Pomelo Care Logo

Pomelo Care

Director of Security Compliance

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
200K-230K Annually
Senior level
Remote
Hiring Remotely in United States
200K-230K Annually
Senior level
Lead Pomelo Care’s enterprise security governance, risk, and compliance program. Own SOC 2 Type II and HITRUST certification lifecycles, security policies, access governance, HIPAA risk assessments, awareness training, control monitoring, incident response, and third-party risk assessments. Partner with engineering leadership to align technical roadmaps with security strategy, represent the company during audits and partner due diligence, and report security posture and program maturity to executives.
The summary above was generated by AI

Pomelo Care is the leading virtual medical practice for women and children, providing care across pregnancy, postpartum, pediatrics, menopause, and perimenopause. We combine proactive, 24/7 clinical care with technology that helps us reach patients earlier, identify risks sooner, and deliver personalized care throughout their journey. Our team includes clinicians, technologists, operators, and problem-solvers working together to make high-quality care more accessible for families nationwide.

About The Role:

We are looking for a Director of Security Compliance to lead our security governance, risk, and assurance strategy. Reporting to the Head of Compliance, you will be the primary architect of our security governance program and the most senior voice on security oversight, owning the roadmap for our HITRUST and SOC certification lifecycles.

This is a hands-on role: in partnership with the Head of Compliance, you will build and run our security compliance program. It is not a software engineering position. You will define our security standards, risk appetite, and compliance requirements, while our engineering team owns technical implementation. Your success will come from setting direction, influencing technical roadmaps, and holding the organization accountable to a security posture that protects our patients and enables the business to move fast.

What you’ll do:

  • Define and own the enterprise-wide security strategy and policy framework in partnership with our engineering team and help shape our security risk appetite across all of Pomelo Care.

  • Lead the full lifecycle for SOC 2 Type II and HITRUST certifications, managing external auditors and coordinating internal evidence collection.

  • Own day-to-day security compliance operations, including drafting and maintaining security policies and procedures, access control governance and periodic user access reviews, the annual HIPAA Security Risk Assessment, security awareness training, and ongoing control monitoring.

  • Serve as the security “Design Authority”: setting the governance standards that engineering’s security team builds to.

  • Partner as a peer with engineering leadership to ensure that technical roadmaps align with the enterprise security strategy.

  • Provide governance oversight for technical risk management, ensuring engineering-led solutions meet regulatory and contractual thresholds.

  • Act as the primary security point of contact for our health plan partners, leading security due diligence and representing our program during external audits and questionnaires.

  • Own the security assessment component of our Third-Party Risk Management program ensuring our vendors and partners meet our security and privacy requirements.

  • Own the Incident Response Plan, leading coordination, communication, and the compliance response while engineering handles technical containment and remediation.

  • Report regularly on security risk posture and program maturity to executive leadership.

What you’ll bring:

  • 8+ years of experience in Information Security, with at least 3 years in a leadership or GRC-focused role, including direct experience in healthcare, and ideally in a high-growth startup environment.

  • Deep knowledge of HIPAA (particularly the Security Rule) and HITECH, and working knowledge of state privacy and security laws (CCPA/CPRA).

  • Proven track record personally leading successful SOC 2 and HITRUST (i1 or r2) certification cycles from readiness through audit.

  • Technical fluency. You won't be writing code, but you understand cloud environments (GCP preferred), CI/CD pipelines, and modern security tooling well enough to hold a detailed, credible conversation with the engineers who build them.

  • Exceptional communication skills, including the ability to translate complex security concepts into clear, practical guidance for executives, engineers, and business teams, and the ability to represent Pomelo’s security posture to sophisticated external health plan partners.

  • A pragmatic, business-forward approach to security: you right-size controls to actual risk, find paths to yes, and enable the business to move fast without compromising patient trust.

  • Strong project management skills, and a track record of driving cross-functional initiatives across the engineering, product, and operations teams to on-time completion.

  • Preferred certifications: CISSP, CISM, or CISA.

  • A collaborative mindset and a passion for our mission to improve maternal and infant health outcomes.

Compensation:

The expected base salary range offered for this role is $200,000-$230,000. This role is also eligible for equity, giving you an ownership stake in Pomelo’s mission. Actual compensation may vary based on relevant experience, skills, competencies, and certifications.

We are committed to hiring the best team to improve outcomes for all mothers and babies. To solve the complex challenges facing the diverse population we serve, we need diverse perspectives, actively welcoming people of all races, ages, sexual orientations, gender identities and expressions, national origins, religions, disabilities, and veteran statuses. We strive to cultivate an inclusive and respectful environment where team members thrive by working across disciplines, moving fast, making data driven decisions, learning continuously, and always putting the patient first.

HQ

Pomelo Care New York, New York, USA Office

New York, NY, United States

Similar Jobs

2 Days Ago
Easy Apply
Remote
United States
Easy Apply
225K-305K Annually
Senior level
225K-305K Annually
Senior level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Leads Motive’s global security compliance, privacy, risk, audit, customer trust, and AI governance functions. Builds integrated controls across ISO, SOC, PCI DSS, FedRAMP, GDPR, and related frameworks; manages audits, privacy operations, international regulatory readiness, customer security reviews, policies, training, and human risk. The role also establishes AI-first automation, AI governance, and a path to FedRAMP while leading a distributed team and partnering across Legal, Engineering, Product, IT, Finance, Sales, and Customer Success.
Top Skills: Ai GovernanceCcpaCloud-Native SaasContinuous Control MonitoringCpraData ResidencyEu Ai ActFedrampGdprIso 27001Iso 27701Iso/Iec 42001Law 25LgpdMexican LfpdpppNist Ai Risk Management FrameworkPci DssPipedaSoc 1Soc 2Trust Portals
One Month Ago
In-Office or Remote
New York, NY, USA
140-175 Annually
Senior level
140-175 Annually
Senior level
Artificial Intelligence • Legal Tech • Software
Lead and maintain ISO 27001 and SOC 2 programs, manage vendor security and VSQs, author policies, run risk assessments, coordinate audits and remediation, support engineering on control implementation, handle customer security questionnaires, run awareness and phishing programs, and drive automation of compliance workflows.
Top Skills: AWSAzureCis ControlsCloud IamCloudtrailDrataEncryption At RestEncryption In TransitEndpoint ManagementGCPGrc PlatformsIso 27001Logging And Monitoring PipelinesNist CsfSecureframeSIEMSoc 2Tugboat LogicVantaVsq
An Hour Ago
In-Office or Remote
New York, NY, USA
140K-170K Annually
Senior level
140K-170K Annually
Senior level
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
Manages multiple global regulatory and licensing programs from market-entry planning through approval. Builds plans, sequences dependencies, assigns owners, tracks risks, coordinates Legal, Compliance, Finance, Product, Engineering, and other teams, and prepares executive steering updates. Establishes scalable program standards, reporting metrics, and AI-enabled workflows while supporting policy activities and procurement. Requires regulatory or compliance experience in financial services, fintech, or another regulated industry, strong communication, discretion, and the ability to lead through influence.
Top Skills: AIApple MacosBlockchainChatgptClaudeGeminiGoogle SuiteSlackVibebox

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account