Pomelo Care

Director of Governance, Risk and Compliance (GRC)

United States

Not SpecifiedCompensation
Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Healthcare Technology, Information SecurityIndustries

Director of Information Security Governance, Risk and Compliance (GRC)

Employment Type: [Not Specified] Location Type: [Not Specified] Salary: [Not Specified]

About Us

Pomelo Care is a multi-disciplinary team of clinicians, engineers, and problem solvers who are passionate about improving care for moms and babies. We are transforming outcomes for pregnant people and babies with evidence-based pregnancy and newborn care at scale. Our technology-driven care platform enables us to engage patients early, conduct individualized risk assessments for poor pregnancy outcomes, and deliver coordinated, personalized virtual care throughout pregnancy, NICU stays, and the first postpartum year. We measure ourselves by reductions in preterm births, NICU admissions, c-sections, and maternal mortality; we improve outcomes and reduce healthcare spend.

What You'll Do

Pomelo Care is looking to grow our information security team. We are actively seeking an accomplished and motivated Director of Information Security Governance, Risk and Compliance (GRC) who shares our commitment to information security as a cornerstone in safeguarding our organization. This is an exciting opportunity to be part of a fast-paced environment that pushes you to learn while doing.

This role needs to be both strategic and intensely focused on GRC with an emphasis on process, scalability, and automation to ensure our security posture aligns seamlessly with business objectives. We value experience in collaborating with key stakeholders, understanding regulatory requirements, and implementing effective security strategies.

Key Responsibilities:

Governance

  • Develop and maintain an information security governance framework.
  • Establish and enforce security policies, standards, and procedures.
  • Provide guidance on security best practices and industry standards.
  • Collaborate with leadership to ensure security strategies align with business objectives.

Security Risk Management

  • Lead the security team’s risk management efforts.
  • Conduct risk assessments to identify and evaluate security risks.
  • Develop and implement risk mitigation strategies and action plans.
  • Monitor and report on risk metrics and trends to senior management.

Compliance

  • Ensure the organization's compliance with relevant laws, regulations, certifications, assessments, and industry standards including HIPAA, CCPA, CPRA, HITRUST, SOC 2, NIST-800, GDPR, among others.
  • Conduct regular compliance assessments and audits.
  • Collaborate with legal and regulatory affairs to address compliance requirements.
  • Stay abreast of changes in relevant laws and regulations affecting security.

Security Strategy

  • Contribute to the development of the organization's overall security strategy.
  • Provide strategic direction for security initiatives and projects.
  • Collaborate with other departments to integrate security into business processes.
  • Assess emerging technologies and trends for their impact on security.

Security Awareness and Training

  • Oversee the development and delivery of security awareness programs.
  • Conduct training sessions for employees on security policies and procedures.
  • Foster a security-conscious culture throughout the organization.

Vendor and Third-Party Risk Management

  • Assess and manage security risks associated with third-party vendors.
  • Develop and maintain a vendor risk management program.
  • Ensure third-party compliance with security standards.

Reporting and Communication

  • Provide regular updates and reports on security, risk, and compliance to senior management.
  • Communicate security strategies and priorities to all stakeholders.
  • Act as a liaison between technical security teams and executive leadership.

Leadership

  • Build, recruit, lead, and manage a team of security professionals.
  • Foster a collaborative and high-performing security team.
  • Provide mentorship and professional development opportunities.

Continuous Improvement

  • Identify opportunities for process improvement.

Skills

Governance Framework Development
Security Policies and Standards
Risk Management
Regulatory Compliance
Security Strategy Alignment
Stakeholder Collaboration
Process Automation
Security Best Practices

Pomelo Care

Personalized healthcare for pregnancy and newborns

About Pomelo Care

Pomelo Care provides personalized healthcare services for pregnant individuals and newborns. The company combines traditional medical practices with advanced technology to improve health outcomes for families. Their services are designed to be accessible and focus on evidence-based care, ensuring that expectant mothers and their newborns receive the best possible support. Unlike many competitors, Pomelo Care emphasizes a tailored approach to healthcare, integrating technology to enhance the patient experience. The goal of Pomelo Care is to create a supportive environment that promotes the health and well-being of families during pregnancy and early childhood.

New York City, New YorkHeadquarters
2021Year Founded
$84.6MTotal Funding
SERIES_BCompany Stage
HealthcareIndustries
11-50Employees

Benefits

Health Insurance
Company Equity
Paid Vacation

Risks

Competition from similar maternity care providers may reduce Pomelo's market share.
Operational challenges from integrating The Doula Network could affect service delivery.
Regulatory scrutiny on virtual healthcare may increase compliance costs for Pomelo.

Differentiation

Pomelo Care combines virtual and in-person maternity services, unique in the industry.
The acquisition of The Doula Network enhances Pomelo's comprehensive care model.
Pomelo uses data science to improve maternal and infant health outcomes.

Upsides

Increased demand for telehealth boosts Pomelo's virtual care services.
Expansion of Medicaid coverage offers Pomelo new market opportunities.
Growing interest in personalized healthcare aligns with Pomelo's service model.

Land your dream remote job 3x faster with AI