Head of Technology Governance Risk Compliance (GRC) - (Hybrid - San Diego, CA or Acton, MA)
Insulet CorporationAbout the role
The Head of Technology (GRC) reports directly to the Chief Information Security Officer and plays a pivotal role within Insulet’s Chief Technology Office (CTO). This executive will lead an enterprise-wide function that encompasses Information Security, Governance, Technology Risk, and Compliance (GRC), with strategic oversight of internal systems, customer-facing platforms, and clinical data environments. The role includes direct management of senior leaders and tight partnership with leadership across Finance, Global Operations, International Commercial, Product functions, along with other internal compliance and audit functions.
This position will be responsible for building Insulet’s technology risk, compliance and resiliency strategy, proactively identifying and mitigating risks, and ensuring alignment with external auditors, regulators, and legal teams. The leader chairs the cross-functional Technology Risk Committee and regularly presents, alongside the CISO, to the Executive Leadership Team (ELT) and Board of Directors on compliance/regulatory status, governance, and technology risk posture.
The position requires a visionary leader who can formulate and implement a cohesive framework for data governance, business continuity, and technology risk management. This includes oversight of all technology risks—beyond cybersecurity and IT—such as AI usage, data protection, and technology adoption. This leader will influence and advise peers across CTO/R&D (e.g., Systems and Software Engineering), Finance (e.g., Audit and Accounting), Procurement, Regulatory, and Compliance, and will be customer-facing to communicate security controls and compliance adherence.
Responsibilities
Governance & Policy Leadership
Setting the strategic direction of the Technology GRC organization and oversight of the team that designs, implements, and maintains the IT GRC framework, including policies, standards, and controls aligned with business objectives and risk appetite.
Oversees and sets the Insulet roadmap for our Information Security Management System (ISMS), ensuring alignment with ISO 27001 and other relevant frameworks.
Overseeing self-assessments, escalating decisions and escalations per requirements, to drive decisions, and risk reduction.
Govern Business Continuity Management Program and lead risk quantification efforts
Risk Management
Design and implement a robust Three Lines of Defense (3LOD) framework, clearly delineating roles and responsibilities across business units, risk management, and internal audit to enhance accountability, risk ownership, and assurance effectiveness in alignment with industry best practices.
Lead risk assessments activities, integrating findings into Risk Register or into the Enterprise Risk Management (ERM) program.
Maintain and report on the risk register, risk treatment plans, and mitigation strategies.
Provide actionable, data-driven insights to executive leadership and the Board on risk posture and emerging threats.
Regulatory Compliance & Audit
Ensure compliance with HI
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s