Director, Information Security + Compliance
Pelago · New York, NY
About this role
**Pelago — Director, Information Security + Compliance** Pelago is a specialty substance use care provider built on the belief that effective treatment matches care intensity to what each member actually needs—not the most expensive intervention. With Sona, Pelago also applies a clinically-driven, voice-first AI model to mental health. Our engineering team operates as empowered, outcome-oriented problem solvers, evolving how we build software so we spend less time on mechanical implementation and more time on system design, judgment, and impact. --- ## About the Role Pelago’s clients trust us with highly sensitive data. Our SOC 2 Type II and HITRUST certifications are central to how we earn and keep that trust. The **Director of Information Security & Compliance** will strengthen that foundation as Pelago’s business, data, and AI platform grow—setting security strategy and leading the team that executes it. This is a **hybrid role** with a high-collaboration rhythm (**3 days/week in our NYC office**). --- ## In this role you will: - **Own SOC 2 Type II and HITRUST** certification end-to-end, including audits, remediation, and recertification. - Develop and manage Pelago’s **security roadmap, budget, and tooling**, and present key risks and recommendations to the executive team and Board. - Serve as the security lead in **client security reviews, RFPs, questionnaires, and partner due diligence**, partnering with Sales to position Pelago’s security posture as a competitive advantage. - Maintain **security policies** and conduct **third-party vendor risk reviews**, including reviews of new AI tools. - **Automate evidence collection** and implement **continuous control monitoring** so compliance scales with the business. - Own **incident response, vulnerability management, and the penetration testing program**. - Partner with **Engineering** on security monitoring, disaster recovery, secure design, and the security of the AI platform. - Partner with **IT** on identity and access management, and own periodic access reviews required for audits. - Partner with **Legal** on the privacy program (**HIPAA, GDPR, BAAs**) and lead breach assessments. - **Lead, coach, and grow** the security team as a player-coach (currently **1–2 direct reports**), including building the case for and hiring future team members. - Set the bar for the function: clear ownership, sustainable on-call, career paths, and performance expectations. - Build **security literacy** across the company (engineering, clinical, commercial, and operations). --- ## The background we are looking for: - Direct accountability for **SOC 2 Type II** and **HITRUST** outcomes. - Experience leading information security and compliance in **healthcare/health tech** or another regulated industry; strong working knowledge of **HIPAA**. - Cloud security expertise in a modern stack (**AWS, infrastructure as code, containers, CI/CD**). - Working knowledge across **GRC, security operations, application security, and identity & access management**. - **Player-coach** leadership experience: hands-on while building a team. - Sound commercial risk judgment (when to accept vs. when to escalate). - Ability to communicate clearly with **engineers, clients, auditors, executives, and the Board**. ### Nice to have: - Experience securing **AI/LLM systems**, agentic tools, or data used in model workflows. - Experience scaling a security program at a **Series B/C** company. - Certifications such as **CI
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.