← Back to jobs

Remote job

Senior Director of Information Risk & Governance

Other Full-time Permanent US

Job details

$231,300—$272,100 Salary
US Eligibility
Senior Experience
Full-time Employment

About this role

Role overview

This senior leadership role establishes the second-line-of-defense information risk and governance function inside a digital mental health organization. The position sits within Legal, reporting to the General Counsel, and is deliberately independent from the teams that build, operate, and execute security and IT programs. It is a builder-integrator seat that connects existing security and risk assets into coherent, audited programs as the company scales into enterprise and regulated customer segments in healthcare, financial services, and global employers.

Responsibilities

- Serve as the independent second-line-of-defense leader for information technology risk, partnering closely with the head of operational security, IT, legal, privacy, compliance, sales, procurement, and product teams. - Own the customer-facing security assurance function: review and risk-calibrate non-standard security questionnaires, RFP responses, trust-center content, audit responses, and client-facing security commitments, including direct engagement with strategic customer security teams. - Direct the information security policy suite, the annual review cycle, and risk-awareness content, coordinating with but not duplicating compliance training programs. - Integrate existing assets — vendor intake, access reviews, risk register, answer library, incident response, and trust center — into repeatable, evidenced governance programs for enterprise and regulated clients. - Translate technical control gaps, vendor risk, certification status, and customer assurance issues into concise, decision-ready reporting for executives and the board. - Calibrate decisions against the actual control environment and risk appetite, recommending when issues should be accepted, mitigated, escalated, or deferred.

Requirements

- 10+ years in information-security risk management, security governance, GRC, assurance, or security program leadership, including 5+ years in a regulated PHI-handling environment. - Digital health, health plan, or healthcare services experience strongly preferred. - Senior experience guiding SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable assurance frameworks through scope, findings, remediation, evidence strategy, and escalation. - Deep working knowledge of the HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations. - Strong risk-decision judgment and the ability to turn technical issues into business-ready decisions and executive reporting. - A builder-integrator profile able to convert distributed processes into coherent, repeatable programs; relevant certifications such as CISM, CRISC, CISSP, CISA, CIPP/US, or HITRUST CCSFP preferred.

Nice to have

- Familiarity with NIST AI RMF and emerging AI governance expectations.

Benefits and work setup

- Fully remote; US-based team members outside the Pacific time zone are expected to work at least six hours overlapping with 8 am–5 pm Pacific each workday. - Medical, dental, vision, disability, and life insurance; high-deductible health plan with HSA option; flexible spending account. - Access to mental health coaching and therapy, generous time off, and company-wide collective pause days. - Parental leave, family-forming benefits, and family care assistance. - 401(k) and financial planning support. - Professional development stipend, annual wellness stipend, annual work-from-home stipend, monthly cell phone reimbursement, and virtual community and employee resource group events. - Base salary ranges from approximately $196,605 to $272,100 USD depending on location zone; full-time employees also participate in an equity program. - Immigration sponsorship is not available for this position.

Skills detected in the listing

Information Security
Detected Oct 8, 2026
Last verified Oct 8, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight