CareerPlanSign in

Governance, Risk & Compliance (GRC) Manager

Ottawa, ON🌐 Remote💼 Full-time🗓 2026-09-02 → 2026-09-26

Core

Lead and mature the security compliance program for a health technology platform serving practitioners and patients, ensuring audit readiness and operationalizing controls across the business.

Role type

Senior GRC Manager (hands-on leadership)

Builds

Enterprise security compliance program, audit readiness, and scalable control frameworks

Domain

Health technology / SaaS / Regulatory Compliance

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Governance, Risk & Compliance program ownership, SOC 2 Type II, PCI DSS, HITRUST, GDPR, HIPAA, NIST CSF, CIS Controls, ISO 27001, risk register management, third-party risk management, audit leadership, team management, policy development, cross-functional partnership

Preferred skills

Healthcare or health technology experience, GRC platform experience (Vanta, Drata, OneTrust), professional certifications (CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, ISO 27001 Lead Auditor), customer security review support

Technologies

SOC 2 Type II, PCI DSS, HITRUST, GDPR, HIPAA, NIST CSF, CIS Controls, ISO 27001, Vanta, Drata, OneTrust

Responsibilities

Own and evolve the GRC program; maintain compliance across SOC 2, PCI DSS, HITRUST, GDPR, and HIPAA; lead external audits and coordinate remediation; manage risk registers and third-party risk; partner with Privacy, Legal, Security, and Engineering; lead and develop a team of two GRC professionals; develop reporting dashboards for compliance posture.

Seniority

Senior, hands-on IC with people management

Sourced via lever · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.