# Director of Security Compliance at Pomelo Care

Pomelo Care is hiring a Director of Security Compliance for a remote role open to applicants in United States. It pays $200k-$230k a year and Level rates it Little AI ●○○○; you can [apply on Level](https://jobsbylevel.com/go/4a02b1b5-170b-4692-95e7-d4c37f578c89).

AI Level 1, AI centrality 37 out of 100. Remote (United States).

## Details

- Company: [Pomelo Care](https://jobsbylevel.com/companies/pomelo-care)
- AI level: AI Level 1 (score 37 out of 100)
- Location: Remote (United States)
- Salary: $200k-$230k
- Posted: October 9, 2026
- Apply: https://jobsbylevel.com/go/4a02b1b5-170b-4692-95e7-d4c37f578c89

## Description

Pomelo Care is the leading virtual medical practice for women and children, providing care across pregnancy, postpartum, pediatrics, menopause, and perimenopause. We combine proactive, 24/7 clinical care with technology that helps us reach patients earlier, identify risks sooner, and deliver personalized care throughout their journey. Our team includes clinicians, technologists, operators, and problem-solvers working together to make high-quality care more accessible for families nationwide. About The Role: We are looking for a Director of Security Compliance to lead our security governance, risk, and assurance strategy. Reporting to the Head of Compliance, you will be the primary architect of our security governance program and the most senior voice on security oversight, owning the roadmap for our HITRUST and SOC certification lifecycles. This is a hands-on role: in partnership with the Head of Compliance, you will build and run our security compliance program. It is not a software engineering position. You will define our security standards, risk appetite, and compliance requirements, while our engineering team owns technical implementation. Your success will come from setting direction, influencing technical roadmaps, and holding the organization accountable to a security posture that protects our patients and enables the business to move fast. What you’ll do: Define and own the enterprise-wide security strategy and policy framework in partnership with our engineering team and help shape our security risk appetite across all of Pomelo Care. Lead the full lifecycle for SOC 2 Type II and HITRUST certifications, managing external auditors and coordinating internal evidence collection. Own day-to-day security compliance operations, including drafting and maintaining security policies and procedures, access control governance and periodic user access reviews, the annual HIPAA Security Risk Assessment, security awareness training, and ongoing control monitoring. Serve as the security “Design Authority”: setting the governance standards that engineering’s security team builds to. Partner as a peer with engineering leadership to ensure that technical roadmaps align with the enterprise security strategy. Provide governance oversight for technical risk management, ensuring engineering-led solutions meet regulatory and contractual thresholds. Act as the primary security point of contact for our health plan partners, leading security due diligence and representing our program during external audits and questionnaires. Own the security assessment component of our Third-Party Risk Management program ensuring our vendors and partners meet our security and privacy requirements. Own the Incident Response Plan, leading coordination, communication, and the compliance response while engineering handles technical containment and remediation. Report regularly on security risk posture and program maturity to executive leadership. What you’ll bring: 8+ years of experience in Information Security, with at least 3 years in a leadership or GRC-focused role, including direct experience in healthcare, and ideally in a high-growth startup environment. Deep knowledge of HIPAA (particularly the Security Rule) and HITECH, and working knowledge of state privacy and security laws (CCPA/CPRA). Proven track record personally leading successful SOC 2 and HITRUST (i1 or r2) certification cycles from readiness through audit. Technical fluency. You won't be writing code, but you understand cloud environments (GCP preferred), CI/CD pipelines, and modern security tooling well enough to hold a detailed, credible conversation with the engineers who build them. Exceptional communication skills, including the ability to translate complex security concepts into clear, practical guidance for executives, engineers, and business teams, and the ability to represent Pomelo’s security posture to sophisticated external health plan partners. A pragmatic, business-forward

The description is cut here. Read the full offer: https://jobsbylevel.com/jobs/director-of-security-compliance-at-pomelo-care-fa057d

Source: https://jobsbylevel.com/jobs/director-of-security-compliance-at-pomelo-care-fa057d

## Cite this page

Level. https://jobsbylevel.com/jobs/director-of-security-compliance-at-pomelo-care-fa057d.

Get job alerts: https://jobsbylevel.com/newsletter
