Назад
Company hidden
1 день назад

Senior Director of Information Risk & Governance (Healthcare)

231 300 - 272 100$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Director of Information Risk & Governance (Healthcare): Building and governing enterprise information-risk, AI-governance, incident-management, data-governance, third-party-risk, and assurance programs for regulated healthcare clients with an accent on second-line oversight, risk decision support, and customer assurance. Focus on integrating distributed security assets into evidenced programs, calibrating remediation and risk acceptance, and communicating complex security risks to executives, boards, auditors, and strategic customers.

Location: Remote - US; US-based team members outside the Pacific time zone must work at least six hours between 8 am and 5 pm Pacific time each workday.

Annual base pay: $231,300–$272,100 USD in Zones 1–2; $208,170–$244,890 USD in Zone 3; $196,605–$231,285 USD in Zone 4. Full-time employees are also eligible for equity and benefits.

Company

hirify.global is a mental health benefits platform providing employers and their employees with one-on-one, group, and self-serve digital mental health resources.

What you will do

  • Own information-security risk governance, including the risk register, risk appetite and tolerance model, exception register, decision rights, executive reporting, and enterprise Risk Committee workstreams.
  • Balance security risk with business priorities across enterprise deals, product launches, and AI initiatives, providing recommendations on remediation, acceptance, escalation, and deferral.
  • Run the cross-functional AI governance program, including intake, approved and restricted-use administration, AI vendor eligibility, coding-agent governance, product review gates, incident management, and customer-facing evidence.
  • Lead enterprise incident-management governance, including severity thresholds, playbooks, escalation paths, tabletop exercises, leadership notifications, and corrective-action tracking.
  • Drive security-side data governance covering retention, deletion, classification, hosting, residency, data segregation, and the data governance decision forum.
  • Provide second-line oversight for HITRUST, SOC 2, ISO 27001, HIPAA risk assessments, third-party risk, customer assurance, security questionnaires, policies, and risk-awareness content.

Requirements

  • 10+ years of experience in information-security risk management, security governance, assurance, GRC, or security program leadership, including 5+ years in a regulated, PHI-handling environment.
  • Experience providing senior governance or program leadership for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable assurance frameworks.
  • Deep knowledge of the HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations.
  • Experience with vendor risk tiering, incident-management governance, escalation paths, tabletop exercises, corrective-action tracking, and customer security reviews.
  • Strong executive communication and risk-decision judgment, with the ability to translate technical risk into business recommendations for executives, boards, auditors, assessors, and strategic customers.
  • Applicants must maintain US work authorization for the duration of employment; immigration sponsorship, employer-provided training plans, and attestations are not available.

Nice to have

  • Digital health, health plan, or healthcare services experience.
  • Familiarity with NIST AI RMF and emerging AI governance expectations.
  • CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar certification.

Culture & Benefits

  • Fully remote work environment with overlapping working hours to support team connection.
  • Medical, dental, vision, disability, life insurance, HSA and FSA options.
  • Generous time off, company-wide collective pause days, parental leave, and family support benefits.
  • Professional development stipend, annual wellness stipend, work-from-home setup stipend, and monthly cell phone reimbursement.
  • 401(k), financial planning support, access to coaches and therapists, and virtual community events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →