Senior Director of Information Risk & Governance (Healthcare)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Remote - US; US-based team members outside the Pacific time zone must work at least six hours between 8 am and 5 pm Pacific time each workday.
Annual base pay: $231,300–$272,100 USD in Zones 1–2; $208,170–$244,890 USD in Zone 3; $196,605–$231,285 USD in Zone 4. Full-time employees are also eligible for equity and benefits.
Company
is a mental health benefits platform providing employers and their employees with one-on-one, group, and self-serve digital mental health resources.
What you will do
- Own information-security risk governance, including the risk register, risk appetite and tolerance model, exception register, decision rights, executive reporting, and enterprise Risk Committee workstreams.
- Balance security risk with business priorities across enterprise deals, product launches, and AI initiatives, providing recommendations on remediation, acceptance, escalation, and deferral.
- Run the cross-functional AI governance program, including intake, approved and restricted-use administration, AI vendor eligibility, coding-agent governance, product review gates, incident management, and customer-facing evidence.
- Lead enterprise incident-management governance, including severity thresholds, playbooks, escalation paths, tabletop exercises, leadership notifications, and corrective-action tracking.
- Drive security-side data governance covering retention, deletion, classification, hosting, residency, data segregation, and the data governance decision forum.
- Provide second-line oversight for HITRUST, SOC 2, ISO 27001, HIPAA risk assessments, third-party risk, customer assurance, security questionnaires, policies, and risk-awareness content.
Requirements
- 10+ years of experience in information-security risk management, security governance, assurance, GRC, or security program leadership, including 5+ years in a regulated, PHI-handling environment.
- Experience providing senior governance or program leadership for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable assurance frameworks.
- Deep knowledge of the HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations.
- Experience with vendor risk tiering, incident-management governance, escalation paths, tabletop exercises, corrective-action tracking, and customer security reviews.
- Strong executive communication and risk-decision judgment, with the ability to translate technical risk into business recommendations for executives, boards, auditors, assessors, and strategic customers.
- Applicants must maintain US work authorization for the duration of employment; immigration sponsorship, employer-provided training plans, and attestations are not available.
Nice to have
- Digital health, health plan, or healthcare services experience.
- Familiarity with NIST AI RMF and emerging AI governance expectations.
- CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar certification.
Culture & Benefits
- Fully remote work environment with overlapping working hours to support team connection.
- Medical, dental, vision, disability, life insurance, HSA and FSA options.
- Generous time off, company-wide collective pause days, parental leave, and family support benefits.
- Professional development stipend, annual wellness stipend, work-from-home setup stipend, and monthly cell phone reimbursement.
- 401(k), financial planning support, access to coaches and therapists, and virtual community events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →