This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Fullscript is currently looking for a GRC Analyst (Risk) to join our growing Security team and help establish and scale foundational risk management practices across the organization. The Security team is responsible for product security, governance, risk, compliance, as well as security operations and incident response. This role is critical to evolving Fullscript’s risk management approach from an ad hoc, reactive model to a structured, proactive, and measurable enterprise risk program. You will work closely with teams across Fullscript to identify, assess, and track security and operational risks, while providing leadership with clear visibility into the company’s risk posture.
Job Responsibility:
Identify, document, and assess security and operational risks across business units
Maintain a comprehensive and up-to-date enterprise risk register
Apply a consistent methodology for evaluating risk likelihood, impact, ownership, and treatment
Partner with risk owners to ensure risks are clearly articulated and appropriately managed
Ensure risk acceptance, mitigation, and transfer decisions are documented, traceable, and aligned with Fullscript’s risk appetite
Track remediation efforts and follow up with stakeholders to ensure timely risk reduction
Produce clear, data-driven risk reporting and dashboards to support leadership and executive decision-making
Support and manage Fullscript’s third-party risk management program
Conduct risk assessments for vendors and partners, including onboarding and periodic reviews
Collaborate with Procurement, Legal, Security, and Engineering to ensure third-party risks are identified and addressed
Partner with Security, Engineering, IT, Legal, Compliance, and business teams to surface emerging risks
Act as a trusted partner and advisor on risk-related questions across the organization
Help drive clarity around risk ownership and accountability
Help define, document, and refine risk management processes, standards, and procedures
Contribute to policies and controls that support effective risk governance
Support audit, compliance, and regulatory activities by providing risk context and evidence
Requirements:
Experience in governance, risk management, compliance, security operations, IT risk, or a related field
Understanding of security and operational risk concepts and common risk management frameworks
Ability to assess technical and non-technical risks and translate them into business impact
Strong analytical and problem-solving skills, with the ability to identify patterns and trends in risk data
Experience creating clear documentation, reports, and dashboards for technical and non-technical audiences
Strong verbal and written communication skills
Ability to work cross-functionally and influence without direct authority
Willingness to ask questions, seek feedback, and continuously improve processes
Comfortable operating in a growing, evolving environment where programs are being built and scaled
Strong situational awareness and judgment when evaluating risk trade-offs
Ability to support and influence risk decisions with data and context
Nice to have:
Experience with third-party risk management programs
Familiarity with frameworks such as NIST, ISO 27001, SOC 2, CIS, or HITRUST
Experience supporting audits or executive and board-level risk reporting
Background in security operations, compliance, or incident response
What we offer:
Generous PTO and competitive pay
Fullscript’s RRSP match program for financial health
Flexible benefits package and workplace wellness program
Training budget and company-wide learning initiatives