Director of Governance, Risk and Compliance (GRC)
United States
About us
Pomelo Care is a multi-disciplinary team of clinicians, engineers and problem solvers who are passionate about improving care for moms and babies. We are transforming outcomes for pregnant people and babies with evidence-based pregnancy and newborn care at scale. Our technology-driven care platform enables us to engage patients early, conduct individualized risk assessments for poor pregnancy outcomes, and deliver coordinated, personalized virtual care throughout pregnancy, NICU stays, and the first postpartum year. We measure ourselves by reductions in preterm births, NICU admissions, c-sections and maternal mortality; we improve outcomes and reduce healthcare spend.
What you'll do
Pomelo Care is looking to grow our information security team. We are actively seeking an accomplished and motivated Director of Information Security Governance, Risk and Compliance (GRC) who shares our commitment to information security as a cornerstone in safeguarding our organization. It is an exciting opportunity to be part of a fast-paced environment that pushes you to learn while doing.
This role needs to be both strategic and intensely focused on GRC with an emphasis on process, scalability, and automation to ensure our security posture aligns seamlessly with business objectives. We value experience in collaborating with key stakeholders, understanding regulatory requirements, and implementing effective security strategies.
Key responsibilities will include:
Governance
- Develop and maintain an information security governance framework.
- Establish and enforce security policies, standards, and procedures.
- Provide guidance on security best practices and industry standards.
- Collaborate with leadership to ensure security strategies align with business objectives.
Security Risk Management
- Lead the security team’s risk management efforts.
- Conduct risk assessments to identify and evaluate security risks.
- Develop and implement risk mitigation strategies and action plans.
- Monitor and report on risk metrics and trends to senior management.
Compliance
- Ensure the organization's compliance with relevant laws, regulations, certifications, assessments and industry standards including HIPAA, CCPA, CPRA, HITRUST, SOC 2, NIST-800, GDPR, among others.
- Conduct regular compliance assessments and audits.
- Collaborate with legal and regulatory affairs to address compliance requirements.
- Stay abreast of changes in relevant laws and regulations affecting security.
Security Strategy
- Contribute to the development of the organization's overall security strategy.
- Provide strategic direction for security initiatives and projects.
- Collaborate with other departments to integrate security into business processes.
- Assess emerging technologies …
This job isn't fresh anymore!
Search Fresh JobsJob Profile
Remote
Benefits/PerksCompetitive healthcare Competitive healthcare benefits Equity Equity Compensation Fast-paced environment Generous equity Generous equity compensation Healthcare Healthcare Benefits Team environment Unlimited Vacation
Tasks- Conduct risk assessments
- Conduct training sessions
- Develop governance framework
- Ensure compliance with regulations
Automation C CCPA Communication Compliance Continuous Improvement CPRA Diversity Equity GDPR Governance Healthcare HIPAA HITRUST Leadership Process Automation Process Improvement Risk assessments Risk Management SAML Security Awareness Security policies Security standards SOC 2 Software Strategic planning Team Leadership Training Vendor risk management Virtual care
Experience5 years
TimezonesAmerica/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9