on Fullscript catalog of products

  • Ability to work Wherever You Work Well*

Our Wherever You Work Well philosophy means Fullscript teammates get to pick their own office - whether that's in-office, at home, or a bit of both

Compensation range
The salary range for this role is between $140,000 and $165,000 CAD. Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only. Additional incentives, perks, and benefits may be available as part of Fullscript's total rewards package.
Final base salary depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Why Fullscript
 
Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.
 
What to Know Before You Apply
 
We're grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.
A quick note: Due to the high volume of applications, we're not able to respond to phone or email inquiries about application status. If there's a match, our team will reach out directly.
 
Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected].
 
All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.
 
We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.
 
Learn More
 
www.fullscript.com
@fullscriptHQ on instagram
Let's make healthcare whole 
 
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job