The Senior Director, Information Risk & Governance is the company's second-line-of-defense leader for information technology risk: an independent risk, governance, and assurance function reporting to ...
The Senior Director, Information Risk & Governance is the company's second-line-of-defense leader for information technology risk: an independent risk, governance, and assurance function reporting to ...
Director-Information Technology - Manufacturing IT systems
Chicago, IL · On-site
$187K - $248K/yr
The Director - Information Technology oversees specific functions within the IT department ... Collaborate with other IT teams, such as Information Risk Management, to ensure comprehensive ...
Director-Information Technology - Manufacturing IT systems
Chicago, IL · On-site
$187K - $248K/yr
The Director - Information Technology oversees specific functions within the IT department ... Collaborate with other IT teams, such as Information Risk Management, to ensure comprehensive ...
Head of Information Risk
Richardson, TX · On-site
For more information about joining our team, please visit us at www.texascapitalbank.com. Brief ... Report key risks and metrics to the Board of Directors and the Enterprise Risk Committee. Oversee ...
Head of Information Risk
Richardson, TX · On-site
For more information about joining our team, please visit us at www.texascapitalbank.com. Brief ... Report key risks and metrics to the Board of Directors and the Enterprise Risk Committee. Oversee ...
The Senior Director, Information Risk & Governance is the company's second-line-of-defense leader for information technology risk: an independent risk, governance, and assurance function reporting to ...
The Senior Director, Information Risk & Governance is the company's second-line-of-defense leader for information technology risk: an independent risk, governance, and assurance function reporting to ...
Head of Information Risk
Richardson, TX · On-site
For more information about joining our team, please visit us at www.texascapitalbank.com. Brief ... Directors for cybersecurity, data privacy, risk management, and regulatory compliance. The CIRO ...
Head of Information Risk
Richardson, TX · On-site
For more information about joining our team, please visit us at www.texascapitalbank.com. Brief ... Directors for cybersecurity, data privacy, risk management, and regulatory compliance. The CIRO ...
Head of Information Risk (Dallas)
Dallas, TX · On-site
For more information about joining our team, please visit us at www.texascapitalbank.com. Brief ... Report key risks and metrics to the Board of Directors and the Enterprise Risk Committee. * Oversee ...
New
Head of Information Risk (Dallas)
Dallas, TX · On-site
For more information about joining our team, please visit us at www.texascapitalbank.com. Brief ... Report key risks and metrics to the Board of Directors and the Enterprise Risk Committee. * Oversee ...
New
Director, Information Security
Manhattan, NY · On-site
Director, Information Security will provide strategic and operational leadership for enterprise ... Responsibilities will also encompass security and Risk Management Framework (RMF) focused ...
Director, Information Security
Manhattan, NY · On-site
Director, Information Security will provide strategic and operational leadership for enterprise ... Responsibilities will also encompass security and Risk Management Framework (RMF) focused ...
Director Information Technology
Braintree, MA · On-site
$180K - $220K/yr
The Director of Information Technology leads the company's IT strategy, operations, infrastructure ... Cybersecurity & Information Risk Management * Develop and maintain the company's cybersecurity ...
Director Information Technology
Braintree, MA · On-site
$180K - $220K/yr
The Director of Information Technology leads the company's IT strategy, operations, infrastructure ... Cybersecurity & Information Risk Management * Develop and maintain the company's cybersecurity ...
Director, Information Security
Manhattan, NY · On-site
Director, Information Security will provide strategic and operational leadership for enterprise ... Responsibilities will also encompass security and Risk Management Framework (RMF) focused ...
Director, Information Security
Manhattan, NY · On-site
Director, Information Security will provide strategic and operational leadership for enterprise ... Responsibilities will also encompass security and Risk Management Framework (RMF) focused ...
The Director of Information Technology leads the company's IT strategy, operations, infrastructure ... Cybersecurity & Information Risk Management * Develop and maintain the company's cybersecurity ...
The Director of Information Technology leads the company's IT strategy, operations, infrastructure ... Cybersecurity & Information Risk Management * Develop and maintain the company's cybersecurity ...
Director Information Technology
Braintree, MA · On-site
The Director of Information Technology leads the company's IT strategy, operations, infrastructure ... Cybersecurity & Information Risk Management * Develop and maintain the company's cybersecurity ...
Director Information Technology
Braintree, MA · On-site
The Director of Information Technology leads the company's IT strategy, operations, infrastructure ... Cybersecurity & Information Risk Management * Develop and maintain the company's cybersecurity ...
Director IT Embedded Risk
Jersey City, NJ · On-site
Being a member of IT FinSight Delivery team, a IT ERM Director has primary responsibility for supporting and conducting targeted IT risk assessments, managing the risk profile of aligned IT ...
Director IT Embedded Risk
Jersey City, NJ · On-site
Being a member of IT FinSight Delivery team, a IT ERM Director has primary responsibility for supporting and conducting targeted IT risk assessments, managing the risk profile of aligned IT ...
Director, Information Security
Manhattan, NY · On-site
$150K/yr
Director, Information Security will provide strategic and operational leadership for enterprise ... Responsibilities will also encompass security and Risk Management Framework (RMF) focused ...
Director, Information Security
Manhattan, NY · On-site
$150K/yr
Director, Information Security will provide strategic and operational leadership for enterprise ... Responsibilities will also encompass security and Risk Management Framework (RMF) focused ...
Director Information Technology
Braintree, MA · On-site
$180K - $220K/yr
The Director of Information Technology leads the company's IT strategy, operations, infrastructure ... Cybersecurity & Information Risk Management * Develop and maintain the company's cybersecurity ...
Director Information Technology
Braintree, MA · On-site
$180K - $220K/yr
The Director of Information Technology leads the company's IT strategy, operations, infrastructure ... Cybersecurity & Information Risk Management * Develop and maintain the company's cybersecurity ...
Director IT Embedded Risk
Jersey City, NJ · Hybrid
Being a member of IT FinSight Delivery team, a IT ERM Director has primary responsibility for supporting and conducting targeted IT risk assessments, managing the risk profile of aligned IT ...
Director IT Embedded Risk
Jersey City, NJ · Hybrid
Being a member of IT FinSight Delivery team, a IT ERM Director has primary responsibility for supporting and conducting targeted IT risk assessments, managing the risk profile of aligned IT ...
$112K - $236K/yr
Every day, we rise to the challenge to make a difference and here's how the Director, Information Security Governance Risk Compliance role will make an impact: Position Overview The primary purpose ...
$112K - $236K/yr
Every day, we rise to the challenge to make a difference and here's how the Director, Information Security Governance Risk Compliance role will make an impact: Position Overview The primary purpose ...
Director, Information Security Governance Risk Compliance
$112K - $236K/yr
Every day, we rise to the challenge to make a difference and here's how the Director, Information Security Governance Risk Compliance role will make an impact: The primary purpose of the Director ...
Director, Information Security Governance Risk Compliance
$112K - $236K/yr
Every day, we rise to the challenge to make a difference and here's how the Director, Information Security Governance Risk Compliance role will make an impact: The primary purpose of the Director ...
Director, Information Security Governance Risk Compliance
$112K - $236K/yr
Every day, we rise to the challenge to make a difference and here's how the Director, Information Security Governance Risk Compliance role will make an impact: The primary purpose of the Director ...
Director, Information Security Governance Risk Compliance
$112K - $236K/yr
Every day, we rise to the challenge to make a difference and here's how the Director, Information Security Governance Risk Compliance role will make an impact: The primary purpose of the Director ...
Sr. Manager, Information Security
Santa Clara, CA · On-site
$190K - $240K/yr
Description Director, Information Security We are seeking a highly skilled and experienced Security ... Establish and manage Cybersecurity / Information Risk Management practices within the organization.
Sr. Manager, Information Security
Santa Clara, CA · On-site
$190K - $240K/yr
Description Director, Information Security We are seeking a highly skilled and experienced Security ... Establish and manage Cybersecurity / Information Risk Management practices within the organization.
Senior Director, IT Security
Greenville, SC · On-site
Through advanced analytics and technology, we can more accurately predict credit risk and provide ... The Senior Director, IT Security is responsible for the development, implementation, and oversight ...
Senior Director, IT Security
Greenville, SC · On-site
Through advanced analytics and technology, we can more accurately predict credit risk and provide ... The Senior Director, IT Security is responsible for the development, implementation, and oversight ...
Director Information Risk information
See salary details
$54K - $72.7K
6% of jobs
$72.7K - $91.5K
6% of jobs
$104.9K is the 25th percentile. Wages below this are outliers.
$91.5K - $110.2K
17% of jobs
$110.2K - $128.9K
16% of jobs
The median wage is $132.3K / yr.
$128.9K - $147.6K
23% of jobs
$157.9K is the 75th percentile. Wages above this are outliers.
$147.6K - $166.4K
11% of jobs
$166.4K - $185.1K
6% of jobs
$185.1K - $203.8K
4% of jobs
$203.8K - $222.5K
4% of jobs
$222.5K - $241.3K
2% of jobs
$241.3K - $260K
3% of jobs
$54K
$143.2K
$260K
How much do director information risk jobs pay per year?
What cities are hiring for Director Information Risk jobs?
Cities with the most Director Information Risk job openings:
What are the most commonly searched types of Information Risk jobs?
The most popular types of Information Risk jobs are:
What are popular job titles related to Director Information Risk jobs?
For Director Information Risk jobs, the most frequently searched job titles are:

Senior Director of Information Risk & Governance
Remote
Full-time
Medical, Dental, Vision, Life, Retirement
Posted 29 days ago
Job description
Modern Health is scaling into enterprise and regulated clients - health plans, financial services, and global employers - whose trust depends on demonstrable information technology risk governance. Much of Modern Health's information technology risk and governance framework already exists - policies, vendor intake, access reviews, a trust center, an answer library, a risk register, incident response, and incident tooling. What this role adds is the senior ownership and oversight to establish and run our cross-functional governance programs: connecting those assets into coherent, evidenced, enterprise-credible programs, and representing our posture to strategic clients, auditors, and assessors.
The Senior Director, Information Risk & Governance is the company's second-line-of-defense leader for information technology risk: an independent risk, governance, and assurance function reporting to the General Counsel, deliberately separated from the teams that build, operate, and execute security and IT programs. The role partners closely with the Head of Security Engineering, who continues to run operational security execution, certification readiness, audit evidence production, and day-to-day customer security response workflows. This role provides program governance, risk decision support, escalation, remediation-plan calibration, executive reporting, and client-facing support.
What you'll do:- Information technology risk governance. Own the information-security risk register, a leadership-approved risk appetite and tolerance model, and the exception/risk-acceptance register. Drive cross-functionally ratified decision rights (RACI) for risk acceptance, questionnaires, incidents, vendor exceptions, and contractual security commitments. Deliver the monthly executive information-risk report and periodic board reporting, and own the information-risk and AI-risk workstream of the enterprise Risk Committee (chaired by the Compliance & Privacy Officer).
- Risk-balanced business prioritization. Coordinate and facilitate the balance between risk and business imperative, in partnership with business functions: prioritize security reviews, resourcing, and remediation by business need and revenue impact; frame risk decisions as tradeoffs with recommendations; and embed security engagement points early in enterprise deals, product launches, and AI initiatives so risk work accelerates the business rather than gates it.
- AI governance program operations. Run the cross-functional AI governance program built with the Compliance & Privacy Officer, who retains AI policy content and legal counsel: committee operations, intake (GAT) at enterprise scale, approved/restricted-use administration, AI vendor eligibility and BAA/DPA-chain requirements, coding-agent governance, product AI review gates, AI incident management, and customer-facing AI governance evidence.
- Incident management program. Own incident management as an enterprise program: unified severity thresholds, playbooks by incident type (security, privacy, provider/clinical, vendor), tabletop exercises, escalation paths and leadership notification standards, and post-incident corrective action tracking. Commands cross-functional non-technical incidents. Security engineering serves as technical incident commander for cyber incidents; the Compliance & Privacy Officer retains investigations program, privacy breach determinations and regulator/individual notification decisions.
- Data governance (security side). Drive management of the data retention and deletion program, the data classification program, and data hosting/residency positions - and lead the data segregation program (PHI data map designated record set (DSR) into the EMR segregation of non-DRS PHI) as a critical-path priority that gates AI capability and shrinks the certification boundary. Partner with Security Engineering, IT, and Data on implementation and with the privacy team on privacy positions. Stand up the data governance decision forum.
- Certification & assurance programs. Provide second-line governance, program assistance, and risk escalation support for Modern Health's certification and assurance programs, including HITRUST, SOC 2, ISO 27001 readiness, and third-party HIPAA risk assessments. The Head of Security Engineering owns day-to-day program execution, control operation, evidence production, auditor walkthrough support, and remediation execution. This role partners with the Head of Security Engineering on certification strategy, scope, prioritization, risk decisions, findings, remediation plans, exception requests, executive visibility, and customer-facing assurance positions.
- Third-party risk. Own the overall vendor risk program and risk-tiered assessment framework. Set minimum review standards, risk-tiering rules, approval and exception paths, escalation criteria, reassessment cadence, remediation expectations, and customer-commitment alignment. Ensure Modern Health is consistently assessing vendors against the right risks, applying the right level of review, and escalating material vendor risk decisions through the appropriate governance path.
- Customer trust & enterprise assurance. Provide second-line review and risk calibration for customer security questionnaires, RFP security responses, trust-center materials, standard assurance packages, audit-right responses, and client-facing security commitments. Security owns the day-to-day response process, answer-library content, technical inputs, and evidence production. This role reviews higher-risk responses and non-standard positions, helps calibrate commitments against Modern Health's actual control environment and risk appetite, and interfaces directly with strategic customer information-risk and security teams.
- Policy & awareness (information risk). Own the information security and risk policy suite (Vanta-managed), annual review cycle, and risk awareness content - coordinated with, not duplicative of, the compliance training program.
- 10+ years in information-security risk management, security governance, assurance, GRC, or security program leadership, with 5+ years in a regulated, PHI-handling environment.
- Digital health, health plan, or healthcare services experience strongly preferred.
- Experience providing senior governance, oversight, or program leadership for SOC 2, HITRUST, HIPAA Security risk assessments, ISO 27001 readiness, or comparable security assurance frameworks. Direct execution experience is valuable, but this role requires the judgment to guide scope, findings, remediation plans, evidence strategy, and risk escalation in partnership with Security.
- Deep working knowledge of HIPAA Security Rule, NIST CSF 2.0, SOC 2, HITRUST, third-party risk frameworks, and customer security assurance expectations. Familiarity with NIST AI RMF and emerging AI governance expectations preferred.
- Strong risk-decision judgment: able to distinguish technical control gaps from material enterprise risk, calibrate remediation plans against customer commitments and business priorities, and recommend when risk should be accepted, mitigated, escalated, or deferred.
- Experience partnering with Security, IT, Legal, Privacy, Compliance, Sales, Procurement, and Product teams to translate technical issues into business-ready decisions, executive reporting, customer commitments, and audit-ready evidence.
- Customer-facing credibility: comfortable engaging with strategic customer CISOs, security review teams, procurement risk teams, auditors, and assessors, especially when responses require risk calibration or senior escalation.
- Experience with third-party security risk programs, including vendor risk tiering, assessment standards, exception paths, remediation expectations, and alignment between vendor commitments and customer obligations.
- Experience with incident management program governance, including severity thresholds, escalation paths, playbook design, tabletop facilitation, corrective action tracking, and coordination with Legal and Privacy on notification-related decision points.
- Executive communication: translates technical risk, certification status, vendor risk, and customer assurance issues into concise, decision-ready business terms for executive team and board audiences.
- Builder-integrator profile: able to take existing distributed processes, including security tickets, vendor intake, trust-center content, answer libraries, risk registers, audit evidence, and policy suites, and turn them into coherent, evidenced, repeatable programs.
- Relevant certifications preferred: CISM, CRISC, CISSP, CISA, CIPP/US, HITRUST CCSFP, or similar.
- Immigration sponsorship is not available for this position. Applicants must be able to maintain work authorization for the duration of employment without employer sponsorship or employer-provided training plans or attestations (including, for example, the Form I-983 required for STEM OPT).
Fundamentals:
- Medical / Dental / Vision / Disability / Life InsuranceÂ
- High Deductible Health Plan with Health Savings Account (HSA) option
- Flexible Spending Account (FSA)
- Access to coaches and therapists through Modern Health's platform
- Generous Time OffÂ
- Company-wide Collective Pause DaysÂ
Family Support:
- Parental Leave PolicyÂ
- Family Forming Benefit through Carrot
- Family Assistance Benefit through UrbanSitter
Professional Development:
- Professional Development Stipend
Financial Wellness:
- 401k
- Financial Planning Benefit through Origin
But wait there's more...!Â
- Annual Wellness Stipend to use on items that promote your overall well beingÂ
- New Hire Stipend to help cover work-from-home setup costs
- ModSquad Community: Virtual events like active ERGs, holiday themed activities, team-building events and more
- Monthly Cell Phone Reimbursement
About Modern Health
Sourced by ZipRecruiter
Industry
Offices of mental health practitioners
Company size
51 - 200 Employees
Headquarters location
San Francisco, CA, US
Year founded
2017