Senior Director of Information Risk & Governance

1 month, 1 week ago
Full-time
Lead
Cybersecurity
Modern Health

Modern Health

Modern Health provides a personalized mental health care platform tailored for enterprises, aiming to enhance employee resilience, productivity, and overall well-being through evidence-based services.

Health Care Providers & Services
251-1K
Founded 2017
$167M raised

Description

  • Own the information-security risk register, risk appetite and tolerance model, and risk-acceptance process.
  • Deliver executive and board reporting on information risk, AI risk, and governance status.
  • Lead cross-functional governance programs for risk decisions, incidents, vendors, questionnaires, and contractual security commitments.
  • Run the AI governance program, including intake, approved/restricted use administration, vendor eligibility, and product AI review gates.
  • Own enterprise incident management governance, including severity thresholds, playbooks, escalations, tabletop exercises, and corrective action tracking.
  • Drive security-side data governance, including retention, deletion, classification, residency, and data segregation priorities.
  • Provide second-line governance support for certification and assurance programs such as HITRUST, SOC 2, ISO 27001 readiness, and HIPAA risk assessments.
  • Own the overall third-party risk program and vendor assessment framework.
  • Review higher-risk customer security responses, trust-center materials, audit-right requests, and assurance commitments.
  • Own the information security and risk policy suite and annual review cycle.

Requirements

  • 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership.
  • 5+ years of experience in a regulated, PHI-handling environment.
  • Digital health, health plan, or healthcare services experience strongly preferred.
  • Experience with SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or similar assurance frameworks.
  • Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations.
  • Familiarity with NIST AI RMF and emerging AI governance expectations preferred.
  • Strong risk judgment with the ability to calibrate remediation plans and recommend accept, mitigate, escalate, or defer decisions.
  • Experience partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams.
  • Customer-facing credibility with CISOs, security review teams, procurement risk teams, auditors, and assessors.
  • Experience with third-party security risk programs, including vendor risk tiering, assessment standards, and exception paths.
  • Experience with incident management governance, including severity thresholds, escalation paths, playbook design, and tabletop facilitation.
  • Executive communication skills for translating technical risk into decision-ready business terms.
  • Ability to integrate distributed processes into coherent, repeatable governance programs.
  • Relevant certifications preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.
  • Must be able to maintain work authorization without employer sponsorship.

Benefits

  • Medical, dental, vision, disability, and life insurance.
  • High Deductible Health Plan with HSA option and FSA.
  • Access to coaches and therapists through Modern Health's platform.
  • Generous time off and company-wide Collective Pause Days.
  • Parental leave and family-forming support through Carrot.
  • Professional development stipend.
  • 401(k) and financial planning support through Origin.
  • Annual wellness stipend, work-from-home setup stipend, monthly cell phone reimbursement, and virtual community events.
  • Full-time employees are eligible for Modern Health's equity program.
  • Base salary range of $231,300-$272,100 in Zones 1-2, $208,170-$244,890 in Zone 3, and $196,605-$231,285 in Zone 4.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Licensing Project Specialist

JustMarkets 1-10 Capital Markets

JustMarkets is seeking a Licensing Specialist to manage legal and regulatory licensing operations across multiple jurisdictions supporting its global fintech, crypto, FX, and payments business.

1 hour, 44 minutes ago

Security & Compliance Manager

FamilyWell 11-50 Health Care Providers & Services

FamilyWell Health is hiring a Security & Compliance Manager to run the day-to-day security and compliance operations for its HIPAA-regulated, AI-enabled virtual mental healthcare platform as the company expands nationally.

Encryption Penetration Testing
1 day, 1 hour ago

Manager, Compliance & Risk

TrueML 51-250 Internet Software & Services

TrueML is seeking a Manager, Compliance & Risk to lead operational compliance, audit, due diligence, payments, and risk-management activities for its AI-driven financial software platforms.

Confluence JIRA Looker
1 day, 2 hours ago

Sanctions Advisory Specialist

Binance 5K-10K Capital Markets

Binance is hiring a mid-level Financial Crime Compliance professional for its global Sanctions Advisory team to provide expert guidance, assess sanctions risks, and strengthen compliance controls across the blockchain ecosystem.

Agile Blockchain
1 day, 2 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers