Pomelo Care is the leading virtual medical practice for women and children, providing care across pregnancy, postpartum, pediatrics, menopause, and perimenopause. We combine proactive, 24/7 clinical care with technology that helps us reach patients earlier, identify risks sooner, and deliver personalized care throughout their journey. Our team includes clinicians, technologists, operators, and problem-solvers working together to make high-quality care more accessible for families nationwide.
About The Role:
We are looking for a Director of Security Compliance to lead our security governance, risk, and assurance strategy. Reporting to the Head of Compliance, you will be the primary architect of our security governance program and the most senior voice on security oversight, owning the roadmap for our HITRUST and SOC certification lifecycles.
This is a hands-on role: in partnership with the Head of Compliance, you will build and run our security compliance program. It is not a software engineering position. You will define our security standards, risk appetite, and compliance requirements, while our engineering team owns technical implementation. Your success will come from setting direction, influencing technical roadmaps, and holding the organization accountable to a security posture that protects our patients and enables the business to move fast.
What you’ll do:
Define and own the enterprise-wide security strategy and policy framework in partnership with our engineering team and help shape our security risk appetite across all of Pomelo Care.
Lead the full lifecycle for SOC 2 Type II and HITRUST certifications, managing external auditors and coordinating internal evidence collection.
Own day-to-day security compliance operations, including drafting and maintaining security policies and procedures, access control governance and periodic user access reviews, the annual HIPAA Security Risk Assessment, security awareness training, and ongoing control monitoring.
Serve as the security “Design Authority”: setting the governance standards that engineering’s security team builds to.
Partner as a peer with engineering leadership to ensure that technical roadmaps align with the enterprise security strategy.
Provide governance oversight for technical risk management, ensuring engineering-led solutions meet regulatory and contractual thresholds.
Act as the primary security point of contact for our health plan partners, leading security due diligence and representing our program during external audits and questionnaires.
Own the security assessment component of our Third-Party Risk Management program ensuring our vendors and partners meet our security and privacy requirements.
Own the Incident Response Plan, leading coordination, communication, and the compliance response while engineering handles technical containment and remediation.
Report regularly on security risk posture and program maturity to executive leadership.
What you’ll bring:
8+ years of experience in Information Security, with at least 3 years in a leadership or GRC-focused role, including direct experience in healthcare, and ideally in a high-growth startup environment.
Deep knowledge of HIPAA (particularly the Security Rule) and HITECH, and working knowledge of state privacy and security laws (CCPA/CPRA).
Proven track record personally leading successful SOC 2 and HITRUST (i1 or r2) certification cycles from readiness through audit.
Technical fluency. You won't be writing code, but you understand cloud environments (GCP preferred), CI/CD pipelines, and modern security tooling well enough to hold a detailed, credible conversation with the engineers who build them.
Exceptional communication skills, including the ability to translate complex security concepts into clear, practical guidance for executives, engineers, and business teams, and the ability to represent Pomelo’s security posture to sophisticated external health plan partners.
A pragmatic, business-forward approach to security: you right-size controls to actual risk, find paths to yes, and enable the business to move fast without compromising patient trust.
Strong project management skills, and a track record of driving cross-functional initiatives across the engineering, product, and operations teams to on-time completion.
Preferred certifications: CISSP, CISM, or CISA.
A collaborative mindset and a passion for our mission to improve maternal and infant health outcomes.
Compensation:
The expected base salary range offered for this role is $200,000-$230,000. This role is also eligible for equity, giving you an ownership stake in Pomelo’s mission. Actual compensation may vary based on relevant experience, skills, competencies, and certifications.
We are committed to hiring the best team to improve outcomes for all mothers and babies. To solve the complex challenges facing the diverse population we serve, we need diverse perspectives, actively welcoming people of all races, ages, sexual orientations, gender identities and expressions, national origins, religions, disabilities, and veteran statuses. We strive to cultivate an inclusive and respectful environment where team members thrive by working across disciplines, moving fast, making data driven decisions, learning continuously, and always putting the patient first.
Skills Required
- 8+ years of experience in Information Security
- At least 3 years in a leadership or GRC-focused role
- Direct experience in healthcare
- Deep knowledge of HIPAA, particularly the Security Rule, and HITECH
- Working knowledge of state privacy and security laws, including CCPA and CPRA
- Experience leading SOC 2 certification cycles from readiness through audit
- Experience leading HITRUST i1 or r2 certification cycles from readiness through audit
- Technical fluency with cloud environments, CI/CD pipelines, and modern security tooling
- Exceptional communication skills for executives, engineers, business teams, and external partners
- Pragmatic, business-forward approach to security and risk management
- Strong project management skills and experience driving cross-functional initiatives to completion
- CISSP, CISM, or CISA certification
- Experience in a high-growth startup environment
Pomelo Care Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Pomelo Care and has not been reviewed or approved by Pomelo Care.
-
Healthcare Strength — Healthcare benefits are described as platinum-level medical, dental, and vision coverage, with a high share of premiums covered for employees and partial support for dependents. Free access to the company’s own healthcare services is also offered to eligible employees.
-
Parental & Family Support — Paid parental leave is reported at around 16 weeks, aligning with the company’s maternal and infant health mission. Family-oriented benefits and support resources are emphasized as part of the package.
-
Equity Value & Accessibility — Equity compensation is described as generous stock option grants for employees. This sits alongside other financial perks and professional development support.
Pomelo Care Insights
What We Do
Pomelo Care is the leading virtual medical practice for women and children, providing care across pregnancy, postpartum, pediatrics, menopause, and perimenopause. We combine proactive, 24/7 clinical care with technology that helps us reach patients earlier, identify risks sooner, and deliver personalized care throughout their journey. Our team includes clinicians, technologists, operators, and problem-solvers working together to make high-quality care more accessible for families nationwide.
Why Work With Us
Pomelo Care redefines women’s and pediatric healthcare by combining 24/7 virtual care with proactive technology to catch risks early. Working here means joining a fast-paced, mission-driven team where clinicians, engineers, and operators collaborate directly to meaningfully improve maternal and child health outcomes nationwide.









