Security and Compliance Analyst

1 Month ago • 3 Years + • Cyber Security • $120,000 PA - $140,000 PA

Job Summary

Job Description

Pomelo Care is seeking a proactive and detail-oriented Security and Compliance Analyst to support the development and execution of its information security and Governance, Risk, and Compliance (GRC) program. This role involves collaborating across departments to identify and mitigate cybersecurity risks, ensure regulatory compliance, and contribute to security and privacy initiatives. The ideal candidate will have a solid foundation in information security or GRC, strong project management skills, and a passion for improving processes in a dynamic healthcare startup environment. Key responsibilities include supporting the implementation and maintenance of the GRC program, performing security risk assessments, tracking remediation activities, managing third-party risk, participating in audits, and ensuring compliance with regulations like HIPAA.
Must have:
  • Minimum 3 years of professional experience in GRC, cybersecurity, compliance, or risk management.
  • Experience coordinating or managing projects.
  • Excellent organizational skills and attention to detail.
  • Strong written and verbal communication skills.
  • Ability to work independently and prioritize tasks.
Good to have:
  • Bachelor’s degree in Computer Science, Information Security, Information Systems, Business, or related.
  • Professional certification (CISA, CRISC, Security+, PMP).
  • Experience in healthcare technology startups.
  • Familiarity with healthcare regulatory requirements (HIPAA, HITRUST).
  • Experience with GRC tools (Vanta, MyCSF).
Perks:
  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network

Job Details

About us

Pomelo Care is a multi-disciplinary team of clinicians, engineers and problem solvers who are passionate about improving care for moms and babies. We are transforming outcomes for pregnant people and babies with evidence-based pregnancy and newborn care at scale. Our technology-driven care platform enables us to engage patients early, conduct individualized risk assessments for poor pregnancy outcomes, and deliver coordinated, personalized virtual care throughout pregnancy, NICU stays, and the first postpartum year. We measure ourselves by reductions in preterm births, NICU admissions, c-sections and maternal mortality; we improve outcomes and reduce healthcare spend.

What you'll do

Pomelo Care is seeking a proactive and detail-oriented Security and Compliance Analyst to support the development and execution of our information security and Governance, Risk, and Compliance (GRC) program. In this role, you will collaborate across departments to help identify and mitigate cybersecurity risks, ensure regulatory compliance, and contribute to security and privacy initiatives. The ideal candidate has a solid foundation in information security or GRC, strong project management skills, and a passion for improving processes in a dynamic healthcare startup environment.

Key responsibilities will include: 

  • Support the implementation and maintenance of Pomelo Care’s information security and GRC program, including policies, standards, and procedures.
  • Assist in performing security risk assessments and control evaluations across the organization.
  • Track and coordinate remediation activities for identified risks or compliance gaps.
  • Support third-party risk management activities, including vendor security reviews, user access reviews and due diligence assessments.
  • Participate in internal and external audits (e.g., SOC 2, HITRUST), including evidence collection and responding to the auditor. inquiries.
  • Help manage compliance with healthcare-specific regulations (e.g., HIPAA) and security frameworks.
  • Support the development and project management of security compliance workflows, including implementation of technical and administrative controls
  • Develop and maintain metrics and dashboards to communicate GRC program status to stakeholders.
  • Document processes, workflows, and control narratives to support governance and compliance efforts.
  • Manage GRC or security-related projects, ensuring timely and quality delivery.
  • Provide support for security awareness and training initiatives.

Who you are

  • Minimum 3 years of professional experience in GRC, cybersecurity, compliance, risk management, or a related field.
  • Experience coordinating or managing projects, including developing plans, tracking progress, and collaborating with stakeholders.
  • Excellent organizational skills and attention to detail.
  • Strong written and verbal communication skills.
  • Ability to work independently and prioritize multiple tasks in a fast-paced startup environment.

We'll be super excited if you have

  • Bachelor’s degree in Computer Science, Information Security, Information Systems, Business, or a related discipline.
  • Professional certification such as CISA, CRISC, Security+, PMP or similar.
  • Experience in healthcare technology startups or familiarity with healthcare regulatory requirements (e.g., HIPAA, HITRUST).
  • Experience with GRC tools and platforms, such as Vanta and MyCSF.

Why you should join our team

By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.

We strive to create an environment where employees from all backgrounds are respected. We also offer:

  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)

At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.

Our salary ranges are based on paying competitively for our company’s size and industry, and are one part of the total compensation package that also includes equity, benefits, and other opportunities at Pomelo Care. In accordance with New York City, Colorado, California, and other applicable laws, Pomelo Care is required to provide a reasonable estimate of the compensation range for this role. Individual pay decisions are ultimately based on a number of factors, including qualifications for the role, experience level, skillset, geography, and balancing internal equity. Given that this role is open to candidates of different skill levels, determining a salary range is challenging. A reasonable estimate of the current salary range is $120,000 to $140,000. We expect most candidates to fall in the middle of the range.

 

#LI-Remote

Potential Fraud Warning


Please be cautious of potential recruitment fraud. With the increase of remote work and digital hiring, phishing and job scams are on the rise with malicious actors impersonating real employees and sending fake job offers in an effort to collect personal or financial information.

Pomelo Care will never ask you to pay a fee or download software as part of the interview process with our company. Pomelo Care will also never ask for your personal banking or other financial information until after you have signed an offer of employment and completed onboarding paperwork that is provided by our People Operations team. All official communication with Pomelo Care People Operations team will come from domain email addresses ending in @pomelocare.com.

If you receive a message that seems suspicious, we encourage you to pause communication and contact us directly at careers@pomelocare.com  to confirm its legitimacy. For your safety, we also recommend applying only through our official Careers page. If you believe you have been the victim of a scam or identity theft, please contact your local law enforcement agency or another trusted authority for guidance.

Similar Jobs

Toast - Retail Account Executive

Toast

Greenville, South Carolina, United States (On-Site)
2 Months ago
Thales - Senior Naval Architect

Thales

Sydney, New South Wales, Australia (Hybrid)
3 Weeks ago
Riot Games - Staff Software Engineer, Audio - Unpublished R&D Product

Riot Games

Mercer Island, Washington, United States (On-Site)
3 Months ago
Halcyon - Senior Manager, Product Marketing

Halcyon

(Remote)
1 Month ago
IGT - Talent Management Specialist III

IGT

Providence, Rhode Island, United States (On-Site)
2 Months ago
Rippling - Senior Security Engineer, Offensive Security

Rippling

United States (Remote)
1 Month ago
Cadence - Sr. Software Security Engineer

Cadence

Cork, County Cork, Ireland (On-Site)
2 Months ago
Take-Two Interactive - Information Security Operations Analyst

Take-Two Interactive

Las Vegas, Nevada, United States (On-Site)
3 Weeks ago
Devoteam - Cybersecurity Architect

Devoteam

Porto, Porto District, Portugal (On-Site)
1 Month ago
Tide - Staff Backend Engineer - DevEx, Security and Technology Foundations

Tide

Vilnius, Vilnius County, Lithuania (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Dave Ramsey - Senior Copywriter

Dave Ramsey

Franklin, Tennessee, United States (On-Site)
2 Months ago
Rackspace Technology - Bid Manager V - IN

Rackspace Technology

India (Remote)
2 Weeks ago
smarsh - Cloud Engineer III-Kubernetes

smarsh

India (Hybrid)
6 Months ago
Global Business Travel - Sr. Analytics Manager

Global Business Travel

London, England, United Kingdom (On-Site)
1 Month ago
Riot Games - Staff Software Engineer, MGS - 2XKO

Riot Games

Dublin, County Dublin, Ireland (On-Site)
9 Months ago
Saviynt - Identity Security Practice - Director, Professional Services

Saviynt

California, United States (Remote)
1 Month ago
level ai - Senior Machine Learning Engineer

level ai

Noida, Uttar Pradesh, India (On-Site)
3 Months ago
Glitch production - 3D Asset Lead

Glitch production

Parramatta, New South Wales, Australia (On-Site)
1 Month ago
PwC - Accountant

PwC

Qormi, Malta (On-Site)
10 Months ago
Mistral AI - Data Quality Specialist, AI Tutor

Mistral AI

Paris, Île-de-France, France (Hybrid)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in United States

extreme network - Senior SLED Account Manager

extreme network

Sacramento, California, United States (On-Site)
2 Months ago
Minecast - Senior Customer Success Manager

Minecast

Lexington, Massachusetts, United States (Hybrid)
1 Year ago
Twitch - Software Engineer I

Twitch

San Francisco, California, United States (On-Site)
3 Months ago
Nintendo - Web QA Specialist

Nintendo

Redmond, Washington, United States (Hybrid)
4 Months ago
HCL Tech - ET - Senior Group Technical Architect

HCL Tech

California, United States (On-Site)
2 Months ago
Pluralsight - Vice President of Financial Planning and Analysis

Pluralsight

United States (Remote)
1 Month ago
Mindtickle - Director, Customer Success

Mindtickle

United States (Remote)
3 Months ago
Clearwater Analytics - Senior Client Engineer

Clearwater Analytics

New York, United States (On-Site)
2 Weeks ago
Jane Street - Linux Engineer

Jane Street

New York, United States (On-Site)
1 Month ago
Survay Monkey - Manager - Finance Systems

Survay Monkey

Portland, Oregon, United States (Remote)
4 Weeks ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

London stock Exchange - Business Manager - Cyber Security & Engineering Risk

London stock Exchange

Bucharest, Bucharest, Romania (On-Site)
2 Months ago
Alpha Sense - Senior Cloud Security Engineer

Alpha Sense

Pune, Maharashtra, India (On-Site)
2 Months ago
DOTSOFT SA - Security Engineer

DOTSOFT SA

Greece (On-Site)
4 Months ago
DataVisor - Security Engineer

DataVisor

Austin, Texas, United States (Remote)
1 Month ago
CyberArk - Senior Director, Cyber Security Center

CyberArk

Israel (Hybrid)
1 Month ago
Experian - Information Security Specialist Senior

Experian

Cyberjaya, Selangor, Malaysia (On-Site)
3 Months ago
Optiv - Sr. Client Manager - Cybersecurity

Optiv

Winnipeg, Manitoba, Canada (On-Site)
3 Months ago
Jane Street - Cybersecurity Detection and Response Analyst

Jane Street

Singapore (On-Site)
3 Months ago
Techland - Security Analyst

Techland

Wrocław, Lower Silesian Voivodeship, Poland (On-Site)
2 Months ago
Varonis  - Frontend Angular Engineer - AI Security

Varonis

Herzliya, Tel Aviv District, Israel (Hybrid)
4 Months ago

Get notifed when new similar jobs are uploaded