
About Modern Health
Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digital resources for their emotional, professional, social, financial, and physical well-being needs—all within a single platform. Whether someone wants to proactively manage stress or treat depression, Modern Health guides people to the right care at the right time. We empower companies to help all their employees be the best version of themselves, and believe in meeting people wherever they are in their mental health journey.
Modern Health is backed by investors like Kleiner Perkins, Founders Fund, John Doerr, Y Combinator, and Battery Ventures and raised more than $170 million in less than two years, making Modern Health the fastest entirely female-founded company in the U.S. to reach Unicorn status.
Our Culture
- “It Takes a Village” culture: Centered around high empathy and high accountability with a drive to win.
- An obsession to win: Highly ambitious and passionate about the work we do to continuously innovate for customers.
- Accountable and reliable: Committed to transparent communication and continuous feedback.
- Empathy in action: Supportive and diverse culture fostering a collaborative environment.
- Bias towards action: Empowering people to jump into problems, experiment, iterate, and initiate solutions.
Modern Health is a fully remote workforce. To protect our culture and help our team stay connected, we require overlapping hours. US-based team members living outside the Pacific time zone are expected to work at least six hours between 8:00 AM and 5:00 PM Pacific Time each workday.
The Role
Modern Health is scaling into enterprise and regulated clients—health plans, financial services, and global employers—whose trust depends on demonstrable information technology risk governance. Much of Modern Health's information technology risk and governance framework already exists (policies, vendor intake, access reviews, trust center, answer library, risk register, incident response, and tooling). This role provides senior ownership and oversight to establish and run cross-functional governance programs: connecting those assets into coherent, evidenced, enterprise-credible programs, and representing our posture to strategic clients, auditors, and assessors.
The Senior Director, Information Risk & Governance is the company’s second-line-of-defense leader for information technology risk: an independent risk, governance, and assurance function reporting to the General Counsel, deliberately separated from the teams that build, operate, and execute security and IT programs. The role partners closely with the Head of Security Engineering, who continues to run operational security execution, certification readiness, audit evidence production, and day-to-day customer security response workflows.
What You'll Do
- Information technology risk governance: Own the information-security risk register, a leadership-approved risk appetite and tolerance model, and the exception/risk-acceptance register. Drive cross-functionally ratified decision rights (RACI) for risk acceptance, questionnaires, incidents, vendor exceptions, and contractual security commitments. Deliver the monthly executive information-risk report, board reporting, and lead the information-risk and AI-risk workstream of the enterprise Risk Committee.
- Risk-balanced business prioritization: Balance risk and business imperative in partnership with business functions. Prioritize security reviews, resourcing, and remediation by business need and revenue impact; frame risk decisions as tradeoffs with recommendations; embed security engagement early in enterprise deals, product launches, and AI initiatives.
- AI governance program operations: Run the cross-functional AI governance program built with the Compliance & Privacy Officer: committee operations, enterprise intake (GAT), approved/restricted-use administration, AI vendor eligibility and BAA/DPA-chain requirements, coding-agent governance, product AI review gates, AI incident management, and customer-facing governance evidence.
- Incident management program: Own incident management as an enterprise program: unified severity thresholds, playbooks by incident type (security, privacy, provider/clinical, vendor), tabletop exercises, escalation paths, and post-incident corrective action tracking. Command cross-functional non-technical incidents.
- Data governance (security side): Drive management of data retention, deletion, classification, and data hosting/residency positions. Lead the data segregation program (PHI data map → designated record set (DRS) into the EMR → segregation of non-DRS PHI). Stand up the data governance decision forum.
- Certification & assurance programs: Provide second-line governance, program assistance, and risk escalation support for certification and assurance programs, including HITRUST, SOC 2, ISO 27001 readiness, and third-party HIPAA risk assessments.
- Third-party risk: Own the overall vendor risk program and risk-tiered assessment framework. Set minimum review standards, tiering rules, approval and exception paths, escalation criteria, reassessment cadence, and remediation expectations.
- Customer trust & enterprise assurance: Provide second-line review and risk calibration for customer security questionnaires, RFP security responses, trust-center materials, standard assurance packages, audit-right responses, and client-facing commitments.
- Policy & awareness: Own the information security and risk policy suite (Vanta-managed), annual review cycles, and risk awareness content.
Who You Are
- 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership, with 5+ years in a regulated, PHI-handling environment.
- Digital health, health plan, or healthcare services experience strongly preferred.
- Experience providing senior governance, oversight, or program leadership for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable frameworks.
- Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations. Familiarity with NIST AI RMF and emerging AI governance expectations preferred.
- Strong risk-decision judgment: able to distinguish technical control gaps from material enterprise risk and recommend when risk should be accepted, mitigated, escalated, or deferred.
- Proven track record partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams.
- Customer-facing credibility: comfortable engaging with strategic customer CISOs, security review teams, procurement risk teams, auditors, and assessors.
- Experience with third-party security risk programs and enterprise incident management program governance.
- Executive communication skills: ability to translate technical risk, certification status, and vendor risk into concise, decision-ready business terms for leadership and board audiences.
Timezone overlap
UTC-8–-4
Benefits
Equity, Commission, Health, Dental, Vision, Mental health, 401k, Parental leave, Learning, Wellness, Home office
Open to
US
Sign in to track applications and earn points.