Senior Director of Information Risk & Governance

Modern Health
United States
Workplace: RemoteFull timeFunction: Legal, Risk & ComplianceExperience: 10+ yearsSkills: ["Risk judgment","Executive communication","Cross-functional partnership","Program governance"]

Own Modern Health’s second-line information security risk governance across enterprise clients and regulated environments. Lead and connect risk register, risk appetite/tolerance, AI risk governance operations, incident management governance, data classification/retention governance, and third-party vendor risk programs. Partner with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product to balance risk vs. business priorities, deliver executive/board reporting, and provide audit- and customer-facing assurance calibration.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Modern Health
Modern Health
22 hours ago

Senior Director of Information Risk & Governance

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Own Modern Health’s second-line information security risk governance across enterprise clients and regulated environments. Lead and connect risk register, risk appetite/tolerance, AI risk governance operations, incident management governance, data classification/retention governance, and third-party vendor risk programs. Partner with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product to balance risk vs. business priorities, deliver executive/board reporting, and provide audit- and customer-facing assurance calibration.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Director level

Key Responsibilities

  • •Own the information-security risk register, risk appetite/tolerance model, exception/risk-acceptance register, and drive cross-functional ratified decision rights; deliver monthly executive information-risk reporting and board reporting.
  • •Run the enterprise risk committee workstream, and provide risk-balanced prioritization by coordinating security reviews, resourcing, and remediation based on business need and revenue impact.
  • •Operate the cross-functional AI governance program, including committee operations, AI vendor eligibility (BAA/DPA requirements), approved/restricted-use administration, coding-agent governance, AI review gates, AI incident management, and evidence.
  • •Own incident management as an enterprise program (severity thresholds, incident-type playbooks, tabletop exercises, escalation paths, corrective action tracking) and coordinate notification-related decision points with Legal and Privacy.
  • •Provide second-line certification and assurance governance (HITRUST, SOC 2, ISO 27001 readiness, HIPAA risk assessments), manage third-party/vendor risk programs and customer trust/enterprise assurance reviews.

Key Requirements

  • •10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership, including 5+ years in a regulated, PHI-handling environment.
  • •Experience providing senior governance/oversight for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable assurance frameworks.
  • •Deep knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations (NIST AI RMF preferred).
  • •Strong risk-decision judgment to calibrate remediation plans, distinguish control gaps vs. material risk, and recommend risk acceptance/mitigation/escalation/deferment.
  • •Customer-facing credibility with CISOs, procurement risk teams, auditors, and assessors for risk calibration and senior escalation; executive communication skills.
Experience:10+ yearsDigital healthHealthcareRegulated environmentsPHIGRCThird-party risk
Skills:Risk judgmentExecutive communicationCross-functional partnershipProgram governance
Certifications:CISMCRISCCISSPCISACIPP/USHITRUST CCSFP
Tech Stack:VantaHIPAA Security RuleNIST CSF 2.0NIST AI RMFSOC 2HITRUSTISO 27001BAADPA

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Modern Health
Provides a mental health and well-being platform for employers, combining coaching, therapy, and self-guided digital resources to support employee mental health and improve workplace outcomes.
Industry: Mental Health
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Funding: Series C
Headquarters: San Francisco, United States
Founded: 2017
WebsiteLinkedIn