Senior Director of Information Risk & Governance

19 hours, 41 minutes ago
Full-time
Lead
Cybersecurity
Modern Health

Modern Health

Modern Health provides a personalized mental health care platform tailored for enterprises, aiming to enhance employee resilience, productivity, and overall well-being through evidence-based services.

Health Care Providers & Services
251-1K
Founded 2017
$167M raised

Description

  • Own the information-security risk register, risk appetite and tolerance model, and risk-acceptance process.
  • Deliver executive and board reporting on information risk, AI risk, and governance status.
  • Lead cross-functional governance programs for risk decisions, incidents, vendors, questionnaires, and contractual security commitments.
  • Run the AI governance program, including intake, approved/restricted use administration, vendor eligibility, and product AI review gates.
  • Own enterprise incident management governance, including severity thresholds, playbooks, escalations, tabletop exercises, and corrective action tracking.
  • Drive security-side data governance, including retention, deletion, classification, residency, and data segregation priorities.
  • Provide second-line governance support for certification and assurance programs such as HITRUST, SOC 2, ISO 27001 readiness, and HIPAA risk assessments.
  • Own the overall third-party risk program and vendor assessment framework.
  • Review higher-risk customer security responses, trust-center materials, audit-right requests, and assurance commitments.
  • Own the information security and risk policy suite and annual review cycle.

Requirements

  • 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership.
  • 5+ years of experience in a regulated, PHI-handling environment.
  • Digital health, health plan, or healthcare services experience strongly preferred.
  • Experience with SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or similar assurance frameworks.
  • Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations.
  • Familiarity with NIST AI RMF and emerging AI governance expectations preferred.
  • Strong risk judgment with the ability to calibrate remediation plans and recommend accept, mitigate, escalate, or defer decisions.
  • Experience partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams.
  • Customer-facing credibility with CISOs, security review teams, procurement risk teams, auditors, and assessors.
  • Experience with third-party security risk programs, including vendor risk tiering, assessment standards, and exception paths.
  • Experience with incident management governance, including severity thresholds, escalation paths, playbook design, and tabletop facilitation.
  • Executive communication skills for translating technical risk into decision-ready business terms.
  • Ability to integrate distributed processes into coherent, repeatable governance programs.
  • Relevant certifications preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.
  • Must be able to maintain work authorization without employer sponsorship.

Benefits

  • Medical, dental, vision, disability, and life insurance.
  • High Deductible Health Plan with HSA option and FSA.
  • Access to coaches and therapists through Modern Health's platform.
  • Generous time off and company-wide Collective Pause Days.
  • Parental leave and family-forming support through Carrot.
  • Professional development stipend.
  • 401(k) and financial planning support through Origin.
  • Annual wellness stipend, work-from-home setup stipend, monthly cell phone reimbursement, and virtual community events.
  • Full-time employees are eligible for Modern Health's equity program.
  • Base salary range of $231,300-$272,100 in Zones 1-2, $208,170-$244,890 in Zone 3, and $196,605-$231,285 in Zone 4.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Compliance Lead

Aegis Ventures 51-250 Professional Services

Avandra Imaging, backed by Aegis Ventures, is hiring a Compliance Lead to build and run a scalable healthcare compliance program for a growing medical imaging data platform.

HIPAA
19 hours, 26 minutes ago

AML Compliance Analyst

Alpaca 51-250 Capital Markets

Alpaca is hiring a Financial Crimes Analyst to support its securities and crypto compliance operations by investigating suspicious activity and helping maintain AML, sanctions, fraud, and surveillance controls.

19 hours, 26 minutes ago

Head of Compliance

Gauntlet 51-200 Software Development

Gauntlet is hiring its first dedicated Head of Compliance to build and run a scalable compliance program for its onchain financial business as it expands into capital markets registrations.

19 hours, 56 minutes ago

Compliance & Sustainability Intelligence Manager (EPR)

rePurpose Global 51-250 Professional Services

rePurpose Global is hiring a remote Compliance & Sustainability Intelligence Manager to lead U.S. packaging EPR market education, customer guidance, and regulatory intelligence for consumer brands navigating evolving compliance obligations.

19 hours, 56 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers