Senior Director of Information Risk & Governance
New
M
Modern HealthMental Health Benefits
Remote - US, Overlap with 8 am - 5 pm Pacific Time required for non-Pacific time zone residents.Full-TimeDirector
SalaryZone 1 Base Pay $231,300 — $272,100; Zone 2 Base Pay $231,300 — $272,100; Zone 3 Base Pay $208,170 — $244,890; Zone 4 Base Pay $196,605 — $231,285 USD
Apply NowOpens the employer's application page
Job Details
- Experience
- 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership, with 5+ years in a regulated, PHI-handling environment.
- Required Skills
- HIPAARisk Management
Requirements
- 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership.
- 5+ years of experience in a regulated, PHI-handling environment.
- Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, and third-party risk frameworks.
- Experience providing senior governance or program leadership for security assurance frameworks.
- Strong risk-decision judgment to balance technical control gaps against enterprise risk.
- Proven ability to partner across Security, IT, Legal, Privacy, Compliance, Sales, and Product teams.
- Comfortable engaging with strategic customer CISOs and procurement teams.
- Familiarity with NIST AI RMF and emerging AI governance expectations.
- Experience with incident management program governance.
- Ability to turn distributed processes into coherent, repeatable programs.
Responsibilities
- Own the information-security risk register, risk appetite model, and exception register.
- Drive cross-functional decision rights for risk acceptance, incidents, and vendor exceptions.
- Operate the cross-functional AI governance program, including intake, eligibility, and policy compliance.
- Manage the enterprise incident management program, including playbooks and tabletop exercises.
- Lead data governance initiatives, including data classification and data segregation mapping for PHI.
- Provide second-line governance and risk escalation support for SOC 2, HITRUST, and ISO 27001 programs.
- Own the third-party risk program and risk-tiered assessment framework.
- Provide second-line review for customer security questionnaires and RFP responses.
View Full Description & ApplyYou'll be redirected to the employer's site