Director of Security Compliance
Pomelo Care is hiring a Director of Security Compliance for a remote role open to applicants in United States. It pays $200k-$230k a year and Level rates it ; you can apply on Level.
AI in this role
Pomelo Care is the leading virtual medical practice for women and children, providing care across pregnancy, postpartum, pediatrics, menopause, and perimenopause. We combine proactive, 24/7 clinical care with technology that helps us reach patients earlier, identify risks sooner, and deliver personalized care throughout their journey. Our team includes clinicians, technologists, operators, and problem-solvers working together to make high-quality care more accessible for families nationwide.
About The Role:
We are looking for a Director of Security Compliance to lead our security governance, risk, and assurance strategy. Reporting to the Head of Compliance, you will be the primary architect of our security governance program and the most senior voice on security oversight, owning the roadmap for our HITRUST and SOC certification lifecycles.
This is a hands-on role: in partnership with the Head of Compliance, you will build and run our security compliance program. It is not a software engineering position. You will define our security standards, risk appetite, and compliance requirements, while our engineering team owns technical implementation. Your success will come from setting direction, influencing technical roadmaps, and holding the organization accountable to a security posture that protects our patients and enables the business to move fast.
What you’ll do:
Define and own the enterprise-wide security strategy and policy framework in partnership with our engineering team and help shape our security risk appetite across all of Pomelo Care.
Lead the full lifecycle for SOC 2 Type II and HITRUST certifications, managing external auditors and coordinating internal evidence collection.
Own day-to-day security compliance operations, including drafting and maintaining security policies and procedures, access control governance and periodic user access reviews, the annual HIPAA Security Risk Assessment, security awareness training, and ongoing control monitoring.
Serve as the security “Design Authority”: setting the governance standards that engineering’s security team builds to.
Partner as a peer with engineering leadership to ensure that technical roadmaps align with the enterprise security strategy.
Provide governance oversight for technical risk management, ensuring engineering-led solutions meet regulatory and contractual thresholds.
Act as the primary security point of contact for our health plan partners, leading security due diligence and representing our program during external audits and questionnaires.
Own the security assessment component of our Third-Party Risk Management program ensuring our vendors and partners meet our security and privacy requirements.
Own the Incident Response Plan, leading coordination, communication, and the compliance response while engineering handles technical containment and remediation.
Report regularly on security risk posture and program maturity to executive leadership.
What you’ll bring:
8+ years of experience in Information Security, with at least 3 years in a leadership or GRC-focused role, including direct experience in healthcare, and ideally in a high-growth startup environment.
Deep knowledge of HIPAA (particularly the Security Rule) and HITECH, and working knowledge of state privacy and security laws (CCPA/CPRA).
Proven track record personally leading successful SOC 2 and HITRUST (i1 or r2) certification cycles from readiness through audit.
Technical fluency. You won't be writing code, but you understand cloud environments (GCP preferred), CI/CD pipelines, and modern security tooling well enough to hold a detailed, credible conversation with the engineers who build them.
Exceptional communication skills, including the ability to translate complex security concepts into clear, practical guidance for executives, engineers, and business teams, and the ability to represent Pomelo’s security posture to sophisticated external health plan partners.
A pragmatic, business-forward approach to security: you right-size controls to actual risk, find paths to yes, and enable the business to move fast without compromising patient trust.
Strong project management skills, and a track record of driving cross-functional initiatives across the engineering, product, and operations teams to on-time completion.
Preferred certifications: CISSP, CISM, or CISA.
A collaborative mindset and a passion for our mission to improve maternal and infant health outcomes.
Compensation:
The expected base salary range offered for this role is $200,000-$230,000. This role is also eligible for equity, giving you an ownership stake in Pomelo’s mission. Actual compensation may vary based on relevant experience, skills, competencies, and certifications.
We are committed to hiring the best team to improve outcomes for all mothers and babies. To solve the complex challenges facing the diverse population we serve, we need diverse perspectives, actively welcoming people of all races, ages, sexual orientations, gender identities and expressions, national origins, religions, disabilities, and veteran statuses. We strive to cultivate an inclusive and respectful environment where team members thrive by working across disciplines, moving fast, making data driven decisions, learning continuously, and always putting the patient first.
How we rate this
Director of Security Compliance at Pomelo Care rates 37 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Get new remote security jobs by email
One email a week with the new remote security jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step