Governance, Risk, and Compliance; GRC Lead
Listed on 2026-01-15
-
IT/Tech
Cybersecurity, Data Security
Who we are
At WELLSTAR, we are committed to reshaping Canadian healthcare by leveraging technology to address the administrative burdens that pull physicians away from their true calling—patient care. Our mission is focused on supporting providers and patients, shifting the emphasis back to quality, time, and positive outcomes. With a comprehensive suite of technology solutions, we have successfully helped thousands of providers adopt and benefit from modern, interoperable technologies that improve patient outcomes and system efficiency.
Whether you are in research and development, administration, communications, operations leadership, or technology, joining us now is a chance to play a critical role in transforming the way healthcare is managed and experienced in Canada.
The opportunityWELLSTAR, a majority-owned subsidiary of WELL Health Technologies Corp, is a high-growth SaaS company with a focused objective of reshaping healthcare through digital enablement. Our innovative solutions are designed to streamline care delivery, integrate healthcare systems and improve patient outcomes.
We are seeking a highly motivated and proactive Governance, Risk, and Compliance (GRC) Lead to own and drive our Governance, Risk, and Compliance efforts. Reporting directly to the Business Information Security Officer, you will be the first dedicated member of the GRC team with the opportunity to define the function, shape the roadmap, and eventually grow and lead a team.
This role is ideal for someone who thrives on both execution and vision, rolling up their sleeves to maintain compliance frameworks while also building scalable processes that will support our rapid growth. You will partner with leaders across nine companies (and growing) to embed ISO 27001 and SOC 2 Type 2 standards and will play a critical role in onboarding new acquisitions into WELLSTAR’s compliance program.
This job posting is for existing vacancy that is a remote-friendly role, limited to candidates based in Canada. This job posting is for existing vacancy.
What’s in it for youImpact and exposure. Unlike traditional roles, you will feature as a prominent part of the acquisition process, working with multiple new companies every year. You will partner with executives across multiple business units and subsidiaries, directly influencing the compliance posture of our expanding portfolio.
Growth and ownership. You will have the opportunity to help align the WELL Health Corporate GRC best practices with the WELLSTAR's business units GRC function, and prepare to lead a growing team as company matures.
Mission and purpose. You will be part of a purpose-driven company transforming healthcare delivery through technology while ensuring security and compliance at every level.
Career development. As one of the founding members of the team, you will be positioned for leadership advancement within WELL’s Cybersecurity department, supported by an environment that values initiative and long-term growth.
What you will do:- Maintain. You will oversee WELLSTAR’s ISO 27001 ISMS and SOC 2 Type 2 control framework, ensuring readiness for audits, collecting evidence, and tracking remediation.
- Build. You will establish and continuously improve policies, processes, and GRC practices that can scale with our rapid growth.
- Enable. You will own the compliance onboarding process for newly acquired entities, designing and executing 12-month roadmaps and ensuring alignment with WELLSTAR standards.
- Assess. You will perform gap analyses, risk assessments, and maturity evaluations, and define remediation plans with business unit leaders.
- Manage. You will maintain the GRC risk register, coordinate internal control testing, and support third-party risk reviews with security and procurement teams for eight unique business units.
- Report. You will track and present GRC KPIs and compliance metrics to leadership, creating dashboards that measure and demonstrate program success.
- Educate. You will support awareness campaigns, facilitate employee training, and foster a culture of compliance across the organization.
- Adapt. You will monitor changes in regulatory requirements and industry trends,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).