跳到主要内容
OOfficialJobs
菜单
官方来源官方来源职位

信息风险与治理高级总监

机器翻译
查看雇主原标题Senior Director of Information Risk & Governance

Modern Health · Remote - US · On Target Earnings (OTE) and includes both base pay and commission at 100% achievement of established targets.

职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。

为什么值得关注?

发现指数 50/100,仅依据与该职位一起存储的证据计算。

50/100 发现指数
  • 新的雇主官方职位
  • 远程职位

分数构成

  • 时效性 (随职位发布时间变化)+18
  • 雇主官方来源+15
  • 远程职位+8
  • 稀有职位+1
  • 公司来源健康度+8

该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。

这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。

职位描述

英文原文

该职位由雇主以英文发布,暂无中文版本,下面完整显示英文原文。 查看官方职位页面.

职位描述

Modern Health

Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digital resources for their emotional, professional, social, financial, and physical well-being needs—all within a single platform. Whether someone wants to proactively manage stress or treat depression, Modern Health guides people to the right care at the right time. We empower companies to help all their employees be the best version of themselves, and believe in meeting people wherever they are in their mental health journey.

Modern Health is backed by investors like Kleiner Perkins, Founders Fund, John Doerr, Y Combinator, and Battery Ventures and raised more than $170 million in less than two years, making Modern Health the fastest entirely female-founded company in the U.S. to reach Unicorn status.

More about our culture and what you can expect when you join the team:

• “It Takes a Village” culture . Modern Health has a unique and unabashed culture centered around high empathy and high accountability - with a drive to win. We are energized by bringing together the best talent in the industry to achieve audacious goals focused on making mental health a strength and priority for all.

• We have an obsession to win. We are highly ambitious and passionate about the work that we do. We take pride in delivering excellence and our personal best and we continuously innovate to uniquely solve our customers’ needs.

• We are accountable and can rely on each other. We are a team and hold ourselves and each other accountable. We believe in transparent communication and continuous feedback to foster a culture of trust, reliability, and growth.

• We demonstrate empathy. We have a supportive and diverse culture where we bolster and uplift each other as we pursue our lofty goals. We encourage selflessness and a willingness to support others, fostering a collaborative and respectful environment.

• We exhibit a bias towards action. This is a fast-paced environment. We jump into problems and initiate solutions. We empower our people to make decisions and experiment, iterate, and repeat until we get it right.

Modern Health is a fully remote workforce and a hyper-growth company that is often recognized for its excellence, winning awards such as World’s Most Innovative Companies of 2023 by Fast Company, Top 25 Companies of San Francisco 2023 , and 2023 Well-Being Trailblazer Award . To protect our culture and help our team stay connected, we require overlapping hours for everyone. While many roles may function from anywhere in the world—see individual job listing for more—US based team members who live outside the Pacific time zone are expected to work at least six hours between 8 am and 5 pm Pacific time each workday.

We are looking for driven, creative, and passionate individuals to join in our mission. An inclusive and diverse culture are key components of mental well-being in the workplace, and that starts with how we build our own team. If you're excited about a role, we'd love to hear from you!

岗位职责

Modern Health is scaling into enterprise and regulated clients — health plans, financial services, and global employers — whose trust depends on demonstrable information technology risk governance. Much of Modern Health's information technology risk and governance framework already exists — policies, vendor intake, access reviews, a trust center, an answer library, a risk register, incident response, and incident tooling. What this role adds is the senior ownership and oversight to establish and run our cross-functional governance programs: connecting those assets into coherent, evidenced, enterprise-credible programs, and representing our posture to strategic clients, auditors, and assessors.

The Senior Director, Information Risk & Governance is the company’s second-line-of-defense leader for information technology risk: an independent risk, governance, and assurance function reporting to the General Counsel, deliberately separated from the teams that build, operate, and execute security and IT programs. The role partners closely with the Head of Security Engineering, who continues to run operational security execution, certification readiness, audit evidence production, and day-to-day customer security response workflows. This role provides program governance, risk decision support, escalation, remediation-plan calibration, executive reporting, and client-facing support.

• Information technology risk governance. Own the information-security risk register, a leadership-approved risk appetite and tolerance model, and the exception/risk-acceptance register. Drive cross-functionally ratified decision rights (RACI) for risk acceptance, questionnaires, incidents, vendor exceptions, and contractual security commitments. Deliver the monthly executive information-risk report and periodic board reporting, and own the information-risk and AI-risk workstream of the enterprise Risk Committee (chaired by the Compliance & Privacy Officer).

• Risk-balanced business prioritization. Coordinate and facilitate the balance between risk and business imperative, in partnership with business functions: prioritize security reviews, resourcing, and remediation by business need and revenue impact; frame risk decisions as tradeoffs with recommendations; and embed security engagement points early in enterprise deals, product launches, and AI initiatives so risk work accelerates the business rather than gates it.

• AI governance program operations. Run the cross-functional AI governance program built with the Compliance & Privacy Officer, who retains AI policy content and legal counsel: committee operations, intake (GAT) at enterprise scale, approved/restricted-use administration, AI vendor eligibility and BAA/DPA-chain requirements, coding-agent governance, product AI review gates, AI incident management, and customer-facing AI governance evidence.

• Incident management program. Own incident management as an enterprise program: unified severity thresholds, playbooks by incident type (security, privacy, provider/clinical, vendor), tabletop exercises, escalation paths and leadership notification standards, and post-incident corrective action tracking. Commands cross-functional non-technical incidents. Security engineering serves as technical incident commander for cyber incidents; the Compliance & Privacy Officer retains investigations program, privacy breach determinations and regulator/individual notification decisions.

• Data governance (security side). Drive management of the data retention and deletion program, the data classification program, and data hosting/residency positions — and lead the data segregation program (PHI data map → designated record set (DSR) into the EMR → segregation of non-DRS PHI) as a critical-path priority that gates AI capability and shrinks the certification boundary. Partner with Security Engineering, IT, and Data on implementation and with the privacy team on privacy positions. Stand up the data governance decision forum.

• Certification & assurance programs. Provide second-line governance, program assistance, and risk escalation support for Modern Health’s certification and assurance programs, including HITRUST, SOC 2, ISO 27001 readiness, and third-party HIPAA risk assessments. The Head of Security Engineering owns day-to-day program execution, control operation, evidence production, auditor walkthrough support, and remediation execution. This role partners with the Head of Security Engineering on certification strategy, scope, prioritization, risk decisions, findings, remediation plans, exception requests, executive visibility, and customer-facing assurance positions.

• Third-party risk. Own the overall vendor risk program and risk-tiered assessment framework. Set minimum review standards, risk-tiering rules, approval and exception paths, escalation criteria, reassessment cadence, remediation expectations, and customer-commitment alignment. Ensure Modern Health is consistently assessing vendors against the right risks, applying the right level of review, and escalating material vendor risk decisions through the appropriate governance path.

• Customer trust & enterprise assurance. Provide second-line review and risk calibration for customer security questionnaires, RFP security responses, trust-center materials, standard assurance packages, audit-right responses, and client-facing security commitments. Security owns the day-to-day response process, answer-library content, technical inputs, and evidence production. This role reviews higher-risk responses and non-standard positions, helps calibrate commitments against Modern Health’s actual control environment and risk appetite, and interfaces directly with strategic customer information-risk and security teams.

• Policy & awareness (information risk). Own the information security and risk policy suite (Vanta-managed), annual review cycle, and risk awareness content — coordinated with, not duplicative of, the compliance training program.

任职要求

• 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership, with 5+ years in a regulated, PHI-handling environment.

• Digital health, health plan, or healthcare services experience strongly preferred.

• Experience providing senior governance, oversight, or program leadership for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable security assurance frameworks. Direct execution experience is valuable, but this role requires the judgment to guide scope, findings, remediation plans, evidence strategy, and risk escalation in partnership with Security.

• Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations. Familiarity with NIST AI RMF and emerging AI governance expectations preferred.

• Strong risk-decision judgment: able to distinguish technical control gaps from material enterprise risk, calibrate remediation plans against customer commitments and business priorities, and recommend when risk should be accepted, mitigated, escalated, or deferred.

• Experience partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams to translate technical issues into business-ready decisions, executive reporting, customer commitments, and audit-ready evidence.

• Customer-facing credibility: comfortable engaging with strategic customer CISOs, security review teams, procurement risk teams, auditors, and assessors, especially when responses require risk calibration or senior escalation.

• Experience with third-party security risk programs, including vendor risk tiering, assessment standards, exception paths, remediation expectations, and alignment between vendor commitments and customer obligations.

• Experience with incident management program governance, including severity thresholds, escalation paths, playbook design, tabletop facilitation, corrective action tracking, and coordination with Legal and Privacy on notification-related decision points.

• Executive communication: translates technical risk, certification status, vendor risk, and customer assurance issues into concise, decision-ready business terms for executive team and board audiences.

• Builder-integrator profile: able to take existing distributed processes, including security tickets, vendor intake, trust-center content, answer libraries, risk registers, audit evidence, and policy suites, and turn them into coherent, evidenced, repeatable programs.

• Relevant certifications preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.

• Immigration sponsorship is not available for this position. Applicants must be able to maintain work authorization for the duration of employment without employer sponsorship or employer-provided training plans or attestations (including, for example, the Form I-983 required for STEM OPT).

福利待遇

Fundamentals:

• Medical / Dental / Vision / Disability / Life Insurance

• High Deductible Health Plan with Health Savings Account (HSA) option

• Flexible Spending Account (FSA)

• Access to coaches and therapists through Modern Health's platform

• Generous Time Off

• Company-wide Collective Pause Days

Family Support:

• Parental Leave Policy

• Family Forming Benefit through Carrot

• Family Assistance Benefit through UrbanSitter

Professional Development:

• Professional Development Stipend

Financial Wellness:

• 401k

• Financial Planning Benefit through Origin

But wait there’s more…!

• Annual Wellness Stipend to use on items that promote your overall well being

• New Hire Stipend to help cover work-from-home setup costs

• ModSquad Community: Virtual events like active ERGs, holiday themed activities, team-building events and more

• Monthly Cell Phone Reimbursement

Equal Pay for Equal Work Act Information

Please refer to the ranges below to find the starting annual pay range for individuals applying to work remotely from the following locations for this role.

• Zone 1: San Francisco Bay Area and New York City Metro

• Zone 2: All other California locations and Seattle, WA

• Zone 3: All other New York locations, All other Washington locations, Washington DC, Austin, TX, CT, IL, MA, NH, NJ, OR, RI, VT

• Zone 4: All other Texas locations, AL, AK, AZ, AR, CO, DE, FL, GA, HI, ID, IN, IA, KS, KY, LA, ME, MD, MI, MN, MS, MO, MT, NE, NV, NM, NC, ND, OH, OK, PA, SC, SD, TN, UT, VA, WV, WI, WY

Compensation for the role will depend on a number of factors, including a candidate's qualifications, skills, competencies, and experience and may fall outside of the range shown. Ranges are not necessarily indicative of the associated starting pay range in other locations. Full-time employees are also eligible for Modern Health's equity program and incredible benefits package. See our Careers page for more information.

Depending on the scope of the role, some ranges are indicative of On Target Earnings (OTE) and includes both base pay and commission at 100% achievement of established targets.

Zone 1 Base Pay $231,300 — $272,100 USD

Zone 2 Base Pay $231,300 — $272,100 USD

Zone 3 Base Pay $208,170 — $244,890 USD

Zone 4 Base Pay $196,605 — $231,285 USD

Below, we are asking you to complete identity information for the Equal Employment Opportunity Commission (EEOC). While we are required by law to ask these questions in the format provided by the EEOC, at Modern Health we know that gender is not binary, and we recognize that these categories do not reflect our employees' full range of identities.

Modern Health 的更多职位

公司主页
官方来源
Remote - US远程全职On Target Earnings (OTE) and includes both base pay and commission at 100% achievement of established targets.
英文原文

Modern Health Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digita…

官方来源职位60/100 发现指数
首次发现于4天前
已核实46分钟前
San Francisco, CA全职On Target Earnings (OTE) and includes both base pay and commission at 100% achievement of established targets.
英文原文

Modern Health Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digita…

官方来源职位44/100 发现指数
首次发现于4天前
已核实46分钟前
Remote - US远程全职On Target Earnings (OTE) and includes both base pay and commission at 100% achievement of established targets.
英文原文

Modern Health Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digita…

官方来源职位50/100 发现指数
首次发现于4天前
已核实46分钟前

高级续约经理

Modern Health · Client Management

官方来源
Remote - US远程合同制On Target Earnings (OTE) and includes both base pay and commission at 100% achievement of established targets.
英文原文

Modern Health Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digita…

官方来源职位60/100 发现指数
首次发现于4天前
已核实46分钟前

其他公司的相似职位

搜索这类职位

Security Risk Management Intern (Summer 2027)原文

Robinhood · Enterprise Technology Division

官方来源最新
Menlo Park, CA实习Base pay for the successful applicant will depend on a variety of job-related factors, which may include education, training, experience, location, business nee
英文原文

Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The…

未出现在监控的职位板上
首次发现于46分钟前
已核实46分钟前

Inspector de Revisión Técnica Vehicular原文

SGS · Inspection and Field Testing

官方来源最新
Guayaquil, Guayas, 厄瓜多尔全职未披露薪资
英文原文

Descripción de la empresa SGS es una compañía líder mundial en servicios de inspección, verificación, análisis y certificación , con presencia global y un fuerte enfoque en garantizar la calidad, se…

未出现在监控的职位板上
首次发现于7小时前
已核实7小时前

Senior Internal Auditor Nigeria原文

SGS · Management, General Administration and Support Functions

官方来源最新
Apapa, Lagos, ng全职未披露薪资
英文原文

Company Description We are SGS – the world’s leading testing, inspection and certification company. We are recognized as the global benchmark for quality and integrity. Our 96,000 employees operate…

未出现在监控的职位板上
首次发现于7小时前
已核实7小时前
官方来源最新
Bangalore全职未披露薪资
英文原文

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world's largest enterprises to the most ambitious startups - use Stripe to…

官方来源职位
首次发现于7小时前
已核实7小时前