Remotery

Senior Director of Information Risk, Governance

atModern HealthRemoteUS flagUnited StatesFull-timeRiskSenior$231.3k – $272.1k/year

Posted Aug 12

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of the information-security risk register, risk appetite and tolerance model, and exception/risk-acceptance register.

• Establish decision-making rights across functions for risk acceptance, questionnaires, incidents, vendor exceptions, and contractual security commitments.

• Produce monthly executive reports on information risks and periodic updates for the board.

• Lead the information-risk and AI-risk workstream as part of the enterprise Risk Committee.

• Coordinate the prioritization of business risks in a balanced manner, oversee security reviews, resource allocation, remediation, and risk-related decisions.

• Manage the cross-functional AI governance program, including intake processes, administration of approved/restricted uses, vendor eligibility for AI, governance of coding agents, gates for product AI reviews, incident management, and customer-facing evidence.

• Oversee the governance of enterprise incident management, including defining severity thresholds, developing playbooks, conducting tabletop exercises, establishing escalation paths, notification standards, and tracking corrective actions.

• Propel initiatives related to data retention/deletion, classification, hosting/residency, and segregation.

• Provide second-line governance and support for risk escalations related to HITRUST, SOC 2, ISO 27001 readiness, and third-party HIPAA risk assessments.

• Manage the vendor risk program alongside a risk-tiered assessment framework.

• Review and refine customer security questionnaires, responses to RFPs, materials for the trust center, assurance packages, audit-right responses, and security commitments.

• Oversee the suite of information security and risk policies, including the annual review cycle and the creation of risk awareness content.


⛳️ Requirements

• A minimum of 10 years' experience in information-security risk management, security governance, assurance, GRC, or leadership of security programs.

• At least 5 years in a regulated environment handling PHI.

• Experience in digital health, health plans, or healthcare services is highly preferred.

• Proven senior governance, oversight, or leadership experience related to SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or similar frameworks.

• Extensive knowledge of the HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and expectations for customer security assurance.

• Strong judgment in risk decisions and the ability to align remediation efforts with customer commitments and business priorities.

• Experience collaborating with teams in Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product.

• Customer-facing experience interacting with strategic customer CISOs, security review teams, procurement risk teams, auditors, and assessors.

• Familiarity with third-party security risk programs, including vendor risk tiering, assessment standards, exception pathways, remediation expectations, and alignment with customer obligations.

• Experience in governance of incident management programs, including defining severity thresholds, escalation paths, playbooks, facilitating tabletop exercises, and tracking corrective actions.

• Strong communication skills for presenting decision-ready reports to executives and boards.

• Ability to transform distributed processes into coherent, evidence-based, repeatable programs.

• Relevant certifications are preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.

• Immigration sponsorship is not available; candidates must have work authorization without employer sponsorship or provided training plans or attestations.


🏝️ Benefits

• Medical, Dental, Vision, Disability, and Life Insurance.

• High Deductible Health Plan with an option for a Health Savings Account (HSA).

• Flexible Spending Account (FSA).

• Access to coaches and therapists via Modern Health's platform.

• Generous Time Off policy.

• Company-wide Collective Pause Days.

• Parental Leave Policy.

• Family Forming Benefit available through Carrot.

• Family Assistance Benefit provided through UrbanSitter.

• Professional Development Stipend.

• 401k plan.

• Financial Planning Benefit through Origin.

• Annual Wellness Stipend.

• New Hire Stipend to assist with work-from-home setup costs.

• ModSquad Community: Participate in virtual events such as active ERGs, holiday-themed activities, team-building events, and more.

• Monthly reimbursement for Cell Phone expenses.

• Full-time employees are eligible for Modern Health's equity program.

People also viewed

Sage Bionetworks1 day ago

Senior Biomedical Research, Data Governance

US flagUnited States OnlyFull-timeRisk$93.3k – $121.7k/year
ApplyView job
SoftDesign1 day ago

Data Governance Analyst

BR flagBrazil OnlyFull-timeRisk
ApplyView job
Neodigital Versicherung AG1 day ago

IT Governance Manager

DE flagGermany OnlyFull-timeRisk
ApplyView job
RHI Magnesita1 day ago

Data Governance and Process Specialist

AT flagAustria OnlyFull-timeRisk
ApplyView job
GuidePoint Security1 day ago

Data Governance Analyst

US flagUnited States OnlyFull-timeRisk
ApplyView job
BMO1 day ago

Governance and Controls Business Line Liaison

US flagColorado OnlyFull-timeRisk$74k – $138k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers