Security Risk Program Lead

Grow Therapy

$152K — $189K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security or enterprise risk management programs
  • Strong knowledge of healthcare security, privacy, and compliance frameworks (HIPAA, SOC 2, HITRUST)
  • Exceptional stakeholder management and communication skills
  • Proven program manager with structured prioritization and documentation skills
  • Bonus: Experience scaling risk programs at high-growth or pre-IPO tech companies

Responsibilities

  • Build and mature the enterprise security risk management program
  • Lead AI risk management initiatives to influence safe adoption of AI tooling
  • Own the third-party/vendor security risk management program
  • Drive audit readiness for external certifications like SOC 2 and HIPAA
  • Develop and deliver executive-level risk reporting
  • Partner proactively with cross-functional teams to embed risk awareness into decision-making

Benefits

  • Comprehensive health coverage including medical, dental, and vision insurance
  • Up to 18 weeks paid parental leave and a child stipend
  • 401(k) program and equity opportunities
  • Home office setup and ongoing meal stipends
  • Flexible PTO, 12 paid holidays, and a winter break week
  • Annual stipends for personal and professional development
  • No-cost access to therapy and wellness apps, plus flexible hours for self-care
  • Pet insurance discounts, commuter benefits, and global travel assistance
Full Job Description
The Opportunity

We are looking for a Security Risk Program Manager to take Grow Therapy's security risk program to the next level of maturity. Reporting directly to the Head of Security, you'll be part of a team focused on protecting Grow's patients, providers, employees, and business by embedding risk awareness into everyday decision-making. Your work will directly support Grow's mission to expand access to high-quality mental healthcare-safely, responsibly, and at scale. Your responsibilities will include building and maturing our enterprise risk management framework, driving audit readiness, shaping executive risk reporting, and partnering closely with teams across Legal, Compliance, Engineering, and Product.
What You'll Be Doing
  • Build and mature Grow's enterprise security risk management program, including risk identification, assessment, prioritization, remediation tracking, and maintaining a comprehensive risk register that informs business decisions.
  • Lead the charge on AI risk management: Security sits within Grow's Internal Foundations pillar, which is building company-wide infrastructure to support AI adoption. You'll be in an incredible position to influence safe and thoughtful adoption of AI tooling at the enterprise level.
  • Own the third-party/vendor security risk management program, streamlining review workflows to support business velocity while ensuring robust security oversight of partners and vendors.
  • Drive audit readiness and external certifications (SOC 2, HIPAA-aligned assessments, HITRUST readiness) in close partnership with Legal and Compliance, reducing repeat findings and improving remediation timelines.
  • Develop and deliver executive-level risk reporting and readouts that translate technical and security risks into clear business impact, enabling leadership to make informed, risk-aware tradeoffs as the company scales.
  • Partner proactively across Security Engineering, Product, Engineering, and Operations to embed security and risk awareness into planning and decision-making cycles-positioning security as a strategic enabler rather than a gatekeeper.
You'll Be a Good Fit If
  • You have deep experience building and operating security or enterprise risk management programs (not just managing projects) and a strong bias toward execution in fast-paced environments.
  • You bring strong knowledge of healthcare security, privacy, and compliance frameworks (HIPAA, SOC 2, HITRUST) and can navigate regulatory obligations without sacrificing speed or innovation.
  • You have exceptional stakeholder management and communication skills, including a track record of influencing senior leaders and translating complex risk concepts into actionable business guidance.
  • You are a strong program manager with a structured approach to prioritization, documentation, and cross-functional alignment.
  • Bonus: Experience scaling risk programs at high-growth or pre-IPO tech companies, prior ownership of vendor risk programs, or familiarity with GRC tooling and automation.

Employment Type: Full Time, Exempt

Base Compensation: The base compensation range for this position is $152,000-$189,750 USD Annually.
The base compensation for this role will vary depending on several factors, including relevant experience, qualifications, and the candidate's working location.

Location: This is a hybrid role with the expectation to work onsite from our NYC or San Francisco hub locations three days per week (Tuesday, Wednesday, and Thursday) and travel 2-3 times per year (e.g., company and department offsites).

Full Time Employee Benefits:
  • Comprehensive Health Coverage: Medical, dental, and vision insurance, plus life and disability coverage.
  • Parental Leave & Family Support: Up to 18 weeks paid leave and a new child stipend.
  • Financial Wellness: 401(k) program and equity opportunities.
  • Meals & Home Office Support: Stipends for home office setup and ongoing funds for meals, with tailored perks for both remote and in-office employees.
  • Time Off to Recharge: Flexible PTO, 12 paid holidays, and a full winter break week.
  • Wellness & Development: Annual stipends to put towards personal & professional growth.
  • Mental & Physical Health Support: No-cost access to therapy through the Grow platform, weekly flexible hours for self-care ("Mental Health Mornings/Afternoons") and memberships to leading wellness apps (such as One Medical, Headspace, and Talkspace).
  • Extra Perks: Pet insurance discounts, commuter benefits, and global travel assistance.

Research shows that some groups hesitate to apply unless they meet every qualification. If you're excited about this role but don't check every box, we encourage you to apply. At Grow, we value diverse experiences, transferable skills, and the unique strengths each person brings.

Similar Jobs

More Healthcare Jobs

Find similar Security Risk Program Lead jobs: