Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Director of Security, GRC (Remote) image - Rise Careers
Job details

Director of Security, GRC (Remote)

Aledade is seeking a Director of Governance, Risk & Compliance (GRC) to lead and scale our enterprise GRC program. Reporting directly to the Chief Information Security Officer (CISO), this role is responsible for building out a cohesive framework for risk management, compliance, and certifications while ensuring that security, privacy, and governance practices align with regulatory, contractual, and audit expectations.


The Director will manage a growing team (currently two direct reports) and own Aledade’s risk program, GRC platforms (including Vanta), and policy framework. This leader will be accountable for driving compliance certifications (SOC 2, HIPAA, SOX/ITGC, HITRUST, CPRA), partnering across Security, IT, Product, and Legal to ensure evidence is ready for external audits, and ensuring governance enables both innovation and protection of sensitive patient data.



Primary Duties:
  • Build, lead, and continuously mature Aledade’s Governance, Risk & Compliance program.
  • Own and maintain the enterprise risk management framework and risk registry, facilitating reviews and reporting to leadership and the Audit Committee.
  • Lead Aledade’s compliance certification programs, including SOC 2, HIPAA, SOX/ITGC, HITRUST, and CPRA.
  • Manage audit preparedness and execution for external assessments, ensuring evidence collection and readiness across business and technology teams.
  • Oversee the Vanta Trust platform, including continuous control monitoring, automation of evidence gathering, and Trust Center management.
  • Develop and enforce policies and standards, ensuring clarity, adoption, and alignment with frameworks such as NIST, ISO 27001, HIPAA, and AI RMF.


Minimum Qualifications:
  • 10+ years of experience in Governance, Risk, and Compliance, Information Security, or related fields, with at least 5 years in leadership roles.
  • Strong knowledge of risk management frameworks and regulatory requirements, including SOC 2, HIPAA, SOX/ITGC, HITRUST, and CPRA.
  • Demonstrated experience preparing organizations for external audits and regulatory certifications.
  • Hands-on experience with GRC platforms (e.g., Vanta, OneTrust, Archer, or similar).
  • Proven ability to design and operationalize compliance programs, policies, and evidence frameworks at scale.
  • Excellent leadership, communication, and cross-functional collaboration skills.
  • Preferred: CISA, CISM, CRISC, or CISSP certifications.


Preferred Knowledge, Skills and/or Abilities:
  • Deep knowledge of GRC frameworks and regulations (SOC 2, HIPAA, SOX/ITGC, HITRUST, CPRA, NIST, ISO 27001).
  • Strong program management and audit readiness skills, including policy development, evidence collection, and external audit coordination.
  • Skilled in leveraging GRC platforms (e.g., Vanta, OneTrust) to automate compliance and streamline controls monitoring.
  • Proven leadership and people development abilities, with experience growing and mentoring high-performing teams.
  • Excellent collaboration and communication skills, with the ability to influence executives, engineers, and auditors.
  • Ability to balance compliance requirements with innovation, translating regulations into scalable, practical processes.


Who We Are:

Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place.


What Does This Mean for You?

At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission.


In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members:


Flexible work schedules and the ability to work remotely are available for many roles

Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners

Robust time-off plan (21 days of PTO in your first year)

Two paid volunteer days and 11 paid holidays

12 weeks paid parental leave for all new parents

Six weeks paid sabbatical after six years of service

Educational Assistant Program and Clinical Employee Reimbursement Program

401(k) with up to 4% match

Stock options

And much more!


At Aledade, we don’t just accept differences, we celebrate them! We strive to attract, develop and retain highly qualified individuals representing the diverse communities where we live and work. Aledade is committed to creating a diverse environment and is proud to be an equal opportunity employer. Employment policies and decisions at Aledade are based on merit, qualifications, performance and business needs. All qualified candidates will receive consideration for employment without regard to age, race, color, national origin, gender (including pregnancy, childbirth or medical conditions related to pregnancy or childbirth), gender identity or expression, religion, physical or mental disability, medical condition, legally protected genetic information, marital status, veteran status, or sexual orientation.


Privacy Policy: By applying for this job, you agree to Aledade's Applicant Privacy Policy available at  https://www.aledade.com/privacy-policy-applicants

Aledade Glassdoor Company Review
4.6 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Aledade DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Aledade
Aledade CEO photo
Farzad Mostashari
Approve of CEO

Average salary estimate

$200000 / YEARLY (est.)
min
max
$170000K
$230000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User

Help shape and operate Anchorage Digital’s transaction monitoring program by reviewing alerts, tuning detection rules, mentoring new hires, and ensuring regulatory compliance across institutional crypto activity.

Photo of the Rise User
KIND Hybrid New York City, NY
Posted 7 hours ago

KIND is hiring a Senior Paralegal to supervise paralegal staff and manage detained-child immigration casework, combining hands-on legal preparation, client contact, and programmatic oversight in New York City.

Photo of the Rise User

Lead and strengthen YMCA of Greenville’s risk, safety, and compliance programs as the Safety & Risk Management Director, ensuring safe operations across aquatics, youth programs, facilities, and volunteers.

Photo of the Rise User
Posted 2 hours ago

Experienced NY State–admitted attorney needed to advise NYCHA on Section 8 programs, regulatory compliance, policy development, and related legal matters.

Photo of the Rise User
Posted 19 hours ago

Experienced cybersecurity policy professional needed to lead policy development and strategic alignment across enterprise cybersecurity and privacy programs for a fast-growing, D.C.-area IT security firm (100% remote).

Posted 4 hours ago

Lead NJEDA’s COIL, EEO, and whistleblower compliance programs, conduct investigations, and advise staff and board members on ethics and regulatory matters in a hybrid full-time role.

Photo of the Rise User
Bosch Group Hybrid 38000 Hills Tech Dr, Farmington Hills, MI 48331, USA
Posted 3 hours ago

Bosch is hiring an Export Control Compliance Manager in Farmington Hills to lead US export control compliance, license management, and classification for North American operations.

Ibility Hybrid Gaithersburg
Posted 3 hours ago

Ibility seeks a Grants Auditor to lead field reviews of federal grant recipients and assess internal controls and compliance for VA grants programs such as GPD and the Sgt. Fox suicide prevention grants.

Photo of the Rise User

Serve the City of Fort Worth as an Assistant City Attorney I advising city departments on employment matters and representing the City in employment-related litigation and administrative proceedings.

Experienced bilingual (English/Spanish) litigation paralegal needed to provide full trial support and case management at a busy Miami Lakes personal injury firm.

Photo of the Rise User
AECOM Hybrid Sacramento, California, United States
Posted 3 hours ago

AECOM is hiring an Environmental Compliance Auditor to conduct construction-area audits, verify permit and regulatory conformance, and coordinate corrective actions for large infrastructure programs.

Photo of the Rise User
Imprint Hybrid San Francisco
Posted 2 hours ago

Imprint is hiring a Product Counsel to advise on regulatory, privacy, and product issues for its sponsor-bank credit card platform and help build the company’s legal function.

Photo of the Rise User
Posted 47 minutes ago

Commercial Counsel needed to support technology sales and commercial contracting across the Americas for a global data-integrity software company.

At the heart of the Aledade model is the simple, but radical, idea that Aledade only succeeds when partner practices succeed in lowering costs to payers through better care for patients. By keeping patients and their healthcare providers at the ce...

26 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
September 17, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!