Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Director of Governance, Risk and Compliance (GRC) image - Rise Careers
Job details

Director of Governance, Risk and Compliance (GRC)

Pomelo Care is a multi-disciplinary team focused on improving care for moms and babies through technology-driven solutions. They are seeking a Director of Information Security Governance, Risk and Compliance who can align security strategies with business objectives.

Skills

  • Governance frameworks
  • Risk management
  • Compliance standards
  • Security policies
  • Technical security concepts
  • Communication skills

Responsibilities

  • Develop and maintain an information security governance framework.
  • Lead the security team’s risk management efforts.
  • Ensure compliance with relevant laws and regulations.
  • Contribute to the overall security strategy.
  • Oversee the development of security awareness programs.
  • Manage vendor and third-party risk.
  • Provide updates to senior management regarding security.
  • Build and manage a team of security professionals.

Education

  • Bachelor's degree in relevant field
  • Relevant certifications (e.g., CISSP, CISM)

Benefits

  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network
To read the complete job description, please click on the ‘Apply’ button
Pomelo Care Glassdoor Company Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
Pomelo Care DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Pomelo Care
Pomelo Care CEO photo
Unknown name
Approve of CEO

Average salary estimate

$210000 / YEARLY (est.)
min
max
$185000K
$235000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Director of Governance, Risk and Compliance (GRC), Pomelo Care

If you have a passion for safeguarding information and are looking for an exciting opportunity, Pomelo Care is seeking a Director of Governance, Risk and Compliance (GRC) to join our innovative and committed team! At Pomelo Care, we focus on transforming care for moms and babies, and your expertise in GRC will be instrumental in maintaining our security posture, which is vital to our mission. In this pivotal role, you will develop and enforce security frameworks, lead risk management initiatives, and ensure compliance with industry standards such as HIPAA and GDPR. You'll collaborate with various stakeholders, providing guidance on best practices and aligning security strategies with our business objectives. Your responsibilities will also include overseeing our vendor risk management program, conducting security awareness training, and reporting directly to senior management about security metrics. This position is perfect for someone who not only excels in strategic thinking but also has the technical know-how to bridge the gap between security and business. With at least 9 years of experience in information security, a strong understanding of compliance frameworks, and relevant certifications, you’ll thrive in a dynamic environment where your ideas and solutions will make a real impact. Join Pomelo Care and help us push the boundaries of information security while having fun and growing alongside a diverse team that values your contributions!

Frequently Asked Questions (FAQs) for Director of Governance, Risk and Compliance (GRC) Role at Pomelo Care
What are the key responsibilities of a Director of Governance, Risk and Compliance at Pomelo Care?

As a Director of Governance, Risk and Compliance (GRC) at Pomelo Care, your key responsibilities will include developing an information security governance framework, leading risk management initiatives, ensuring compliance with laws and regulations, and managing security awareness programs. You'll also oversee vendor risk management and report on security metrics to senior management, all while collaborating with different teams to align security strategies with business objectives.

Join Rise to see the full answer
What qualifications are required for the Director of GRC position at Pomelo Care?

To qualify for the Director of Governance, Risk and Compliance (GRC) position at Pomelo Care, you should have a minimum of 9 years of experience in information security, with a focus on governance, risk management, and compliance. Relevant certifications like CISSP or CISM are required. A solid understanding of security frameworks, excellent communication skills, and a proven ability to collaborate effectively with stakeholders are also essential.

Join Rise to see the full answer
How does the Director of GRC contribute to Pomelo Care's mission?

In the role of Director of Governance, Risk and Compliance (GRC) at Pomelo Care, you’ll be a vital part of our commitment to safeguarding sensitive information, which is integral to our mission of improving care for moms and babies. By implementing robust security policies and collaborating across departments, you will ensure that our information assets remain secure while enabling our technology-driven care platform to operate effectively.

Join Rise to see the full answer
What is Pomelo Care's approach to employee development for the Director of GRC?

Pomelo Care is deeply committed to employee development, particularly for the Director of Governance, Risk and Compliance (GRC). We believe in fostering a collaborative and high-performing environment. You’ll have access to mentorship, professional development opportunities, and a strong support network to enhance your skills and knowledge in information security, ensuring continuous growth in your career.

Join Rise to see the full answer
What type of work culture can a Director of GRC expect at Pomelo Care?

At Pomelo Care, the work culture for the Director of Governance, Risk and Compliance (GRC) is dynamic, inclusive, and mission-driven. You will be part of a team that values diverse perspectives, encourages open communication, and promotes a security-conscious mindset throughout the organization. We strive to create an environment where all contributions are recognized and valued.

Join Rise to see the full answer
Common Interview Questions for Director of Governance, Risk and Compliance (GRC)
How do you ensure compliance with security regulations as a Director of GRC?

In ensuring compliance with security regulations as a Director of Governance, Risk and Compliance (GRC), I would conduct regular audits and risk assessments, keep up-to-date with changes in laws and regulations, and collaborate closely with legal and regulatory teams. It's also essential to develop a compliance framework that adapts to new requirements while training employees on relevant policies.

Join Rise to see the full answer
Can you describe your process for conducting risk assessments?

My process for conducting risk assessments includes identifying critical assets, evaluating potential security threats, and determining the risk levels associated with those threats. I prioritize risks based on their impact and likelihood, and I develop a comprehensive risk mitigation strategy that includes clear action plans to address identified vulnerabilities.

Join Rise to see the full answer
What strategies would you propose for building a strong information security culture at Pomelo Care?

To build a strong information security culture at Pomelo Care, I would propose initiatives like regular training sessions, developing engaging security awareness programs, and fostering open communication about security best practices. It's important to encourage a culture where employees feel responsible for security and understand its significance to the organization.

Join Rise to see the full answer
How would you align security initiatives with business objectives?

Aligning security initiatives with business objectives involves understanding the organization's goals and ensuring that security strategies support and enhance these goals. I would collaborate with leadership and other departments to identify key business drivers and tailor security measures that not only protect data but also enable growth and innovation.

Join Rise to see the full answer
What experience do you have with third-party risk management?

I have extensive experience in third-party risk management, including assessing vendor security standards, implementing effective vendor risk management programs, and ensuring compliance with security policies. My approach involves thorough due diligence and continuous monitoring of third-party security practices to mitigate any risks associated with our partnerships.

Join Rise to see the full answer
Describe a time when you had to communicate complex security concepts to non-technical stakeholders.

In a previous role, I needed to explain the importance of a new compliance framework to a group of non-technical executives. I focused on using simple analogies, visual aids, and relatable examples to illustrate potential risks and the benefits of compliance. By framing the discussion around business impact, I was able to gain their support and understanding.

Join Rise to see the full answer
What are some key security frameworks you are experienced with?

I am well-versed in several key security frameworks, including NIST, ISO 27001, and SOC 2. My experience includes implementing these frameworks, conducting compliance assessments, and ensuring that our security posture aligns with best practices outlined in these standards.

Join Rise to see the full answer
How do you stay current with emerging security threats?

To stay current with emerging security threats, I follow industry news, participate in cybersecurity communities, and attend conferences and webinars. I also regularly engage with peers and thought leaders, as well as utilize threat intelligence tools, to ensure that I am aware of the latest threats and vulnerabilities.

Join Rise to see the full answer
How do you assess the effectiveness of a security awareness program?

The effectiveness of a security awareness program can be assessed through employee engagement metrics, feedback surveys, and testing scenarios. Regularly conducting phishing simulations and monitoring incident reports helps determine how well employees understand and adhere to security practices.

Join Rise to see the full answer
What leadership approach do you take as the Director of GRC?

As the Director of Governance, Risk and Compliance (GRC), I adopt a collaborative leadership approach that emphasizes transparency, communication, and team empowerment. I believe in mentoring my team members, encouraging their professional growth, and fostering a sense of ownership over security initiatives, which contributes to a high-performing security team.

Join Rise to see the full answer
Similar Jobs
Posted 13 days ago
Photo of the Rise User
Devoteam Remote Av. dos Aliados, 4000 Porto, Portugal
Posted 12 days ago
Photo of the Rise User
Persona Remote Persona - New York
Posted 1 hour ago
Photo of the Rise User
Posted 6 days ago
Inclusive & Diverse
Mission Driven
Work/Life Harmony
Diversity of Opinions
Friends Outside of Work
Empathetic
Collaboration over Competition
Fast-Paced
Transparent & Candid
Medical Insurance
Dental Insurance
Vision Insurance
Disability Insurance
Learning & Development
401K Matching
Paid Time-Off
WFH Reimbursements
Paid Holidays
Equity
Flex-Friendly
Photo of the Rise User
BuzzClan LLC Hybrid Ross Ave, Dallas, TX, USA
Posted 3 days ago
Photo of the Rise User
Posted 11 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
SALARY RANGE
$185,000/yr - $235,000/yr
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
January 15, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!