← all jobs

Director of Security, GRC (Remote)

Work from home Full-time role Hiring

Aledade is seeking a Director of Governance, Risk & Compliance (GRC) to lead and scale our enterprise GRC program. Reporting directly to the Chief Information Security Officer (CISO), this role is responsible for building out a cohesive framework for risk management, compliance, and certifications while ensuring that security, privacy, and governance practices align with regulatory, contractual, and audit expectations. The Director will manage a growing team (currently two direct reports) and own Aledade’s risk program, GRC platforms (including Vanta), and policy framework. This leader will be accountable for driving compliance certifications (SOC 2, HIPAA, SOX/ITGC, HITRUST, CPRA), partnering across Security, IT, Product, and Legal to ensure evidence is ready for external audits, and ensuring governance enables both innovation and protection of sensitive patient data. Primary Duties:

  • Build, lead, and continuously mature Aledade’s Governance, Risk & Compliance program.
  • Own and maintain the enterprise risk management framework and risk registry, facilitating reviews and reporting to leadership and the Audit Committee.
  • Lead Aledade’s compliance certification programs, including SOC 2, HIPAA, SOX/ITGC, HITRUST, and CPRA.
  • Manage audit preparedness and execution for external assessments, ensuring evidence collection and readiness across business and technology teams.
  • Oversee the Vanta Trust platform, including continuous control monitoring, automation of evidence gathering, and Trust Center management.
  • Develop and enforce policies and standards, ensuring clarity, adoption, and alignment with frameworks such as NIST, ISO 27001, HIPAA, and AI RMF.

Minimum Qualifications:

  • 10+ years of experience in Governance, Risk, and Compliance, Information Security, or related fields, with at least 5 years in leadership roles.
  • Strong knowledge of risk management frameworks and regulatory requirements, including SOC 2, HIPAA, SOX/ITGC, HITRUST, and CPRA.
  • Demonstrated experience preparing organizations for external audits and regulatory certifications.
  • Hands-on experience with GRC platforms (e.g., Vanta, OneTrust, Archer, or similar).
  • Proven ability to design and operationalize compliance programs, policies, and evidence frameworks at scale.
  • Excellent leadership, communication, and cross-functional collaboration skills.
  • Preferred: CISA, CISM, CRISC, or CISSP certifications.

Preferred Knowledge, Skills and/or Abilities:

  • Deep knowledge of GRC frameworks and regulations (SOC 2, HIPAA, SOX/ITGC, HITRUST, CPRA, NIST, ISO 27001).
  • Strong program management and audit readiness skills, including policy development, evidence collection, and external audit coordination.
  • Skilled in leveraging GRC platforms (e.g., Vanta, OneTrust) to automate compliance and streamline controls monitoring.
  • Proven leadership and people development abilities, with experience growing and mentoring high-performing teams.
  • Excellent collaboration and communication skills, with the ability to influence executives, engineers, and auditors.
  • Ability to balance compliance requirements with innovation, translating regulations into scalable, practical processes.

Who We Are: Aledade, a public benefit corporation, exists to empower the most transformational part of our health care landscape - independent primary care. We were founded in 2014, and since then, we've become the largest network of independent primary care in the country - helping practices, health centers and clinics deliver better care to their patients and thrive in value-based care. Additionally, by creating value-based contracts across a wide variety of health plans, we aim to flip the script on the traditional fee-for-service model. Our work strengthens continuity of care, aligns incentives and ensures primary care physicians are paid for what they do best - keeping patients healthy. If you want to help create a health care system that is good for patients, good for practices and good for society - and if you're eager to join a collaborative, inclusive and remote-first culture - you've come to the right place. What Does This Mean for You? At Aledade, you will be part of a creative culture that is driven by a passion for tackling complex issues with respect, open-mindedness and a desire to learn. You will collaborate with team members who bring a wide range of experiences, interests, backgrounds, beliefs and achievements to their work - and who are all united by a shared passion for public health and a commitment to the Aledade mission. In addition to time off to support work-life balance and enjoyment, we offer the following comprehensive benefits package designed for the overall well-being of our team members: Flexible work schedules and the ability to work remotely are available for many roles Health, dental and vision insurance paid up to 80% for employees, dependents and domestic partners Robust time-off plan (21 days of PTO in your first year) Two paid

More open positions

Cybersecurity Engineer III - Governance, Risk & Compliance (ServiceNow GRC Developer)

Work from home Full-time role

Senior Governance, Risk and Compliance Analyst - Governance / GRC Remote - Netherlands

Work from home Full-time role

GRC Analyst

Work from home Full-time role

GRC Analyst at Suzy Remote

Work from home Full-time role

[Remote] GRC Analyst / Multi-Tenant Access Control & Role Governance Analyst

Work from home Full-time role

Underwriter Sr - Remote

Work from home Full-time role

Remote Client Account Rep

Work from home Full-time role

Virtual Speech Language Pathologist (SLP) Job in Schools

Work from home Full-time role

Associate Attorney - Employment

Work from home Full-time role

Territory Manager Salon Beauty

Work from home Full-time role

Talent Acquisition Specialist (1099 Contractor)

Work from home Full-time role

[Remote] Account Executive- Strategic- North Central

Work from home Full-time role

Admin Support Specialist

Work from home Full-time role

[Remote] Data Analyst I - Data Visualization Specialist (REMOTE)

Work from home Full-time role

Remote Customer Service Representative – Debt Resolution Client Success Specialist (Bilingual Spanish a Plus)

Work from home Full-time role

Cash Impact at Scale Strategy Consultant

Work from home Full-time role

[Remote] Technical Operations & AI Automation Specialist

Work from home Full-time role

AI Security Engineer

Work from home Full-time role

Senior AI Vertical Mini-Series Director (Freelance - Full Remote - Puerto Rico)

Work from home Full-time role

Customer Service Representative – Frontline Policyholder Support & Solutions Specialist – careerzynith North Liberty, IA

Work from home Full-time role

[Remote] eBilling Analyst - Remote (Legal Services)

Work from home Full-time role