[All remote jobs](https://jobicy.com/jobs.md)Open role[![Clover Health logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8d4e74b3-221.jpg)](https://jobicy.com/company/clover-health.md)Remote opportunity at[Clover Health](https://jobicy.com/company/clover-health.md)

# Director, Governance, Risk, and Compliance (GRC)

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/clover-health.md)Share19 Aug 2026Published47Listing views2Application actions18 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryClover Health seeks a senior GRC leader to set enterprise security governance, risk, compliance, and resilience strategy for a public, technology-enabled healthcare company. The role owns security risk posture, regulatory readiness, third-party risk management, and governance for incident response, crisis management, disaster recovery, and business continuity. It relies heavily on cross-functional influence, executive and board communication, and oversight of an external GRC services provider rather than direct authority. Candidates need extensive regulated-environment experience, particularly HIPAA and healthcare security expertise, plus the ability to translate technical risk into business decisions. This is a US-remote, full-time leadership role with a disclosed annual base-salary range of $212,000 to $230,000 USD.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a high-stakes enterprise leadership role spanning public-company compliance, healthcare regulation, vendor accountability, and crisis resilience. Success requires independent strategic judgment and the ability to influence executives, the Board, and multiple business functions without direct authority.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$221,000US market range$210k–$270k0$297k

AI insightThe disclosed annual base salary is $212,000–$230,000 USD, producing an offer median of $221,000 USD. A competitive US market base-salary range for a Director of GRC in a regulated healthcare/public-company environment is approximately $210,000–$270,000 USD; total compensation may be higher when bonus and equity are included.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Security governance](https://jobicy.com/jobs?search_keywords=Security%20governance.md)[GRC strategy](https://jobicy.com/jobs?search_keywords=GRC%20strategy.md)[HIPAA compliance](https://jobicy.com/jobs?search_keywords=HIPAA%20compliance.md)[NIST CSF](https://jobicy.com/jobs?search_keywords=NIST%20CSF.md)[NIST AI RMF](https://jobicy.com/jobs?search_keywords=NIST%20AI%20RMF.md)[Third-party risk management](https://jobicy.com/jobs?search_keywords=Third-party%20risk%20management.md)[Security audits](https://jobicy.com/jobs?search_keywords=Security%20audits.md)[Incident response](https://jobicy.com/jobs?search_keywords=Incident%20response.md)[Disaster recovery](https://jobicy.com/jobs?search_keywords=Disaster%20recovery.md)[Business continuity](https://jobicy.com/jobs?search_keywords=Business%20continuity.md)

Cover letter sampleDear Hiring Team,

I am excited to apply for the Director, Governance, Risk, and Compliance role at Clover Health. My background leading security governance, regulatory compliance, third-party risk, and operational resilience programs in regulated environments aligns closely with Clover’s need for a strategic, business-oriented GRC leader.

I bring the ability to translate HIPAA, NIST, and enterprise risk requirements into practical roadmaps, clear decision rights, and executive-ready reporting. I would welcome the opportunity to partner with the CISO and cross-functional leaders to strengthen audit readiness, incident governance, and scalable security risk management.

Thank you for your consideration. I look forward to discussing how I can help Clover make GRC a trusted enabler of its healthcare mission and growth.

Copy   Sample interview questionsHow have you built or matured a security governance and risk management program in a regulated environment?I begin by aligning the risk taxonomy, control framework, ownership model, and reporting cadence to business objectives and regulatory obligations. I then prioritize the highest-impact gaps, establish measurable remediation plans, and provide leaders with concise risk decisions and trend reporting.

Describe how you would communicate a significant security risk to the CISO and Board.

I would frame the issue in business terms: affected assets or processes, likelihood, potential operational and regulatory impact, current controls, residual risk, and recommended decision options. The discussion would clearly identify the accountable owner, required investment or tradeoff, timeline, and escalation triggers.

What is your approach to third-party security risk management?

I use a lifecycle approach covering tiering, pre-contract diligence, risk-based assessments, contractual security requirements, remediation tracking, continuous monitoring, and periodic reassessment. For critical vendors, I establish clear service expectations, governance reviews, escalation paths, and evidence-based accountability.

How would you prepare the organization for a HIPAA-related security incident?

I would ensure documented incident-response playbooks, defined legal and privacy engagement points, severity criteria, evidence-handling procedures, communication protocols, and post-incident corrective-action governance. Regular tabletop exercises would validate decision-making, reporting readiness, and coordination across Security, Legal, Privacy, Compliance, and Operations.

How do you influence stakeholders when you do not have direct authority over their teams?

I build credibility through a clear understanding of each team’s goals, use data to explain risk and tradeoffs, and offer practical paths to resolution rather than simply identifying problems. Shared metrics, explicit decision rights, and consistent executive sponsorship help convert alignment into sustained delivery.

At Clover, the Business Enablement team leads our technological advancement while ensuring robust security and compliance. We deliver user-friendly corporate applications, manage complex data ecosystems, and provide efficient tech solutions across the organization. Our goal is simple: we make it easy for the business to do what’s right for Clover.

Clover Health is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute our security governance and risk strategy in support of Clover’s growth as a public,
technology-enabled healthcare company.

This role operates at the enterprise level, shaping functional strategy while driving execution through cross-functional influence rather than direct authority. The Director of GRC is
accountable for Clover’s security risk posture, regulatory compliance readiness, and resilience capabilities, ensuring that governance, risk, and compliance activities are aligned to business
priorities and long-term company outcomes.

The role manages a third-party vendor providing GRC services and staffing, while serving as Clover Health’s internal owner for security governance, risk decision-making, and executive-level accountability.

As a Director, Governance, Risk, and Compliance you will:

Governance & Security Risk Strategy

• Define and evolve Clover Health’s security governance and risk management strategy, aligning function-level priorities with enterprise objectives and the security roadmap.
• Establish a risk-driven approach to governance aligned with:
– HIPAA Security and Privacy Rules
– NIST Cybersecurity Framework (CSF) v2
– NIST AI Risk Management Framework (AI RMF), where applicable
• Anticipate security and regulatory risks 12+ months out, using business, product, regulatory, and market signals to inform strategy and tradeoffs.
• Ensure security risk decisions are clearly framed, documented, and communicated in business terms for executive and board-level audiences.
• Assist the CISO in setting security risk priorities, framing tradeoffs, and communicating risk posture and progress to executive leadership and the Board.

Compliance & Regulatory Leadership

• Own Clover Health’s security compliance posture as a public healthcare company, including federal and state regulatory obligations.
• Lead security-related audits, assessments, and regulatory inquiries in partnership with Legal, Compliance, Privacy, and Internal Audit.
• Drive clarity, consistency, and maturity in security policies, standards, and procedures.
• Ensure compliance efforts are proactive, scalable, integrated into how Clover Health builds and operates products, and maintained over time to support ongoing audit readiness and regulatory expectations.

Accountability & Delivery Leadership

• Own high-stakes outcomes for the GRC function, ensuring accountability across internal partners and third-party providers.
• Set clear success metrics, decision rights, and escalation paths for risk and compliance activities.
• Make and communicate tough prioritization calls when business needs, regulatory demands, or risk profiles shift.
• Surface high-risk issues early and transparently to the CISO, peers, and senior leaders.

Third-Party Risk Management

• Lead Clover Health’s third-party security risk management program end-to-end.
• Oversee vendor due diligence, risk assessments, remediation tracking, and ongoing monitoring.
• Manage and hold accountable a third-party GRC services vendor, ensuring delivery quality, prioritization, and alignment to Clover’s risk appetite.
• Ensure third-party risks are evaluated holistically and escalated appropriately.

Incident, Crisis, and Resilience Governance

• Lead governance and coordination for:
– Security incident response (IR)
– Crisis management
– Disaster recovery (DR)
– Business continuity (BC)
• Ensure incidents are tracked, analyzed for root cause, reported appropriately, and followed through with corrective actions.
• Lead or support enterprise tabletop exercises and simulations.
• Balance immediate response needs with long-term system and process improvements.

Cross-Functional Problem Solving & Influence

• Lead multi-team, cross-functional problem solving on complex security and compliance issues.
• Connect operational issues to systemic root causes and drive sustainable fixes rather than short-term workarounds.
• Influence peers and senior leaders through credibility, data, and executive presence —not authority.
• Build durable partnerships across Engineering, IT, MA, Legal, Compliance, Privacy, Finance, and Operations.

Culture, Coaching, and Enterprise Presence

• Build trust and credibility as a senior Clover leader.
• Coach people managers, high-potential ICs, and vendor staff to elevate GRC maturity across the organization.
• Model transparency, accountability, and alignment in leadership forums.
• Contribute to a culture of thoughtful risk-taking, strong execution, and shared ownership.

Success in this role looks like:

• Security risk management is clearly aligned to Clover Health’s growth strategy and enterprise priorities.
• The CISO has confidence in Clover’s security, compliance, and resilience posture.
• Security risk is managed, mapped, and reported on a regular cadence.
• Compliance activities scale with the business and avoid last-minute fire drills.
• Incidents and crises are handled with discipline, transparency, and continuous improvement.
• GRC is viewed as a strategic enabler — not a blocker — across the organization.

You should get in touch if:

• 8+ years of experience in information security, GRC, risk management, or related disciplines.
• Demonstrated experience leading security governance and compliance programs in regulated environments.
• Strong working knowledge of HIPAA and healthcare security requirements.
• Experience operating in a public company or similarly regulated environment.
• Proven experience managing third-party vendors providing GRC services or staff augmentation.
• Hands-on experience with incident response governance, crisis management, disaster recovery, and business continuity.
• Strong business acumen with the ability to translate security and compliance risks into business impact.
• Excellent executive-level communication and stakeholder management skills.

Preferred Qualifications

• Familiarity with NIST CSF v2 and NIST AI RMF.
• Experience supporting AI-enabled, data-intensive, or technology-forward healthcare platforms.
• Relevant certifications such as CISM, CRISC, or similar are a plus.
• Service-management and automation mindset.

Benefits Overview:

* Financial Well-Being: Our commitment to attracting and retaining top talent begins with a competitive base salary and equity opportunities. Additionally, we offer a performance-based bonus program, 401k matching, and regular compensation reviews to recognize and reward exceptional contributions.
* Physical Well-Being: We prioritize the health and well-being of our employees and their families by providing comprehensive medical, dental, and vision coverage. Your health matters to us, and we invest in ensuring you have access to quality healthcare.
* Mental Well-Being: We understand the importance of mental health in fostering productivity and maintaining work-life balance. To support this, we offer initiatives such as No-Meeting Fridays, monthly company holidays, access to mental health resources, and a generous flexible time-off policy. Additionally, we embrace a remote-first culture that supports collaboration and flexibility, allowing our team members to thrive from any location.
* Professional Development: Developing internal talent is a priority for Clover. We offer learning programs, mentorship, professional development funding, and regular performance feedback and reviews.

Additional Perks:

* Employee Stock Purchase Plan (ESPP) offering discounted equity opportunities
* Reimbursement for office setup expenses
* Monthly cell phone & internet stipend
* Remote-first culture, enabling collaboration with global teams
* Paid parental leave for all new parents
* And much more!

About Clover: We are reinventing health insurance by combining the power of data with human empathy to keep our members healthier. We believe the healthcare system is broken, so we’ve created custom software and analytics to empower our clinical staff to intervene and provide personalized care to the people who need it most.

We always put our members first, and our success as a team is measured by the quality of life of the people we serve. Those who work at Clover are passionate and mission-driven individuals with diverse areas of expertise, working together to solve the most complicated problem in the world: healthcare.

From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, perspectives, opinions, and backgrounds, who share a passion for improving people’s lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity. All of our employee’s points of view are key to our success, and inclusion is everyone’s responsibility.

#LI-Remote

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. We are an [E-Verify](https://www.e-verify.gov/?utm_medium=search&utm_source=google&utm_campaign=everify2018&utm_content=bg_Branded_Everify_General_English_BMM_E_Verify&utm_keyword=everify) company.

Final pay is based on several factors including but not limited to internal equity, market data, and the applicant’s education, work experience, certifications, etc.

A reasonable estimate of the base salary range for this role is:

$212,000—$230,000 USD

Show more

[Apply now >](https://jobicy.com/jobs/151150-director-governance-risk-and-compliance-grc.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Aug 19

### [Application Security Engineering Manager](https://jobicy.com/jobs/146803-application-security-engineering-manager.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

*
![Figma logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201016160957-035844.png)
Figma  Aug 18

### [Security Engineer](https://jobicy.com/jobs/151026-security-engineer.md)

Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you’re brainstorming, creating…

*
![Clickhouse logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/6394b9a0-221.png)
Clickhouse  Aug 18

### [Security Specialist – EMEA (location flexible)](https://jobicy.com/jobs/150995-security-specialist-emea-location-flexible.md)

About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast-growing private cloud companies. With more than 4,000 customers and ARR that…

*
![Experian logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/dcc5b29a570bb19b9f5c3e150db2fdfe.jpg)
Experian  Aug 18

### [Cyber Defense Senior Analyst](https://jobicy.com/jobs/146651-cyber-defense-senior-analyst.md)

Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius  Aug 18

### [Application Security Engineer](https://jobicy.com/jobs/146769-application-security-engineer-2.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Experian logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/dcc5b29a570bb19b9f5c3e150db2fdfe.jpg)
Experian  Aug 18

### [Cyber Defense Senior Analyst](https://jobicy.com/jobs/149401-cyber-defense-senior-analyst-2.md)

Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius  Aug 17

### [Vulnerability Operation Center Lead](https://jobicy.com/jobs/149362-vulnerability-operation-center-lead.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius  Aug 17

### [Offensive Security Lead](https://jobicy.com/jobs/149365-offensive-security-lead.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Consensys logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/19bbacf3-221.jpeg)
Consensys  Aug 16

### [Senior Application Security Engineer](https://jobicy.com/jobs/150834-senior-application-security-engineer.md)

Consensys is the leading blockchain and web3 software company. Founded by Joe Lubin, CEO of Consensys and Co-Founder of Ethereum in 2014, Consensys has been at the forefront of innovation,…

*
![GitLab logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/12/WRILS-201207055737-109952.jpg)
GitLab  Aug 15

### [Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA](https://jobicy.com/jobs/149309-senior-security-engineer-security-incident-response-team-sirt-emea.md)

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50…