Modern Health is a mental health benefits platform for employers. We are the first global mental health solution to offer employees access to one-on-one, group, and self-serve digital resources for their emotional, professional, social, financial, and physical well-being needs—all within a single platform. Whether someone wants to proactively manage stress or treat depression, Modern Health guides people to the right care at the right time. We empower companies to help all their employees be the best version of themselves, and believe in meeting people wherever they are in their mental health journey.Modern Health is backed by investors like Kleiner Perkins, Founders Fund, John Doerr, Y Combinator, and Battery Ventures and raised more than $170 million in less than two years, making Modern Health the fastest entirely female-founded company in the U.S. to reach Unicorn status.“It Takes a Village” culture. Modern Health has a unique and unabashed culture centered around high empathy and high accountability - with a drive to win.We have an obsession to win. We are highly ambitious and passionate about the work that we do.We are accountable and can rely on each other. We are a team and hold ourselves and each other accountable.We demonstrate empathy. We have a supportive and diverse culture where we bolster and uplift each other as we pursue our lofty goals.We exhibit a bias towards action. This is a fast-paced environment.Modern Health is a fully remote workforce and a hyper-growth company that is often recognized for its excellence.To protect our culture and help our team stay connected, we require overlapping hours for everyone. While many roles may function from anywhere in the world—see individual job listing for more—US based team members who live outside the Pacific time zone are expected to work at least six hours between 8 am and 5 pm Pacific time each workday.The Senior Director, Information Risk & Governance is the company’s second-line-of-defense leader for information technology risk: an independent risk, governance, and assurance function reporting to the General Counsel, deliberately separated from the teams that build, operate, and execute security and IT programs. The role partners closely with the Head of Security Engineering.Much of Modern Health's information technology risk and governance framework already exists — policies, vendor intake, access reviews, a trust center, an answer library, a risk register, incident response, and incident tooling. What this role adds is the senior ownership and oversight to establish and run our cross-functional governance programs.The role:Modern Health is scaling into enterprise and regulated clients — health plans, financial services, and global employers — whose trust depends on demonstrable information technology risk governance.This role provides program governance, risk decision support, escalation, remediation-plan calibration, executive reporting, and client-facing support.What you'll do:Information technology risk governance. Own the information-security risk register, a leadership-approved risk appetite and tolerance model, and the exception/risk-acceptance register.Risk-balanced business prioritization. Coordinate and facilitate the balance between risk and business imperative.AI governance program operations. Run the cross-functional AI governance program built with the Compliance & Privacy Officer.Incident management program. Own incident management as an enterprise program.Data governance (security side). Drive management of the data retention and deletion program, the data classification program, and data hosting/residency positions.Certification & assurance programs. Provide second-line governance, program assistance, and risk escalation support for Modern Health’s certification and assurance programs.Third-party risk. Own the overall vendor risk program and risk-tiered assessment framework.Customer trust & enterprise assurance. Provide second-line review and risk calibration for customer security questionnaires, RFP security responses, trust-center materials, standard assurance packages, audit-right responses, and client-facing security commitments.Policy & awareness (information risk). Own the information security and risk policy suite (Vanta-managed), annual review cycle, and risk awareness content.Who you are/ Requirements:10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership, with 5+ years in a regulated, PHI-handling environment.Digital health, health plan, or healthcare services experience strongly preferred.Experience providing senior governance, oversight, or program leadership for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable security assurance frameworks.Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations.Strong risk-decision judgment: able to distinguish technical control gaps from material enterprise risk.Experience partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams to translate technical issues into business-ready decisions.Customer-facing credibility: comfortable engaging with strategic customer CISOs, security review teams, procurement risk teams, auditors, and assessors.Experience with third-party security risk programs, including vendor risk tiering, assessment standards, exception paths, remediation expectations, and alignment between vendor commitments and customer obligations.Experience with incident management program governance, including severity thresholds, escalation paths, playbook design, tabletop facilitation, corrective action tracking, and coordination with Legal and Privacy.Executive communication: translates technical risk, certification status, vendor risk, and customer assurance issues into concise, decision-ready business terms.Builder-integrator profile: able to take existing distributed processes and turn them into coherent, evidenced, repeatable programs.Relevant certifications preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.Immigration sponsorship is not available for this position.BenefitsFundamentals:Medical / Dental / Vision / Disability / Life InsuranceHigh Deductible Health Plan with Health Savings Account (HSA) optionFlexible Spending Account (FSA)Access to coaches and therapists through Modern Health's platformGenerous Time OffCompany-wide Collective Pause DaysFamily Support:Parental Leave PolicyFamily Forming Benefit through CarrotFamily Assistance Benefit through UrbanSitterProfessional Development:Professional Development StipendFinancial Wellness:401kFinancial Planning Benefit through OriginBut wait there’s more…!Annual Wellness Stipend to use on items that promote your overall well beingNew Hire Stipend to help cover work-from-home setup costsModSquad Community: Virtual events like active ERGs, holiday themed activities, team-building events and moreMonthly Cell Phone ReimbursementEqual Pay for Equal Work Act InformationPlease refer to the ranges below to find the starting annual pay range for individuals applying to work remotely from the following locations for this role.Zone 1: San Francisco Bay Area and New York City MetroZone 2: All other California locations and Seattle, WAZone 3: All other New York locations, All other Washington locations, Washington DC, Austin, TX, CT, IL, MA, NH, NJ, OR, RI, VTZone 4: All other Texas locations, AL, AK, AZ, AR, CO, DE, FL, GA, HI, ID, IN, IA, KS, KY, LA, ME, MD, MI, MN, MS, MO, MT, NE, NV, NM, NC, ND, OH, OK, PA, SC, SD, TN, UT, VA, WV, WI, WYDepending on the scope of the role, some ranges are indicative of On Target Earnings (OTE) and includes both base pay and commission at 100% achievement of established targets.