Skip to main content
Modern Health

Senior Director of Information Risk & Governance

RemoteWorldwide
Published
Role
Security
Experience
Lead
Employment
Full-time
$231.3k–$272.1k/yr
Check eligibility

Open to Worldwide. Set where you work from to check your eligibility.

No BS summary

Senior Director for information risk & governance at a mental health benefits platform. Requires 10+ years in security risk/GRC with 5+ in regulated PHI environments. US-based only, no sponsorship; owns risk register, AI governance, incident management, and vendor risk programs.

Core skills

HIPAA Security RuleSOC 2HITRUST

Required skills

NIST CSF 2.0ISO 27001

Optional skills

NIST AI RMFCISMCRISCCISSPCISACIPP/USHITRUST CCSFP

What you'll do

  • Information technology risk governance: Own the information-security risk register, a leadership-approved risk appetite and tolerance model, and the exception/risk-acceptance register. Drive cross-functionally ratified decision rights (RACI) for risk acceptance, questionnaires, incidents, vendor exceptions, and contractual security commitments. Deliver the monthly executive information-risk report and periodic board reporting, and own the information-risk and AI-risk workstream of the enterprise Risk Committee.
  • Risk-balanced business prioritization: Coordinate and facilitate the balance between risk and business imperative, in partnership with business functions: prioritize security reviews, resourcing, and remediation by business need and revenue impact; frame risk decisions as tradeoffs with recommendations; and embed security engagement points early in enterprise deals, product launches, and AI initiatives so risk work accelerates the business rather than gates it.
  • AI governance program operations: Run the cross-functional AI governance program built with the Compliance & Privacy Officer, who retains AI policy content and legal counsel: committee operations, intake (GAT) at enterprise scale, approved/restricted-use administration, AI vendor eligibility and BAA/DPA-chain requirements, coding-agent governance, product AI review gates, AI incident management, and customer-facing AI governance evidence.
  • Incident management program: Own incident management as an enterprise program: unified severity thresholds, playbooks by incident type (security, privacy, provider/clinical, vendor), tabletop exercises, escalation paths and leadership notification standards, and post-incident corrective action tracking. Commands cross-functional non-technical incidents.
  • Data governance (security side): Drive management of the data retention and deletion program, the data classification program, and data hosting/residency positions — and lead the data segregation program (PHI data map → designated record set (DSR) into the EMR → segregation of non-DRS PHI) as a critical-path priority that gates AI capability and shrinks the certification boundary.
  • Certification & assurance programs: Provide second-line governance, program assistance, and risk escalation support for Modern Health’s certification and assurance programs, including HITRUST, SOC 2, ISO 27001 readiness, and third-party HIPAA risk assessments.
  • Third-party risk: Own the overall vendor risk program and risk-tiered assessment framework. Set minimum review standards, risk-tiering rules, approval and exception paths, escalation criteria, reassessment cadence, remediation expectations, and customer-commitment alignment.
  • Customer trust & enterprise assurance: Provide second-line review and risk calibration for customer security questionnaires, RFP security responses, trust-center materials, standard assurance packages, audit-right responses, and client-facing security commitments.
  • Policy & awareness (information risk): Own the information security and risk policy suite (Vanta-managed), annual review cycle, and risk awareness content — coordinated with, not duplicative of, the compliance training program.

What they require

  • 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership, with 5+ years in a regulated, PHI-handling environment.
  • Digital health, health plan, or healthcare services experience strongly preferred.
  • Experience providing senior governance, oversight, or program leadership for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable security assurance frameworks.
  • Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations.
  • Familiarity with NIST AI RMF and emerging AI governance expectations preferred.
  • Strong risk-decision judgment: able to distinguish technical control gaps from material enterprise risk, calibrate remediation plans against customer commitments and business priorities, and recommend when risk should be accepted, mitigated, escalated, or deferred.
  • Experience partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams to translate technical issues into business-ready decisions, executive reporting, customer commitments, and audit-ready evidence.
  • Customer-facing credibility: comfortable engaging with strategic customer CISOs, security review teams, procurement risk teams, auditors, and assessors, especially when responses require risk calibration or senior escalation.
  • Experience with third-party security risk programs, including vendor risk tiering, assessment standards, exception paths, remediation expectations, and alignment between vendor commitments and customer obligations.
  • Experience with incident management program governance, including severity thresholds, escalation paths, playbook design, tabletop facilitation, corrective action tracking, and coordination with Legal and Privacy on notification-related decision points.
  • Executive communication: translates technical risk, certification status, vendor risk, and customer assurance issues into concise, decision-ready business terms for executive team and board audiences.
  • Builder-integrator profile: able to take existing distributed processes, including security tickets, vendor intake, trust-center content, answer libraries, risk registers, audit evidence, and policy suites, and turn them into coherent, evidenced, repeatable programs.
  • Relevant certifications preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.
  • Immigration sponsorship is not available for this position. Applicants must be able to maintain work authorization for the duration of employment without employer sponsorship or employer-provided training plans or attestations (including, for example, the Form I-983 required for STEM OPT).

Benefits

  • Medical / Dental / Vision / Disability / Life Insurance
  • High Deductible Health Plan with Health Savings Account (HSA) option
  • Flexible Spending Account (FSA)
  • Access to coaches and therapists through Modern Health's platform
  • Generous Time Off
  • Company-wide Collective Pause Days
  • Parental Leave Policy
  • Family Forming Benefit through Carrot
  • Family Assistance Benefit through UrbanSitter
  • Professional Development Stipend
  • 401k
  • Financial Planning Benefit through Origin
  • Annual Wellness Stipend
  • New Hire Stipend to help cover work-from-home setup costs
  • ModSquad Community: Virtual events like active ERGs, holiday themed activities, team-building events and more
  • Monthly Cell Phone Reimbursement
🇺🇸 United StatesMental HealthStartupmodernhealthcare.com/

Details

Visa sponsorshipNo
$231.3k–$272.1k/yr