Pomelo Care Logo

Pomelo Care

Director of Security Compliance

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
200K-230K Annually
Senior level
Remote
Hiring Remotely in United States
200K-230K Annually
Senior level
Lead Pomelo Care’s enterprise security governance, risk, and compliance program. Own SOC 2 Type II and HITRUST certification lifecycles, security policies, access governance, HIPAA risk assessments, awareness training, control monitoring, incident response, and third-party risk assessments. Partner with engineering leadership to align technical roadmaps with security strategy, represent the company during audits and partner due diligence, and report security posture and program maturity to executives.
The summary above was generated by AI

Pomelo Care is the leading virtual medical practice for women and children, providing care across pregnancy, postpartum, pediatrics, menopause, and perimenopause. We combine proactive, 24/7 clinical care with technology that helps us reach patients earlier, identify risks sooner, and deliver personalized care throughout their journey. Our team includes clinicians, technologists, operators, and problem-solvers working together to make high-quality care more accessible for families nationwide.

About The Role:

We are looking for a Director of Security Compliance to lead our security governance, risk, and assurance strategy. Reporting to the Head of Compliance, you will be the primary architect of our security governance program and the most senior voice on security oversight, owning the roadmap for our HITRUST and SOC certification lifecycles.

This is a hands-on role: in partnership with the Head of Compliance, you will build and run our security compliance program. It is not a software engineering position. You will define our security standards, risk appetite, and compliance requirements, while our engineering team owns technical implementation. Your success will come from setting direction, influencing technical roadmaps, and holding the organization accountable to a security posture that protects our patients and enables the business to move fast.

What you’ll do:

  • Define and own the enterprise-wide security strategy and policy framework in partnership with our engineering team and help shape our security risk appetite across all of Pomelo Care.

  • Lead the full lifecycle for SOC 2 Type II and HITRUST certifications, managing external auditors and coordinating internal evidence collection.

  • Own day-to-day security compliance operations, including drafting and maintaining security policies and procedures, access control governance and periodic user access reviews, the annual HIPAA Security Risk Assessment, security awareness training, and ongoing control monitoring.

  • Serve as the security “Design Authority”: setting the governance standards that engineering’s security team builds to.

  • Partner as a peer with engineering leadership to ensure that technical roadmaps align with the enterprise security strategy.

  • Provide governance oversight for technical risk management, ensuring engineering-led solutions meet regulatory and contractual thresholds.

  • Act as the primary security point of contact for our health plan partners, leading security due diligence and representing our program during external audits and questionnaires.

  • Own the security assessment component of our Third-Party Risk Management program ensuring our vendors and partners meet our security and privacy requirements.

  • Own the Incident Response Plan, leading coordination, communication, and the compliance response while engineering handles technical containment and remediation.

  • Report regularly on security risk posture and program maturity to executive leadership.

What you’ll bring:

  • 8+ years of experience in Information Security, with at least 3 years in a leadership or GRC-focused role, including direct experience in healthcare, and ideally in a high-growth startup environment.

  • Deep knowledge of HIPAA (particularly the Security Rule) and HITECH, and working knowledge of state privacy and security laws (CCPA/CPRA).

  • Proven track record personally leading successful SOC 2 and HITRUST (i1 or r2) certification cycles from readiness through audit.

  • Technical fluency. You won't be writing code, but you understand cloud environments (GCP preferred), CI/CD pipelines, and modern security tooling well enough to hold a detailed, credible conversation with the engineers who build them.

  • Exceptional communication skills, including the ability to translate complex security concepts into clear, practical guidance for executives, engineers, and business teams, and the ability to represent Pomelo’s security posture to sophisticated external health plan partners.

  • A pragmatic, business-forward approach to security: you right-size controls to actual risk, find paths to yes, and enable the business to move fast without compromising patient trust.

  • Strong project management skills, and a track record of driving cross-functional initiatives across the engineering, product, and operations teams to on-time completion.

  • Preferred certifications: CISSP, CISM, or CISA.

  • A collaborative mindset and a passion for our mission to improve maternal and infant health outcomes.

Compensation:

The expected base salary range offered for this role is $200,000-$230,000. This role is also eligible for equity, giving you an ownership stake in Pomelo’s mission. Actual compensation may vary based on relevant experience, skills, competencies, and certifications.

We are committed to hiring the best team to improve outcomes for all mothers and babies. To solve the complex challenges facing the diverse population we serve, we need diverse perspectives, actively welcoming people of all races, ages, sexual orientations, gender identities and expressions, national origins, religions, disabilities, and veteran statuses. We strive to cultivate an inclusive and respectful environment where team members thrive by working across disciplines, moving fast, making data driven decisions, learning continuously, and always putting the patient first.

Similar Jobs

2 Days Ago
Easy Apply
Remote
United States
Easy Apply
225K-305K Annually
Senior level
225K-305K Annually
Senior level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Leads Motive’s global security compliance, privacy, risk, audit, customer trust, and AI governance functions. Builds integrated controls across ISO, SOC, PCI DSS, FedRAMP, GDPR, and related frameworks; manages audits, privacy operations, international regulatory readiness, customer security reviews, policies, training, and human risk. The role also establishes AI-first automation, AI governance, and a path to FedRAMP while leading a distributed team and partnering across Legal, Engineering, Product, IT, Finance, Sales, and Customer Success.
Top Skills: Ai GovernanceCcpaCloud-Native SaasContinuous Control MonitoringCpraData ResidencyEu Ai ActFedrampGdprIso 27001Iso 27701Iso/Iec 42001Law 25LgpdMexican LfpdpppNist Ai Risk Management FrameworkPci DssPipedaSoc 1Soc 2Trust Portals
One Month Ago
In-Office or Remote
140-175 Annually
Senior level
140-175 Annually
Senior level
Artificial Intelligence • Legal Tech • Software
Lead and maintain ISO 27001 and SOC 2 programs, manage vendor security and VSQs, author policies, run risk assessments, coordinate audits and remediation, support engineering on control implementation, handle customer security questionnaires, run awareness and phishing programs, and drive automation of compliance workflows.
Top Skills: AWSAzureCis ControlsCloud IamCloudtrailDrataEncryption At RestEncryption In TransitEndpoint ManagementGCPGrc PlatformsIso 27001Logging And Monitoring PipelinesNist CsfSecureframeSIEMSoc 2Tugboat LogicVantaVsq
27 Minutes Ago
Remote or Hybrid
55K-75K Annually
Junior
55K-75K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handles inbound calls and warm leads, consults customers on insurance needs, recommends appropriate Property and Casualty coverage, and converts prospects into policyholders. The role includes paid licensing and training, customer communication, sales closing, and adherence to remote-work requirements. Employees must work four weekdays and one weekend day, maintain a dedicated home workspace, and remain in their resident state for at least one year due to licensing restrictions.
Top Skills: Cable InternetDsl InternetFiber InternetPcWired High-Speed Internet

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account