Search Remote Jobs

Senior Director of Information Risk, Governance

Job not on LinkedIn

đŸ”„ 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Modern Health

Modern Health

201 - 500 employees

Founded 2017

đŸ’Œ Consulting

📣 Marketing

đŸ„ Healthcare

💰 $74M Series D on 2021-02

Consulting ‱ Marketing ‱ Healthcare

Modern Health is a comprehensive mental health care platform that provides a global standard for equitable services worldwide. They offer a wide range of mental health support for employees, family care, and healthcare providers through self-guided tools and crisis care, aiming to boost productivity and prevent burnout. Modern Health partners with employers, consultants, and health plans to integrate mental health benefits into the workplace, addressing long-term needs, reducing absenteeism, enhancing operational efficiency, and improving well-being. Their evidence-based solutions cater to a wide array of mental health concerns, promoting personalization and accessibility to culturally centered care globally.

📋 Description

‱ Own the information-security risk register, risk appetite and tolerance model, and exception/risk-acceptance register ‱ Establish cross-functional decision rights for risk acceptance, questionnaires, incidents, vendor exceptions, and contractual security commitments ‱ Deliver monthly executive information-risk reports and periodic board reporting ‱ Own the information-risk and AI-risk workstream of the enterprise Risk Committee ‱ Coordinate risk-balanced business prioritization, security reviews, resourcing, remediation, and risk decisions ‱ Run the cross-functional AI governance program, including intake, approved/restricted-use administration, AI vendor eligibility, coding-agent governance, product AI review gates, incident management, and customer-facing evidence ‱ Own enterprise incident-management governance, including severity thresholds, playbooks, tabletop exercises, escalation paths, notification standards, and corrective-action tracking ‱ Drive data retention/deletion, data classification, data hosting/residency, and data segregation programs ‱ Provide second-line governance and risk escalation support for HITRUST, SOC 2, ISO 27001 readiness, and third-party HIPAA risk assessments ‱ Own the vendor risk program and risk-tiered assessment framework ‱ Review and calibrate customer security questionnaires, RFP responses, trust-center materials, assurance packages, audit-right responses, and security commitments ‱ Own the information security and risk policy suite, annual review cycle, and risk awareness content

🎯 Requirements

‱ 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership ‱ 5+ years in a regulated, PHI-handling environment ‱ Digital health, health plan, or healthcare services experience strongly preferred ‱ Senior governance, oversight, or program leadership experience for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable frameworks ‱ Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations ‱ Strong risk-decision judgment and ability to calibrate remediation against customer commitments and business priorities ‱ Experience partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams ‱ Customer-facing experience with strategic customer CISOs, security review teams, procurement risk teams, auditors, and assessors ‱ Experience with third-party security risk programs, including vendor risk tiering, assessment standards, exception paths, remediation expectations, and customer-obligation alignment ‱ Experience with incident-management program governance, severity thresholds, escalation paths, playbooks, tabletop facilitation, and corrective-action tracking ‱ Executive communication skills for decision-ready reporting to executives and boards ‱ Ability to turn distributed processes into coherent, evidenced, repeatable programs ‱ Relevant certifications preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar ‱ Immigration sponsorship is not available; applicants must maintain work authorization without employer sponsorship or employer-provided training plans or attestations

đŸ–ïž Benefits

‱ Medical / Dental / Vision / Disability / Life Insurance ‱ High Deductible Health Plan with Health Savings Account (HSA) option ‱ Flexible Spending Account (FSA) ‱ Access to coaches and therapists through Modern Health's platform ‱ Generous Time Off ‱ Company-wide Collective Pause Days ‱ Parental Leave Policy ‱ Family Forming Benefit through Carrot ‱ Family Assistance Benefit through UrbanSitter ‱ Professional Development Stipend ‱ 401k ‱ Financial Planning Benefit through Origin ‱ Annual Wellness Stipend ‱ New Hire Stipend to help cover work-from-home setup costs ‱ ModSquad Community: Virtual events like active ERGs, holiday themed activities, team-building events and more ‱ Monthly Cell Phone Reimbursement ‱ Full-time employees are eligible for Modern Health's equity program

Apply Now

Similar Jobs

đŸ”„ 1 hour ago

Amentum

10,000+ employees

đŸ’Œ Consulting

📩 Logistics

🏭 Manufacturing

Insider Risk Manager protecting Amentum’s sensitive information, systems, and assets. Leading threat assessments, investigations, compliance, and enterprise insider-risk programs.

đŸ‡ș🇾 United States – Remote

đŸ’” $112k - $140k / year

💰 Private Equity Round on 2020-01

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸŽČ Risk

đŸ”„ 5 hours ago

OpenRouter

1 - 10

đŸ’Œ Consulting

📣 Marketing

đŸ€– Artificial Intelligence

Third-Party Risk Analyst building OpenRouter’s vendor security program for AI infrastructure. Assessing model providers and subprocessors against security, privacy, and AI regulations.

đŸ”„ 11 hours ago

Paylocity

5001 - 10000

đŸ‘„ HR Tech

☁ SaaS

đŸ€ B2B

Senior Manager mitigating fraud across Paylocity’s cloud HR, payroll, and payments platforms. Leading investigators, detection systems, chargebacks, regulatory reporting, and cross-functional risk strategy.

đŸ‡ș🇾 United States – Remote

đŸ’” $118.1k - $140k / year

💰 $10M Venture Round - Paylocity on 2008-05

⏰ Full Time

🟠 Senior

đŸŽČ Risk

đŸ”„ 20 hours ago

Extend

201 - 500

đŸ›Ąïž Insurance

📩 Logistics

đŸ›ïž eCommerce

Risk Analytics Manager pricing insurance risk for Extend’s AI-powered post-purchase platform. Owning pricing methodology, risk strategy, data foundations, and team development.

🕒 Yesterday

Guild Mortgage

1001 - 5000

đŸ—ïž Construction

💾 Finance

🏠 Real Estate

Senior Data Governance Analyst advancing governance for Guild Mortgage’s home-financing data platform. Managing metadata, data quality, lineage, PII controls, and governance automation across enterprise teams.