Director, Governance, Risk, and Compliance
Job description
About the role
The Director of Governance, Risk, and Compliance (GRC) defines and executes Clover Health's security governance and risk strategy in support of the company's growth as a public, technology-enabled healthcare organization. This role operates at the enterprise level, shaping functional strategy while driving execution through cross-functional influence rather than direct authority. The Director of GRC is accountable for Clover's security risk posture, regulatory compliance readiness, and resilience capabilities. They ensure that governance, risk, and compliance activities are aligned to business priorities and long-term company outcomes. The role manages a third-party vendor providing GRC services and staffing, while serving as Clover Health's internal owner for security governance, risk decision-making, and executive-level accountability. As a Director, Governance, Risk, and Compliance, you will define and evolve the security governance and risk management strategy, aligning function-level priorities with enterprise objectives and the security roadmap. You will establish a risk-driven approach to governance aligned with HIPAA Security and Privacy Rules, NIST Cybersecurity Framework (CSF) v2, and NIST AI Risk Management Framework (AI RMF), where applicable. You will anticipate security and regulatory risks 12+ months out, using business, product, regulatory, and market signals to inform strategy and tradeoffs. You will ensure security risk decisions are clearly framed, documented, and communicated in business terms for executive and board-level audiences. You will assist the CISO in setting security risk priorities, framing tradeoffs, and communicating risk posture and progress to executive leadership and the Board.
Key facts
What you'll do
Define and evolve Clover Health's security governance and risk management strategy, aligning function-level priorities with enterprise objectives and the security roadmap.
Establish a risk-driven approach to governance aligned with HIPAA Security and Privacy Rules, NIST Cybersecurity Framework (CSF) v2, and NIST AI Risk Management Framework (AI RMF), where applicable.
Anticipate security and regulatory risks 12+ months out, using business, product, regulatory, and market signals to inform strategy and tradeoffs.
Ensure security risk decisions are clearly framed, documented, and communicated in business terms for executive and board-level audiences.
Assist the CISO in setting security risk priorities, framing tradeoffs, and communicating risk posture and progress to executive leadership and the Board.
Own Clover Health's security compliance posture as a public healthcare company, including federal and state regulatory obligations.
Lead security-related audits, assessments, and regulatory inquiries in partnership with Legal, Compliance, Privacy, and Internal Audit.
Drive clarity, consistency, and maturity in security policies, standards, and procedures.
Ensure compliance efforts are proactive, scalable, integrated into how Clover Health builds and operates products, and maintained over time to support ongoing audit readiness and regulatory expectations.
Own high-stakes outcomes for the GRC function, ensuring accountability across internal partners and third-party providers.
Set clear success metrics, decision rights, and escalation paths for risk and compliance activities.
Make and communicate tough prioritization calls when business needs, regulatory demands, or risk profiles shift.
Surface high-risk issues early and transparently to the CISO, peers, and senior leaders.
Lead Clover Health's third-party security risk management program end-to-end, overseeing vendor due diligence and ongoing monitoring.
Requirements
This role requires a demonstrated history of owning security governance, risk management, and compliance programs in complex, regulated environments. You must possess deep expertise in HIPAA Security and Privacy Rules, NIST Cybersecurity Framework (CSF) v2, and NIST AI Risk Management Framework (AI RMF), where applicable. You are experienced in anticipating security and regulatory risks 12+ months out and translating business, product, regulatory, and market signals into strategy and tradeoffs. You have the ability to frame security risk decisions in business terms for executive and board-level audiences. You have a proven track record of managing third-party risk management programs, including vendor due diligence and ongoing monitoring. You are skilled in driving clarity, consistency, and maturity in security policies, standards, and procedures. You have experience leading security-related audits, assessments, and regulatory inquiries in partnership with Legal, Compliance, Privacy, and Internal Audit. You are comfortable making and communicating tough prioritization calls when business needs, regulatory demands, or risk profiles shift.
Nice to have
Preferred experience with healthcare technology products and public company governance, risk, and compliance obligations.
Practical notes
This is a remote role based in the United States. Engagement details are specified in the source documentation.