Demo

Director of Governance, Risk and Compliance (GRC)

Pomelo Care
New York, NY Full Time
POSTED ON 1/16/2025
AVAILABLE BEFORE 3/14/2025

What you'll do

Pomelo Care is looking to grow our information security team. We are actively seeking an accomplished and motivated Director of Information Security Governance, Risk and Compliance (GRC) who shares our commitment to information security as a cornerstone in safeguarding our organization. It is an exciting opportunity to be part of a fast-paced environment that pushes you to learn while doing. 

This role needs to be both strategic and intensely focused on GRC with an emphasis on process, scalability, and automation to ensure our security posture aligns seamlessly with business objectives. We value experience in collaborating with key stakeholders, understanding regulatory requirements, and implementing effective security strategies.

Key responsibilities will include: 

Governance

  • Develop and maintain an information security governance framework. 
  • Establish and enforce security policies, standards, and procedures. 
  • Provide guidance on security best practices and industry standards. 
  • Collaborate with leadership to ensure security strategies align with business objectives. 

Security Risk Management

  • Lead the security team’s risk management efforts. 
  • Conduct risk assessments to identify and evaluate security risks. 
  • Develop and implement risk mitigation strategies and action plans. 
  • Monitor and report on risk metrics and trends to senior management.

Compliance

  • Ensure the organization's compliance with relevant laws, regulations, certifications, assessments and industry standards including HIPAA, CCPA, CPRA, HITRUST, SOC 2, NIST-800, GDPR, among others. 
  • Conduct regular compliance assessments and audits. 
  • Collaborate with legal and regulatory affairs to address compliance requirements. 
  • Stay abreast of changes in relevant laws and regulations affecting security. 

Security Strategy

  • Contribute to the development of the organization's overall security strategy. 
  • Provide strategic direction for security initiatives and projects. 
  • Collaborate with other departments to integrate security into business processes. 
  • Assess emerging technologies and trends for their impact on security.

Security Awareness and Training

  • Oversee the development and delivery of security awareness programs. 
  • Conduct training sessions for employees on security policies and procedures. 
  • Foster a security-conscious culture throughout the organization. 

Vendor and Third-Party Risk Management

  • Assess and manage security risks associated with third-party vendors. 
  • Develop and maintain a vendor risk management program. 
  • Ensure third-party compliance with security standards. 

Reporting and Communication

  • Provide regular updates and reports on security, risk, and compliance to senior management. 
  • Communicate security strategies and priorities to all stakeholders. 
  • Act as a liaison between technical security teams and executive leadership.

Leadership

  • Build, recruit, lead and manage a team of security professionals. 
  • Foster a collaborative and high-performing security team. 
  • Provide mentorship and professional development opportunities. 

Continuous Improvement

  • Identify opportunities for process improvement within the security GRC function. 
  • Stay informed about industry trends and best practices. 
  • Implement continuous improvement initiatives to enhance security posture. 

Values and Behaviors

  • Demonstrate entrepreneurial spirit, strong communication skills, humility, and comfort working in and contributing to a dynamic and cross-functional team environment.

Who you are

  • 9 years experience in information security (or 6 years experience and relevant bachelor’s degree), with a focus on GRC. 
  • Strong understanding of governance, risk management, and compliance frameworks. 
  • Experience in collaborating with and influencing key stakeholders and ensuring security strategies align with business objectives. 
  • Strong technical background including full stack software development, system architecture and security fundamentals such as PKI, SAML, JWT, HMAC as well as MITRE ATT&CK and D3FEND frameworks and OWASP top ten mitigations.
  • Relevant certifications (e.g. CISSP, CISM) required. 
  • Exceptional communication skills and the ability to convey complex security concepts to non-technical stakeholders. 

This role plays a pivotal part in fortifying Pomelo Care's security foundation, ensuring the confidentiality, integrity, and availability of our information assets. If you are a seasoned security professional with a passion for GRC, we invite you to join our dynamic team and contribute to our ongoing commitment to information security excellence.

Why you should join our team

By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.

We strive to create an environment where employees from all backgrounds are respected. We also offer:

  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)

At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.

Our salary ranges are based on paying competitively for our company’s size and industry, and are one part of the total compensation package that also includes equity, benefits, and other opportunities at Pomelo Care. In accordance with New York City, Colorado, California, and other applicable laws, Pomelo Care is required to provide a reasonable estimate of the compensation range for this role. Individual pay decisions are ultimately based on a number of factors, including qualifications for the role, experience level, skillset, geography, and balancing internal equity. Given that this role is open to candidates of different skill levels, determining a salary range is challenging. A reasonable estimate of the current salary range is $185,000 to $235,000. We expect most candidates to fall in the middle of the range.

 

#LI-Remote

Salary : $185,000 - $235,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Director of Governance, Risk and Compliance (GRC)?

Sign up to receive alerts about other jobs on the Director of Governance, Risk and Compliance (GRC) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$270,069 - $359,305
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Pomelo Care

Pomelo Care
Hired Organization Address Houston, TX Full Time
Your North Star : provide compassionate, culturally-relevant, and evidence-based nutrition care. We are hiring a skilled...
Pomelo Care
Hired Organization Address Atlanta, GA Full Time
Role Description Your North Star: Provide medical leadership and collaborative clinical support to a multi-disciplinary ...
Pomelo Care
Hired Organization Address Richmond, VA Full Time
Role Description As a doula in the Pomelo network, you will educate and guide expecting and new families throughout preg...
Pomelo Care
Hired Organization Address Atlanta, GA Full Time
Role Description Your North Star : Provide direct patient care and clinical oversight that optimizes outcomes for pregna...

Not the job you're looking for? Here are some other Director of Governance, Risk and Compliance (GRC) jobs in the New York, NY area that may be a better fit.

AI Assistant is available now!

Feel free to start your new journey!