Jobs and Careers
CL

Director, Governance, Risk, and Compliance (GRC)

Clover Health
Remote - USA, United StatesRemotefull_timeVerifiedPosted 17 Aug 2026
💰 $230,000/yr($212,000/yr$230,000/yr)

About the role

At Clover, the Business Enablement team leads our technological advancement while ensuring robust security and compliance. We deliver user-friendly corporate applications, manage complex data ecosystems, and provide efficient tech solutions across the organization. Our goal is simple: we make it easy for the business to do what’s right for Clover.

Clover Health is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute our security governance and risk strategy in support of Clover’s growth as a public,
technology-enabled healthcare company.

This role operates at the enterprise level, shaping functional strategy while driving execution through cross-functional influence rather than direct authority. The Director of GRC is
accountable for Clover’s security risk posture, regulatory compliance readiness, and resilience capabilities, ensuring that governance, risk, and compliance activities are aligned to business
priorities and long-term company outcomes.

The role manages a third-party vendor providing GRC services and staffing, while serving as Clover Health’s internal owner for security governance, risk decision-making, and executive-level accountability.

As a Director, Governance, Risk, and Compliance you will:

Governance & Security Risk Strategy

Define and evolve Clover Health’s security governance and risk management strategy, aligning function-level priorities with enterprise objectives and the security roadmap.
Establish a risk-driven approach to governance aligned with:
- HIPAA Security and Privacy Rules
- NIST Cybersecurity Framework (CSF) v2
- NIST AI Risk Management Framework (AI RMF), where applicable
Anticipate security and regulatory risks 12+ months out, using business, product, regulatory, and market signals to inform strategy and tradeoffs.
Ensure security risk decisions are clearly framed, documented, and communicated in business terms for executive and board-level audiences.
Assist the CISO in setting security risk priorities, framing tradeoffs, and communicating risk posture and progress to executive leadership and the Board.

Compliance & Regulatory Leadership

Own Clover Health’s security compliance posture as a public healthcare company, including federal and state regulatory obligations.
Lead security-related audits, assessments, and regulatory inquiries in partnership with Legal, Compliance, Privacy, and Internal Audit.
Drive clarity, consistency, and maturity in security policies, standards, and procedures.
Ensure compliance efforts are proactive, scalable, integrated into how Clover Health builds and operates products, and maintained over time to support ongoing audit readiness and regulatory expectations.

Accountability & Delivery Leadership

Own high-stakes outcomes for the GRC function, ensuring accountability across internal partners and third-party providers.
Set clear success metrics, decision rights, and escalation paths for risk and compliance activities.
Make and communicate tough prioritization calls when business needs, regulatory demands, or risk profiles shift.
Surface high-risk issues early and transparently to the CISO, peers, and senior leaders.

Third-Party Risk Management

Lead Clover Health’s third-party security risk management program end-to-end.
Oversee vendor due diligence, risk assessments, remediation tracking, and ongoing monitoring.
Manage and hold accountable a third-party GRC services vendor, ensuring delivery quality, prioritization, and alignment to Clover’s risk appetite.
Ensure third-party risks are evaluated holistically and escalated appropriately.

Incident, Crisis, and Resilience Governance

Lead governance and coordination for:
- Security incident response (IR)
- Crisis management
- Disaster recovery (DR)
- Business continuity (BC)
Ensure incidents are tracked, analyzed for root cause, reported appropriately, and followed through with corrective actions.
Lead or support enterprise tabletop exercises and simulations.
Balance immediate response needs with long-term system and process improvements.

Cross-Functional Problem Solving & Influence

Lead multi-team, cross-functional problem solving on complex security and compliance issue

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Clover Health

View company profile →