
Director of Security, GRC
Aledade, Inc.
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
Job Level
About the role
- Build, lead, and continuously mature Aledade’s Governance, Risk & Compliance program.
- Own and maintain the enterprise risk management framework and risk registry, facilitating reviews and reporting to leadership and the Audit Committee.
- Lead Aledade’s compliance certification programs, including SOC 2, HIPAA, SOX/ITGC, HITRUST, and CPRA.
- Manage audit preparedness and execution for external assessments, ensuring evidence collection and readiness across business and technology teams.
- Oversee the Vanta Trust platform, including continuous control monitoring, automation of evidence gathering, and Trust Center management.
- Develop and enforce policies and standards, ensuring clarity, adoption, and alignment with frameworks such as NIST, ISO 27001, HIPAA, and AI RMF.
Requirements
- 10+ years of experience in Governance, Risk, and Compliance, Information Security, or related fields, with at least 5 years in leadership roles.
- Strong knowledge of risk management frameworks and regulatory requirements, including SOC 2, HIPAA, SOX/ITGC, HITRUST, and CPRA.
- Demonstrated experience preparing organizations for external audits and regulatory certifications.
- Hands-on experience with GRC platforms (e.g., Vanta, OneTrust, Archer, or similar).
- Proven ability to design and operationalize compliance programs, policies, and evidence frameworks at scale.
- Excellent leadership, communication, and cross-functional collaboration skills.
- Preferred: CISA, CISM, CRISC, or CISSP certifications.
Benefits
- Flexible work schedules and the ability to work remotely are available for many roles
- Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners
- Robust time-off plan (21 days of PTO in your first year)
- Two paid volunteer days and 11 paid holidays
- 12 weeks paid parental leave for all new parents
- Six weeks paid sabbatical after six years of service
- Educational Assistant Program and Clinical Employee Reimbursement Program
- 401(k) with up to 4% match
- Stock options
- And much more!
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
GovernanceRisk ManagementComplianceAudit PreparednessEvidence CollectionPolicy DevelopmentControl MonitoringRegulatory CertificationsRisk FrameworksExternal Audits
Soft Skills
LeadershipCommunicationCross-functional Collaboration
Certifications
CISACISMCRISCCISSP