Senior Director of Information Risk & Governance

3 weeks, 1 day ago
Full-time
Lead
Cybersecurity
Modern Health

Modern Health

Modern Health provides a personalized mental health care platform tailored for enterprises, aiming to enhance employee resilience, productivity, and overall well-being through evidence-based services.

Health Care Providers & Services
251-1K
Founded 2017
$167M raised

Description

  • Own the information-security risk register, risk appetite and tolerance model, and risk-acceptance process.
  • Deliver executive and board reporting on information risk, AI risk, and governance status.
  • Lead cross-functional governance programs for risk decisions, incidents, vendors, questionnaires, and contractual security commitments.
  • Run the AI governance program, including intake, approved/restricted use administration, vendor eligibility, and product AI review gates.
  • Own enterprise incident management governance, including severity thresholds, playbooks, escalations, tabletop exercises, and corrective action tracking.
  • Drive security-side data governance, including retention, deletion, classification, residency, and data segregation priorities.
  • Provide second-line governance support for certification and assurance programs such as HITRUST, SOC 2, ISO 27001 readiness, and HIPAA risk assessments.
  • Own the overall third-party risk program and vendor assessment framework.
  • Review higher-risk customer security responses, trust-center materials, audit-right requests, and assurance commitments.
  • Own the information security and risk policy suite and annual review cycle.

Requirements

  • 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership.
  • 5+ years of experience in a regulated, PHI-handling environment.
  • Digital health, health plan, or healthcare services experience strongly preferred.
  • Experience with SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or similar assurance frameworks.
  • Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations.
  • Familiarity with NIST AI RMF and emerging AI governance expectations preferred.
  • Strong risk judgment with the ability to calibrate remediation plans and recommend accept, mitigate, escalate, or defer decisions.
  • Experience partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams.
  • Customer-facing credibility with CISOs, security review teams, procurement risk teams, auditors, and assessors.
  • Experience with third-party security risk programs, including vendor risk tiering, assessment standards, and exception paths.
  • Experience with incident management governance, including severity thresholds, escalation paths, playbook design, and tabletop facilitation.
  • Executive communication skills for translating technical risk into decision-ready business terms.
  • Ability to integrate distributed processes into coherent, repeatable governance programs.
  • Relevant certifications preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.
  • Must be able to maintain work authorization without employer sponsorship.

Benefits

  • Medical, dental, vision, disability, and life insurance.
  • High Deductible Health Plan with HSA option and FSA.
  • Access to coaches and therapists through Modern Health's platform.
  • Generous time off and company-wide Collective Pause Days.
  • Parental leave and family-forming support through Carrot.
  • Professional development stipend.
  • 401(k) and financial planning support through Origin.
  • Annual wellness stipend, work-from-home setup stipend, monthly cell phone reimbursement, and virtual community events.
  • Full-time employees are eligible for Modern Health's equity program.
  • Base salary range of $231,300-$272,100 in Zones 1-2, $208,170-$244,890 in Zone 3, and $196,605-$231,285 in Zone 4.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Compliance Specialist

Binance 5K-10K Capital Markets

Binance is seeking an AML and financial crime compliance professional to investigate suspicious activity, manage regulatory reporting, and support UAE regulatory engagements across its global digital-asset ecosystem.

Blockchain
1 day, 9 hours ago

Product Security and Regulatory Expert

Vailexa Technology 11-50 Internet Software & Services

Vailexa is seeking a product security and IT compliance professional to translate global regulations into technical controls, manage compliance programs, and strengthen regulatory posture across its technology environments.

AWS Azure Encryption
2 days, 9 hours ago

Manager, SAR Filing — BSA/AML & Sanctions Operations

Pathward 251-1K Diversified Financial Services

Pathward is seeking a Manager, SAR Filing to oversee its SAR and CTR filing operations within the BSA/AML and Sanctions Operations team, ensuring accurate, timely, and defensible regulatory filings.

3 days, 7 hours ago

Vice President, BSA/AML Operations – Cases

Pathward 251-1K Diversified Financial Services

Pathward seeks a Vice President, BSA/AML Operations – Cases to lead its Suspicious Activity Monitoring case investigation function and strengthen a compliant, risk-based financial crime program within a regulated financial institution.

3 days, 7 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers