Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director, Governance, Risk, and Compliance (GRC)

$212k - $230k

Clover Health

Director, Governance, Risk, and Compliance (GRC)

Remote - USA

At Clover, the Business Enablement team leads our technological advancement while ensuring robust security and compliance. We deliver user-friendly corporate applications, manage complex data ecosystems, and provide efficient tech solutions across the organization. Our goal is simple: we make it easy for the business to do what’s right for Clover.

Clover Health is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute our security governance and risk strategy in support of Clover’s growth as a public, technology-enabled healthcare company.

This role operates at the enterprise level, shaping functional strategy while driving execution through cross-functional influence rather than direct authority. The Director of GRC is accountable for Clover’s security risk posture, regulatory compliance readiness, and resilience capabilities, ensuring that governance, risk, and compliance activities are aligned to business priorities and long-term company outcomes.

The role manages a third-party vendor providing GRC services and staffing, while serving as Clover Health’s internal owner for security governance, risk decision‑making, and executive‑level accountability.

As a Director, Governance, Risk, and Compliance you will:

Governance & Security Risk Strategy

  • Define and evolve Clover Health’s security governance and risk management strategy, aligning function‑level priorities with enterprise objectives and the security roadmap.
  • Establish a risk‑driven approach to governance aligned with:
    • HIPAA Security and Privacy Rules
    • NIST Cybersecurity Framework (CSF) v2
    • NIST AI Risk Management Framework (AI RMF), where applicable
  • Anticipate security and regulatory risks 12+ months out, using business, product, regulatory, and market signals to inform strategy and tradeoffs.
  • Ensure security risk decisions are clearly framed, documented, and communicated in business terms for executive and board‑level audiences.
  • Assist the CISO in setting security risk priorities, framing tradeoffs, and communicating risk posture and progress to executive leadership and the Board.

Compliance & Regulatory Leadership

  • Own Clover Health’s security compliance posture as a public healthcare company, including federal and state regulatory obligations.
  • Lead security‑related audits, assessments, and regulatory inquiries in partnership with Legal, Compliance, Privacy, and Internal Audit.
  • Drive clarity, consistency, and maturity in security policies, standards, and procedures.
  • Ensure compliance efforts are proactive, scalable, integrated into how Clover Health builds and operates products, and maintained over time to support ongoing audit readiness and regulatory expectations.

Accountability & Delivery Leadership

  • Own high‑stakes outcomes for the GRC function, ensuring accountability across internal partners and third‑party providers.
  • Set clear success metrics, decision rights, and escalation paths for risk and compliance activities.
  • Make and communicate tough prioritization calls when business needs, regulatory demands, or risk profiles shift.
  • Surface high‑risk issues early and transparently to the CISO, peers, and senior leaders.

Third‑Party Risk Management

  • Lead Clover Health’s third‑party security risk management program end‑to‑end.
  • Oversee vendor due diligence, risk assessments, remediation tracking, and ongoing monitoring.
  • Manage and hold accountable a third‑party GRC services vendor, ensuring delivery quality, prioritization, and alignment to Clover’s risk appetite.
  • Ensure third‑party risks are evaluated holistically and escalated appropriately.

Incident, Crisis, and Resilience Governance

  • Lead governance and coordination for:
    • Security incident response (IR)
    • Crisis management
    • Disaster recovery (DR)
    • Business continuity (BC)
  • Ensure incidents are tracked, analyzed for root cause, reported appropriately, and followed through with corrective actions.
  • Lead or support enterprise tabletop exercises and simulations.
  • Balance immediate response needs with long‑term system and process improvements.

Cross‑Functional Problem Solving & Influence

  • Lead multi‑team, cross‑functional problem solving on complex security and compliance issues.
  • Connect operational issues to systemic root causes and drive sustainable fixes rather than short‑term workarounds.
  • Influence peers and senior leaders through credibility, data, and executive presence — not authority.
  • Build durable partnerships across Engineering, IT, MA, Legal, Compliance, Privacy, Finance, and Operations.

Culture, Coaching, and Enterprise Presence

  • Build trust and credibility as a senior Clover leader.
  • Coach people managers, high‑potential ICs, and vendor staff to elevate GRC maturity across the organization.
  • Model transparency, accountability, and alignment in leadership forums.
  • Contribute to a culture of thoughtful risk‑taking, strong execution, and shared ownership.

Success in this role looks like:

  • Security risk management is clearly aligned to Clover Health’s growth strategy and enterprise priorities.
  • The CISO has confidence in Clover’s security, compliance, and resilience posture.
  • Security risk is managed, mapped, and reported on a regular cadence.
  • Compliance activities scale with the business and avoid last‑minute fire drills.
  • Incidents and crises are handled with discipline, transparency, and continuous improvement.
  • GRC is viewed as a strategic enabler — not a blocker — across the organization.

You should get in touch if:

  • 8+ years of experience in information security, GRC, risk management, or related disciplines.
  • Demonstrated experience leading security governance and compliance programs in regulated environments.
  • Strong working knowledge of HIPAA and healthcare security requirements.
  • Experience operating in a public company or similarly regulated environment.
  • Proven experience managing third‑party vendors providing GRC services or staff augmentation.
  • Hands‑on experience with incident response governance, crisis management, disaster recovery, and business continuity.
  • Strong business acumen with the ability to translate security and compliance risks into business impact.
  • Excellent executive‑level communication and stakeholder management skills.

Preferred Qualifications

  • Familiarity with NIST CSF v2 and NIST AI RMF.
  • Experience supporting AI‑enabled, data‑intensive, or technology‑forward healthcare platforms.
  • Relevant certifications such as CISM, CRISC, or similar are a plus.
  • Service‑management and automation mindset.

Benefits Overview

  • Financial Well‑Being : Competitive base salary, equity opportunities, performance‑based bonus program, 401(k) matching, and regular compensation reviews.
  • Physical Well‑Being : Comprehensive medical, dental, and vision coverage.
  • Mental Well‑Being : No‑Meeting Fridays, monthly company holidays, access to mental health resources, flexible time‑off policy, remote‑first culture.
  • Professional Development : Learning programs, mentorship, professional development funding, regular performance feedback.
  • Employee Stock Purchase Plan (ESPP) offering discounted equity opportunities.
  • Reimbursement for office setup expenses.
  • Monthly cell phone & internet stipend.
  • Remote‑first culture, enabling collaboration with global teams.
  • Paid parental leave for all new parents.
  • And much more!

About Clover

We are reinventing health insurance by combining the power of data with human empathy to keep our members healthier. We believe the healthcare system is broken, so we've created custom software and analytics to empower our clinical staff to intervene and provide personalized care to the people who need it most.

We always put our members first, and our success as a team is measured by the quality of life of the people we serve. Those who work at Clover are passionate and mission‑driven individuals with diverse areas of expertise, working together to solve the most complicated problem in the world: healthcare.

From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, perspectives, opinions, and backgrounds, who share a passion for improving people’s lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity.

All of our employee’s points of view are key to our success, and inclusion is everyone's responsibility.

Equal Employment Opportunity

We are an Equal Opportunity Employer. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. We are an E‑Verify company.

Salary Range

Base salary: $212,000 - $230,000 USD.

#J-18808-Ljbffr
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Director, Governance, Risk, and Compliance (GRC) in United States vacancy
  • $205.9k - $270.3k

     ...across technology and business teams to manage risk, protect guest and company data, and ensure compliance with global regulatory requirements while enabling innovation and growth. As Director, Governance Risk & Compliance (GRC), you own end-to-end delivery for the GRC... 
    Suggested
    Permanent employment
    Part time
    Work visa

    lululemon

    Washington DC
    18 days ago
  • Concentra seeks a Director of Security - GRC to lead governance, risk management, and compliance initiatives across the organization. The role focuses on building and maintaining security policies, conducting risk assessments, and driving third party risk management with... 
    Suggested

    Concentra

    Addison, TX
    1 day ago
  • $229.5k - $310.5k

    Alnylam Pharmaceuticals, Inc. is seeking a Senior Director of Governance, Risk & Compliance to define, lead, and mature governance, risk management, and compliance capabilities. This hybrid role is based in Cambridge, MA and involves overseeing cyber risk management, regulatory... 
    Suggested

    Alnylam Pharmaceuticals, Inc.

    Cambridge, MA
    1 day ago
  • $133.2k - $199.8k

     .... Our Team. Our Passion. Our Approach. Position SummaryWe are seeking an experienced Senior Manager, Cybersecurity & Governance, Risk & Compliance (GRC) to lead and mature our enterprise cybersecurity governance, risk management, compliance, and security assurance programs... 
    Suggested
    Full time
    Local area

    MHS Global

    Atlanta, GA
    3 days ago
  • $125.4k - $182.9k

    Job Description:The Manager, Cybersecurity Governance, Risk, Compliance (GRC), ERP Security, and IT Compliance is responsible for leading and advancing the organization's Cybersecurity GRC, IT Compliance, Third-Party Cybersecurity Risk Management, Cybersecurity Awareness... 
    Suggested
    Full time
    Local area
    Flexible hours

    Conagra Brands

    Omaha, NE
    2 days ago
  • Milliman Ireland is seeking a Governance, Risk & Compliance (GRC) Manager to lead the Global GRC program, oversee security reviews, vendor risk, and compliance initiatives. The role reports to the CISO within Global Corporate Services, coordinating with IT leads, PMO,... 
    Remote job

    Milliman Ireland

    Seattle, WA
    18 hours ago
  • $112k

    Manager, InfoSec Governance Risk and Compliance (GRC) New York City, New York, US Manager, InfoSec Governance Risk and Compliance (GRC) (New York City, New York, United States) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.... 
    Contract work
    For contractors
    For subcontractor
    Work at office
    Worldwide

    Ivalua

    New York, NY
    4 days ago
  • Career Opportunities: Sr. Manager, IT Governance, Risk and Compliance (GRC) (28928) Amkor Technology, Inc. (Nasdaq: AMKR) is the world’s largest U.S. headquartered OSAT and is a global leader in outsourced semiconductor packaging and test services. With a strong track... 
    Work at office
    Local area
    Relocation

    Amkor Technology

    Tempe, AZ
    4 days ago
  • Amkor Technology, Inc. in Tempe, AZ, seeks a Sr. Manager of IT Governance, Risk and Compliance (GRC) to lead IT SOX audit readiness and risk management initiatives in a hybrid role at our Tempe headquarters. You will collaborate with internal and external auditors, develop... 

    Amkor Technology

    Tempe, AZ
    4 days ago
  • $220k - $260k

     ...and equity, commensurate with experience The Role Security and compliance at Blitzy currently run on a patchwork: a Security Delegate managing...  ...the start. We're hiring one person to fix that. As Head of GRC, you'll own a compliance program that's audit-ready by design,... 

    Blitzy

    Cambridge, MA
    4 days ago
  • Palantir Technologies is seeking a GRC Program Manager to lead governance, risk, and compliance programs across Commercial, IG, and USG environments. You will partner with compliance engineers, security teams, and developers to scale processes that meet high regulatory... 

    Palantir Technologies

    Seattle, WA
    18 hours ago
  • $158k - $211.3k

     ...meaningful contributions at work and in communities. ​The Director, Global Cybersecurity Governance, Risk, Compliance & Identity is accountable for defining and...  ...leadership of the global Governance Risk Compliance (GRC) function and responsibility for Identity & Access... 
    Full time
    Work experience placement

    Donaldson company

    Bloomington, MN
    1 day ago
  • The Judge Group is seeking a Manager, IT Security, GRC in Burlington, NJ for a full-time, hybrid role. You will lead enterprise GRC efforts, oversee risk assessments, and drive governance across IT and business units. Responsibilities include managing risk registers, KPI... 
    Full time

    The Judge Group

    Burlington, NJ
    4 days ago
  • Governance, Risk & Compliance (GRC) Manager Job Category : Information Technology Requisition Number : GOVER010537 Posted : July 27, 2026 Full-Time Remote Locations Showing 1 location 01-Seattle Seattle, WA 981012635, USA Description POSITION SUMMARY: This position... 
    Full time
    Contract work
    Work experience placement
    Local area
    Remote work
    Worldwide

    Milliman Ireland

    Seattle, WA
    18 hours ago
  •  ...challenges and seeing your work deployed around the world with real impact, Northwood is the place to do it. Role Overview As Governance, Risk & Compliance (GRC) Lead, you will own Northwood's compliance program across CMMC, FedRAMP, SOC 2, and ITAR — building the policies,... 
    Permanent employment
    For contractors
    For subcontractor
    Immediate start

    Northwood

    Torrance, CA
    2 days ago
  •  ...challenges and seeing your work deployed around the world with real impact, Northwood is the place to do it. Role Overview As Governance, Risk & Compliance (GRC) Lead, you will own Northwood's compliance program across CMMC, FedRAMP, SOC 2, and ITAR — building the policies,... 

    Northwood Space

    El Segundo, CA
    18 hours ago
  • Program Manager - GRC (Governance, Risk & Compliance) Location: Bellevue, WA, 98006 Duration: 04 months contract Pay Range: $77.00/hr - $84.00/hr on W2 all-inclusive without benefits Hybrid Role: 2 days remote, 3 days in office Seniority level: Not Applicable Employment... 
    Contract work
    Work experience placement
    Work at office
    Remote work

    eTeam

    Bellevue, WA
    4 days ago
  • $77 - $84 per hour

    A leading consulting firm is seeking a Program Manager - GRC (Governance, Risk & Compliance) for a 4-month contract in Bellevue, WA. This hybrid role involves overseeing compliance standards, conducting audits, and collaborating with departments to mitigate risks. The... 
    Contract work

    eTeam

    Bellevue, WA
    3 days ago
  • $180k - $230k

     ...Overview:Anomali is scaling its compliance program to support an AI-...  ...cybersecurity platform used by governments and enterprises worldwide. We're looking for a hands-on GRC leader who can own and drive our...  ...continuous improvement of controls, risk assessments, and policy... 
    Full time
    Local area
    Remote work
    Worldwide

    Anomali

    Redwood City, CA
    4 days ago
  •  ...home at MX.As we continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will... 
    Work at office

    MX

    Lehi, UT
    2 days ago
  • $231.3k - $272.1k

     ...demonstrable information technology risk governance. Much of Modern Health's...  ...assessors. The Senior Director, Information Risk &...  ...Risk Committee (chaired by the Compliance & Privacy Officer). Risk...  ...security governance, assurance, GRC, or security program... 
    Full time
    Remote work
    Work from home
    Flexible hours

    Modern Health

    Remote
    5 days ago
  • LogicGate® is the leading AI GRC platform for the Enterprise, helping governance, risk, and compliance teams limit surprises, strengthen resilience, augment program performance, and confidently quantify impact and business value. Built to provide a centralized view of risk... 

    LogicGate

    Seattle, WA
    1 day ago
  • Mammoth Brands seeks a seasoned leader to build and grow the internal audit, risk management and governance function. You will own the SOX program, ERM, and a GRC rollout, influencing Finance, IT, Operations and Legal with a practical, scalable approach. This role requires... 

    Harry's

    New York, NY
    1 day ago
  • $108k - $180k

     ...GRC Risk Manager Los Angeles SHEIN Technology is a U.S. technology company. Founded in 2012, SHEIN is a leading global...  ...security infrastructure, risk management, data privacy, governance and regulatory compliance across SHEIN's global footprint. It is composed of a... 
    Temporary work
    Work at office
    Flexible hours

    Shein

    Los Angeles, CA
    2 days ago
  • $175k - $225k

     ...The Director, Investment Risk will establish a centralized investment risk function within the Enterprise...  ...risk measurement, analytics, governance, reporting, and oversight across the...  ...professionals, Product Management, Legal & Compliance, Information Technology, and senior... 
    Work at office
    Local area
    Remote work
    1 day per week

    Gwkinvest

    Boston, MA
    2 days ago
  • $229.5k - $310.5k

     ...millions of patients. Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk management, and compliance capabilities that protect our... 
    Full time
    Temporary work
    Work at office
    Local area
    Flexible hours

    Alnylam Pharmaceuticals

    Cambridge, MA
    4 days ago
  • Global Relay in Vancouver, BC, is seeking a Director of Governance, Risk & Compliance to establish and lead the GRC function. Reporting to the CIO, you will design frameworks, governance structures and an operating model to enable consistent security decision‑making and... 

    Global Relay

    Vancouver, WA
    3 days ago
  • $125.1k - $175.1k

     ...strategic leader to join our Third Party Risk Management (TPRM) function as a Director, Line 1B. This role is...  ...leading the Quality Assurance and governance oversight function across Vendor...  ...deep expertise in audit, regulatory compliance, and Risk & Control Self-Assessment... 
    Full time
    Temporary work
    Local area
    Flexible hours

    John Hancock

    Toronto, OH
    4 days ago
  •  ...EquitySelling Points Shape enterprise risk strategies in a hybrid work...  ...organizational change and governance initiatives. Collaborate with...  ...that meets regulatory and compliance standards.Foster a culture of...  ....Proficiency with ITSM, IRM/GRC platforms, particularly ServiceNow... 

    Green Key Resources

    Los Angeles, CA
    1 day ago
  • $94.6k - $176k

     ...WestJob Family Group:Audit, Risk & ComplianceThis role is specific...  ...challenge, and risk governance across the Bank's Operational...  ...Management, GRCE, Archer, ServiceNow GRC, Power BI, Tableau, Power...  ...assigned portfolio to ensure compliance as well as effective monitoring... 
    Full time
    Contract work
    Part time
    Shift work

    BMO Bank

    Toronto, OH
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director, Governance, Risk, and Compliance (GRC). Be the first to apply!