Director of Governance, Risk and Compliance (GRC)

1 Month ago • 9 Years + • Risk Management • $185,000 PA - $235,000 PA

Job Summary

Job Description

Pomelo Care is seeking an accomplished Director of Information Security Governance, Risk and Compliance (GRC) to join their fast-paced team. This role requires a strategic and focused individual to manage information security as a cornerstone of the organization. The responsibilities include developing and maintaining an information security governance framework, establishing policies, conducting risk assessments, ensuring compliance with regulations like HIPAA, CCPA, HITRUST, SOC 2, and NIST-800, and contributing to the overall security strategy. The role also involves overseeing security awareness programs, managing vendor risk, reporting to senior management, and leading a team of security professionals. Continuous improvement and fostering a security-conscious culture are key aspects of this position. The ideal candidate will have at least 9 years of experience in information security with a GRC focus, strong technical background, and relevant certifications.
Must have:
  • Develop and maintain information security governance framework
  • Establish and enforce security policies, standards, and procedures
  • Lead security risk management efforts
  • Conduct risk assessments and develop mitigation strategies
  • Ensure compliance with HIPAA, CCPA, HITRUST, SOC 2, NIST-800
  • Oversee security awareness programs and training
  • Assess and manage third-party vendor security risks
  • Build, recruit, lead, and manage a security team
  • 9+ years experience in information security with GRC focus
  • Relevant certifications (e.g., CISSP, CISM)
Good to have:
  • 6 years experience and relevant bachelor’s degree
  • Strong technical background including full stack software development
  • Expertise in system architecture and security fundamentals
  • Knowledge of MITRE ATT&CK and D3FEND frameworks
  • Understanding of OWASP top ten mitigations
  • Exceptional communication skills to convey complex security concepts
Perks:
  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network

Job Details

About us

Pomelo Care is a multi-disciplinary team of clinicians, engineers and problem solvers who are passionate about improving care for moms and babies. We are transforming outcomes for pregnant people and babies with evidence-based pregnancy and newborn care at scale. Our technology-driven care platform enables us to engage patients early, conduct individualized risk assessments for poor pregnancy outcomes, and deliver coordinated, personalized virtual care throughout pregnancy, NICU stays, and the first postpartum year. We measure ourselves by reductions in preterm births, NICU admissions, c-sections and maternal mortality; we improve outcomes and reduce healthcare spend.

What you'll do

Pomelo Care is looking to grow our information security team. We are actively seeking an accomplished and motivated Director of Information Security Governance, Risk and Compliance (GRC) who shares our commitment to information security as a cornerstone in safeguarding our organization. It is an exciting opportunity to be part of a fast-paced environment that pushes you to learn while doing. 

This role needs to be both strategic and intensely focused on GRC with an emphasis on process, scalability, and automation to ensure our security posture aligns seamlessly with business objectives. We value experience in collaborating with key stakeholders, understanding regulatory requirements, and implementing effective security strategies.

Key responsibilities will include: 

Governance

  • Develop and maintain an information security governance framework. 
  • Establish and enforce security policies, standards, and procedures. 
  • Provide guidance on security best practices and industry standards. 
  • Collaborate with leadership to ensure security strategies align with business objectives. 

Security Risk Management

  • Lead the security team’s risk management efforts. 
  • Conduct risk assessments to identify and evaluate security risks. 
  • Develop and implement risk mitigation strategies and action plans. 
  • Monitor and report on risk metrics and trends to senior management.

Compliance

  • Ensure the organization's compliance with relevant laws, regulations, certifications, assessments and industry standards including HIPAA, CCPA, CPRA, HITRUST, SOC 2, NIST-800, GDPR, among others. 
  • Conduct regular compliance assessments and audits. 
  • Collaborate with legal and regulatory affairs to address compliance requirements. 
  • Stay abreast of changes in relevant laws and regulations affecting security. 

Security Strategy

  • Contribute to the development of the organization's overall security strategy. 
  • Provide strategic direction for security initiatives and projects. 
  • Collaborate with other departments to integrate security into business processes. 
  • Assess emerging technologies and trends for their impact on security.

Security Awareness and Training

  • Oversee the development and delivery of security awareness programs. 
  • Conduct training sessions for employees on security policies and procedures. 
  • Foster a security-conscious culture throughout the organization. 

Vendor and Third-Party Risk Management

  • Assess and manage security risks associated with third-party vendors. 
  • Develop and maintain a vendor risk management program. 
  • Ensure third-party compliance with security standards. 

Reporting and Communication

  • Provide regular updates and reports on security, risk, and compliance to senior management. 
  • Communicate security strategies and priorities to all stakeholders. 
  • Act as a liaison between technical security teams and executive leadership.

Leadership

  • Build, recruit, lead and manage a team of security professionals. 
  • Foster a collaborative and high-performing security team. 
  • Provide mentorship and professional development opportunities. 

Continuous Improvement

  • Identify opportunities for process improvement within the security GRC function. 
  • Stay informed about industry trends and best practices. 
  • Implement continuous improvement initiatives to enhance security posture. 

Values and Behaviors

  • Demonstrate entrepreneurial spirit, strong communication skills, humility, and comfort working in and contributing to a dynamic and cross-functional team environment.

Who you are

  • 9+ years experience in information security (or 6 years experience and relevant bachelor’s degree), with a focus on GRC. 
  • Strong understanding of governance, risk management, and compliance frameworks. 
  • Experience in collaborating with and influencing key stakeholders and ensuring security strategies align with business objectives. 
  • Strong technical background including full stack software development, system architecture and security fundamentals such as PKI, SAML, JWT, HMAC as well as MITRE ATT&CK and D3FEND frameworks and OWASP top ten mitigations.
  • Relevant certifications (e.g. CISSP, CISM) required. 
  • Exceptional communication skills and the ability to convey complex security concepts to non-technical stakeholders. 

This role plays a pivotal part in fortifying Pomelo Care's security foundation, ensuring the confidentiality, integrity, and availability of our information assets. If you are a seasoned security professional with a passion for GRC, we invite you to join our dynamic team and contribute to our ongoing commitment to information security excellence.

Why you should join our team

By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.

We strive to create an environment where employees from all backgrounds are respected. We also offer:

  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)

At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.

Our salary ranges are based on paying competitively for our company’s size and industry, and are one part of the total compensation package that also includes equity, benefits, and other opportunities at Pomelo Care. In accordance with New York City, Colorado, California, and other applicable laws, Pomelo Care is required to provide a reasonable estimate of the compensation range for this role. Individual pay decisions are ultimately based on a number of factors, including qualifications for the role, experience level, skillset, geography, and balancing internal equity. Given that this role is open to candidates of different skill levels, determining a salary range is challenging. A reasonable estimate of the current salary range is $185,000 to $235,000. We expect most candidates to fall in the middle of the range.

 

#LI-Remote

Potential Fraud Warning


Please be cautious of potential recruitment fraud. With the increase of remote work and digital hiring, phishing and job scams are on the rise with malicious actors impersonating real employees and sending fake job offers in an effort to collect personal or financial information.

Pomelo Care will never ask you to pay a fee or download software as part of the interview process with our company. Pomelo Care will also never ask for your personal banking or other financial information until after you have signed an offer of employment and completed onboarding paperwork that is provided by our People Operations team. All official communication with Pomelo Care People Operations team will come from domain email addresses ending in @pomelocare.com.

If you receive a message that seems suspicious, we encourage you to pause communication and contact us directly at careers@pomelocare.com  to confirm its legitimacy. For your safety, we also recommend applying only through our official Careers page. If you believe you have been the victim of a scam or identity theft, please contact your local law enforcement agency or another trusted authority for guidance.

Similar Jobs

GoMotive - Manager, Enterprise Systems Engineering (QA)

GoMotive

Pakistan (Remote)
3 Months ago
Adyen - Enterprise Account Manager

Adyen

Paris, Île-de-France, France (Hybrid)
2 Weeks ago
ARHS - AWS or Azure Cloud Architect

ARHS

Luxembourg (On-Site)
4 Months ago
deel. - QA Automation Engineer | EMEA

deel.

North Macedonia (Remote)
3 Weeks ago
CookUnity - Senior Growth Marketing Manager, Google

CookUnity

New York, United States (On-Site)
3 Weeks ago
London stock Exchange - Senior Manager - Risk Coverage

London stock Exchange

London, England, United Kingdom (On-Site)
1 Month ago
Lulalend - Senior Credit Risk Analyst

Lulalend

Cape Town, Western Cape, South Africa (On-Site)
2 Months ago
Yodlee - Information Security Risk Management Director

Yodlee

Berwyn, Pennsylvania, United States (Hybrid)
5 Months ago
Ion - Senior Consultant - Risk Advisory, Italy

Ion

Milan, Lombardy, Italy (On-Site)
10 Months ago
binance - Risk Operation Specialist - Transaction Monitoring (EST timezone)

binance

Mexico City, Mexico (Remote)
3 Weeks ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

zeta - Principal Engineer I - Backend

zeta

Hyderabad, Telangana, India (On-Site)
4 Months ago
Ethos Life - Data Scientist

Ethos Life

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Apple - Senior Product Manager, Search Intelligence & Algorithms

Apple

Cupertino, California, United States (On-Site)
4 Weeks ago
Zamp - Backend Senior Engineer

Zamp

Bengaluru, Karnataka, India (On-Site)
1 Year ago
Canva - Senior Software Engineer (Python) - Data Platform

Canva

Auckland, Auckland, New Zealand (Remote)
2 Months ago
Wolters Kluwer - Associate Director, Marketing

Wolters Kluwer

London, England, United Kingdom (On-Site)
3 Weeks ago
Moving Walls India - Android Developer

Moving Walls India

Chennai, Tamil Nadu, India (On-Site)
3 Years ago
Apple - Software Engineer - Backend Systems (Golang)

Apple

San Diego, California, United States (On-Site)
2 Months ago
Ness - Program Manager

Ness

New York, United States (On-Site)
1 Month ago
The Workshop - Data Software Engineer

The Workshop

Málaga, Andalusia, Spain (Hybrid)
11 Months ago

Get notifed when new similar jobs are uploaded

Jobs in United States

crate entertainment  - Environment Artist (Principal / Senior)

crate entertainment

United States (Remote)
1 Month ago
Vimeo - Web Platform Operations Contractor

Vimeo

New York, New York, United States (On-Site)
3 Months ago
Thales - Regional Sales Manager (Data/App Security)

Thales

Illinois, United States (Remote)
3 Months ago
Notion - Technical Recruiter

Notion

San Francisco, California, United States (On-Site)
1 Month ago
Roblox - Senior Machine Learning Engineer - Content Understanding

Roblox

San Mateo, California, United States (On-Site)
1 Month ago
Fireworks AI - Forward Deployed Product Manager

Fireworks AI

Redwood City, California, United States (On-Site)
1 Month ago
gitlab - Engineering Manager, Security Risk Management: Security Insights

gitlab

United States (Remote)
1 Month ago
Aledade - Technical Product Manager (AI/ML Research)

Aledade

United States (Remote)
2 Months ago
HCL Tech - Senior Support Lead

HCL Tech

Pennsylvania, United States (On-Site)
2 Months ago
hogarth - Graphic Production Artist

hogarth

Sunnyvale, California, United States (Hybrid)
2 Months ago

Get notifed when new similar jobs are uploaded

Risk Management Jobs

bytedance - Global Employee Relations - Risk and Dispute Management

bytedance

Singapore (On-Site)
4 Months ago
Visa - Head of Risk Consulting, Visa Consulting & Analytics, CISSEE

Visa

Almaty, Almaty Region, Kazakhstan (On-Site)
10 Months ago
Remote - Payroll Risk & Compliance Lead - APAC

Remote

Asia, Lima Region, Peru (Remote)
3 Weeks ago
Optiv - Associate Consultant - Cyber Strategy & Risk

Optiv

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Ion - Senior Consultant - Risk Advisory, Italy

Ion

Milan, Lombardy, Italy (On-Site)
10 Months ago
Fireworks AI - Governance, Risk, and Compliance Lead

Fireworks AI

Redwood City, California, United States (Hybrid)
1 Month ago
PwC - Manager, Risk Management

PwC

Bangkok, Bangkok, Thailand (On-Site)
10 Months ago
PwC - Senior Manager - Cyber Risk Advisory

PwC

Saint Peter Port, Guernsey (On-Site)
2 Months ago
Visa - Sr. Director, Enterprise & Operational Risk Management

Visa

Atlanta, Georgia, United States (Hybrid)
2 Weeks ago
nubank - Operational Risk Specialist

nubank

Mexico City, Mexico (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded