Director of Governance, Risk and Compliance (GRC)
United States
About us
Pomelo Care is a multi-disciplinary team of clinicians, engineers and problem solvers who are passionate about improving care for moms and babies. We are transforming outcomes for pregnant people and babies with evidence-based pregnancy and newborn care at scale. Our technology-driven care platform enables us to engage patients early, conduct individualized risk assessments for poor pregnancy outcomes, and deliver coordinated, personalized virtual care throughout pregnancy, NICU stays, and the first postpartum year. We measure ourselves by reductions in preterm births, NICU admissions, c-sections and maternal mortality; we improve outcomes and reduce healthcare spend.
What you'll do
Pomelo Care is looking to grow our information security team. We are actively seeking an accomplished and motivated Director of Information Security Governance, Risk and Compliance (GRC) who shares our commitment to information security as a cornerstone in safeguarding our organization. It is an exciting opportunity to be part of a fast-paced environment that pushes you to learn while doing.
This role needs to be both strategic and intensely focused on GRC with an emphasis on process, scalability, and automation to ensure our security posture aligns seamlessly with business objectives. We value experience in collaborating with key stakeholders, understanding regulatory requirements, and implementing effective security strategies.
Key responsibilities will include:
Governance
- Develop and maintain an information security governance framework.
- Establish and enforce security policies, standards, and procedures.
- Provide guidance on security best practices and industry standards.
- Collaborate with leadership to ensure security strategies align with business objectives.
Security Risk Management
- Lead the security team’s risk management efforts.
- Conduct risk assessments to identify and evaluate security risks.
- Develop and implement risk mitigation strategies and action plans.
- Monitor and report on risk metrics and trends to senior management.
Compliance
- Ensure the organization's compliance with relevant laws, regulations, certifications, assessments and industry standards including HIPAA, CCPA, CPRA, HITRUST, SOC 2, NIST-800, GDPR, among others.
- Conduct regular compliance assessments and audits.
- Collaborate with legal and regulatory affairs to address compliance requirements.
- Stay abreast of changes in relevant laws and regulations affecting security.
Security Strategy
- Contribute to the development of the organization's overall security strategy.
- Provide strategic direction for security initiatives and projects.
- Collaborate with other departments to integrate security into business processes.
- Assess emerging technologies and trends for their impact on security.
Security Awareness and Training
- Oversee the development and delivery of security awareness programs.
- Conduct training sessions for employees on security policies and procedures.
- Foster a security-conscious culture throughout the organization.
Vendor and Third-Party Risk Management
- Assess and manage security risks associated with third-party vendors.
- Develop and maintain a vendor risk management program.
- Ensure third-party compliance with security standards.
Reporting and Communication
- Provide regular updates and reports on security, risk, and compliance to senior management.
- Communicate security strategies and priorities to all stakeholders.
- Act as a liaison between technical security teams and executive leadership.
Leadership
- Build, recruit, lead and manage a team of security professionals.
- Foster a collaborative and high-performing security team.
- Provide mentorship and professional development opportunities.
Continuous Improvement
- Identify opportunities for process improvement within the security GRC function.
- Stay informed about industry trends and best practices.
- Implement continuous improvement initiatives to enhance security posture.
Values and Behaviors
- Demonstrate entrepreneurial spirit, strong communication skills, humility, and comfort working in and contributing to a dynamic and cross-functional team environment.
Who you are
- 9+ years experience in information security (or 6 years experience and relevant bachelor’s degree), with a focus on GRC.
- Strong understanding of governance, risk management, and compliance frameworks.
- Experience in collaborating with and influencing key stakeholders and ensuring security strategies align with business objectives.
- Strong technical background including full stack software development, system architecture and security fundamentals such as PKI, SAML, JWT, HMAC as well as MITRE ATT&CK and D3FEND frameworks and OWASP top ten mitigations.
- Relevant certifications (e.g. CISSP, CISM) required.
- Exceptional communication skills and the ability to convey complex security concepts to non-technical stakeholders.
This role plays a pivotal part in fortifying Pomelo Care's security foundation, ensuring the confidentiality, integrity, and availability of our information assets. If you are a seasoned security professional with a passion for GRC, we invite you to join our dynamic team and contribute to our ongoing commitment to information security excellence.
Why you should join our team
By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.
We strive to create an environment where employees from all backgrounds are respected. We also offer:
- Competitive healthcare benefits
- Generous equity compensation
- Unlimited vacation
- Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)
At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.
Our salary ranges are based on paying competitively for our company’s size and industry, and are one part of the total compensation package that also includes equity, benefits, and other opportunities at Pomelo Care. In accordance with New York City, Colorado, California, and other applicable laws, Pomelo Care is required to provide a reasonable estimate of the compensation range for this role. Individual pay decisions are ultimately based on a number of factors, including qualifications for the role, experience level, skillset, geography, and balancing internal equity. Given that this role is open to candidates of different skill levels, determining a salary range is challenging. A reasonable estimate of the current salary range is $185,000 to $235,000. We expect most candidates to fall in the middle of the range.
#LI-Remote
ApplyJob Profile
Remote
Benefits/PerksCompetitive healthcare Competitive healthcare benefits Equity Equity Compensation Fast-paced environment Generous equity Generous equity compensation Healthcare Healthcare Benefits Membership in the first round network Team environment Unlimited Vacation
Tasks- Conduct risk assessments
- Conduct training sessions
- Develop governance framework
- Ensure compliance with regulations
- Lead security strategy
- Manage security team
- Oversee security training
Automation C CCPA Communication Compliance Continuous Improvement CPRA Diversity Equity GDPR Governance Healthcare HIPAA HITRUST Leadership NIST 800 Process Automation Process Improvement Risk assessments Risk Management SAML Security Awareness Security policies Security standards SOC 2 Software Strategic planning Team Leadership Training Vendor risk management Virtual care
Experience5 years
TimezonesAmerica/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9