
Senior Director of Information Risk, Governance
Posted Aug 12

Posted Aug 12
This is a fully remote position, open to applicants in United States.
• Take ownership of the information-security risk register, risk appetite and tolerance model, and exception/risk-acceptance register.
• Establish decision-making rights across functions for risk acceptance, questionnaires, incidents, vendor exceptions, and contractual security commitments.
• Produce monthly executive reports on information risks and periodic updates for the board.
• Lead the information-risk and AI-risk workstream as part of the enterprise Risk Committee.
• Coordinate the prioritization of business risks in a balanced manner, oversee security reviews, resource allocation, remediation, and risk-related decisions.
• Manage the cross-functional AI governance program, including intake processes, administration of approved/restricted uses, vendor eligibility for AI, governance of coding agents, gates for product AI reviews, incident management, and customer-facing evidence.
• Oversee the governance of enterprise incident management, including defining severity thresholds, developing playbooks, conducting tabletop exercises, establishing escalation paths, notification standards, and tracking corrective actions.
• Propel initiatives related to data retention/deletion, classification, hosting/residency, and segregation.
• Provide second-line governance and support for risk escalations related to HITRUST, SOC 2, ISO 27001 readiness, and third-party HIPAA risk assessments.
• Manage the vendor risk program alongside a risk-tiered assessment framework.
• Review and refine customer security questionnaires, responses to RFPs, materials for the trust center, assurance packages, audit-right responses, and security commitments.
• Oversee the suite of information security and risk policies, including the annual review cycle and the creation of risk awareness content.
• A minimum of 10 years' experience in information-security risk management, security governance, assurance, GRC, or leadership of security programs.
• At least 5 years in a regulated environment handling PHI.
• Experience in digital health, health plans, or healthcare services is highly preferred.
• Proven senior governance, oversight, or leadership experience related to SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or similar frameworks.
• Extensive knowledge of the HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and expectations for customer security assurance.
• Strong judgment in risk decisions and the ability to align remediation efforts with customer commitments and business priorities.
• Experience collaborating with teams in Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product.
• Customer-facing experience interacting with strategic customer CISOs, security review teams, procurement risk teams, auditors, and assessors.
• Familiarity with third-party security risk programs, including vendor risk tiering, assessment standards, exception pathways, remediation expectations, and alignment with customer obligations.
• Experience in governance of incident management programs, including defining severity thresholds, escalation paths, playbooks, facilitating tabletop exercises, and tracking corrective actions.
• Strong communication skills for presenting decision-ready reports to executives and boards.
• Ability to transform distributed processes into coherent, evidence-based, repeatable programs.
• Relevant certifications are preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.
• Immigration sponsorship is not available; candidates must have work authorization without employer sponsorship or provided training plans or attestations.
• Medical, Dental, Vision, Disability, and Life Insurance.
• High Deductible Health Plan with an option for a Health Savings Account (HSA).
• Flexible Spending Account (FSA).
• Access to coaches and therapists via Modern Health's platform.
• Generous Time Off policy.
• Company-wide Collective Pause Days.
• Parental Leave Policy.
• Family Forming Benefit available through Carrot.
• Family Assistance Benefit provided through UrbanSitter.
• Professional Development Stipend.
• 401k plan.
• Financial Planning Benefit through Origin.
• Annual Wellness Stipend.
• New Hire Stipend to assist with work-from-home setup costs.
• ModSquad Community: Participate in virtual events such as active ERGs, holiday-themed activities, team-building events, and more.
• Monthly reimbursement for Cell Phone expenses.
• Full-time employees are eligible for Modern Health's equity program.
Sage Bionetworks
Neodigital Versicherung AG
RHI Magnesita
Get handpicked remote jobs straight to your inbox weekly.