Grow Therapy logo
Grow Therapy

Quality therapy that’s covered by insurance.

Security Risk Program Lead

RiskRiskOtherRemoteSeniorTeam 201-500Since 2020H1B No SponsorCompany SiteLinkedIn

Location

New York + 1 moreAll locations: New York, California

Posted

6 days ago

Salary

$152K - $189.8K / year

Seniority

Senior

Bachelor Degree9 yrs expEnglishAi ToolingHipaaHitrustSoc 2

Job Description

About Us:

Grow Therapy is on a mission to serve as the trusted partner for therapists growing their practice, and patients accessing high-quality care. Powered by technology, we are a three-sided marketplace that empowers providers, augments insurance payors, and serves patients. Following the mass increase in depression and anxiety, the need for accessibility is more important than ever. To make our vision for mental healthcare a reality, we’re building a team of entrepreneurs and mission-driven go-getters. Since launching in February 2021, we’ve empowered more than ten thousand therapists and hundreds of thousands of clients across the country and insurance landscape. We’ve raised more than $178mm of funding from Sequoia Capital, Transformation Capital, TCV, SignalFire, and others.


The Opportunity

We are looking for a Security Risk Program Manager to take Grow Therapy's security risk program to the next level of maturity. Reporting directly to the Head of Security, you'll be part of a team focused on protecting Grow's patients, providers, employees, and business by embedding risk awareness into everyday decision-making. Your work will directly support Grow's mission to expand access to high-quality mental healthcare—safely, responsibly, and at scale. Your responsibilities will include building and maturing our enterprise risk management framework, driving audit readiness, shaping executive risk reporting, and partnering closely with teams across Legal, Compliance, Engineering, and Product.

What You'll Be Doing
  • Build and mature Grow's enterprise security risk management program, including risk identification, assessment, prioritization, remediation tracking, and maintaining a comprehensive risk register that informs business decisions.
  • Lead the charge on AI risk management: Security sits within Grow’s Internal Foundations pillar, which is building company-wide infrastructure to support AI adoption. You’ll be in an incredible position to influence safe and thoughtful adoption of AI tooling at the enterprise level.
  • Own the third-party/vendor security risk management program, streamlining review workflows to support business velocity while ensuring robust security oversight of partners and vendors.
  • Drive audit readiness and external certifications (SOC 2, HIPAA-aligned assessments, HITRUST readiness) in close partnership with Legal and Compliance, reducing repeat findings and improving remediation timelines.
  • Develop and deliver executive-level risk reporting and readouts that translate technical and security risks into clear business impact, enabling leadership to make informed, risk-aware tradeoffs as the company scales.
  • Partner proactively across Security Engineering, Product, Engineering, and Operations to embed security and risk awareness into planning and decision-making cycles—positioning security as a strategic enabler rather than a gatekeeper.
You'll Be a Good Fit If
  • You have deep experience building and operating security or enterprise risk management programs (not just managing projects) and a strong bias toward execution in fast-paced environments.
  • You bring strong knowledge of healthcare security, privacy, and compliance frameworks (HIPAA, SOC 2, HITRUST) and can navigate regulatory obligations without sacrificing speed or innovation.
  • You have exceptional stakeholder management and communication skills, including a track record of influencing senior leaders and translating complex risk concepts into actionable business guidance.
  • You are a strong program manager with a structured approach to prioritization, documentation, and cross-functional alignment.
  • Bonus: Experience scaling risk programs at high-growth or pre-IPO tech companies, prior ownership of vendor risk programs, or familiarity with GRC tooling and automation.


Employment Type:
Full Time, Exempt 

Base Compensation: The base compensation range for this position is $152,000–$189,750 USD Annually.
The base compensation for this role will vary depending on several factors, including relevant experience, qualifications, and the candidate's working location.
Location:  This is a hybrid role with the expectation to work onsite from our NYC or San Francisco hub locations three days per week (Tuesday, Wednesday, and Thursday) and travel 2–3 times per year (e.g., company and department offsites).

Full Time Employee Benefits:

  • Comprehensive Health Coverage: Medical, dental, and vision insurance, plus life and disability coverage.
  • Parental Leave & Family Support: Up to 18 weeks paid leave and a new child stipend.
  • Financial Wellness: 401(k) program and equity opportunities.
  • Meals & Home Office Support: Stipends for home office setup and ongoing funds for meals, with tailored perks for both remote and in-office employees.
  • Time Off to Recharge: Flexible PTO, 12 paid holidays, and a full winter break week.
  • Wellness & Development: Annual stipends to put towards personal & professional growth.
  • Mental & Physical Health Support: No-cost access to therapy through the Grow platform, weekly flexible hours for self-care (“Mental Health Mornings/Afternoons”) and memberships to leading wellness apps (such as One Medical, Headspace, and Talkspace).
  • Extra Perks: Pet insurance discounts, commuter benefits, and global travel assistance.

Research shows that some groups hesitate to apply unless they meet every qualification. If you’re excited about this role but don’t check every box, we encourage you to apply. At Grow, we value diverse experiences, transferable skills, and the unique strengths each person brings.

Grow Therapy is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. 

Use of AI Tools: By submitting your application, you acknowledge and consent to the use of automated tools as part of our recruitment process. Specifically, we use a third-party AI tool, Gem, to assist in the initial screening of resumes. This tool analyzes resumes based on role-specific criteria provided by our recruiters to identify potentially strong matches for the role. Importantly, no hiring decisions are made by the AI tool. All decisions about which candidates move forward are made by our human recruiting team after independent review.More information about Gem’s approach to compliance with California FEHA regulations on automated decision systems and New York Local Law 144 can be found on the Gem compliance website.We are committed to transparency and fairness in our hiring practices. If you have questions about how our AI tools work, or would like more information about how your application will be processed, please contact us at talentops@growtherapy.com. If you require an accommodation due to a disability, or have concerns about the use of AI in the hiring process, please also contact us. We are happy to provide assistance or offer an alternative method of participating in the recruitment process.

Benefits

  • 401(K), Childcare benefits, Commuter benefits, Company equity, Company-sponsored outings, Continuing education stipend, Customized development tracks, Dedicated diversity and inclusion staff, Dental insurance, Disability insurance, Diversity manifesto, Documented equal pay policy, Volunteer in local community, Family medical leave, Fitness stipend, Flexible work schedule, Free daily meals, Generous parental leave, Company-sponsored happy hours, Health insurance, Highly diverse management team, Job training & conferences, Open door policy, Life insurance, Mean gender pay gap below 10%, Mentorship program, Paid volunteer time, Open office floor plan, Paid holidays, Paid industry certifications, Paid sick days, Partners with nonprofits, Pet friendly, Pet insurance, Promote from within, Lunch and learns, Relocation assistance, Remote work program, Restricted work hours, Return-to-work program post parental leave, Free snacks and drinks, Team based strategic planning, OKR operational model, Team workouts, Continuing education available during work hours, Tuition reimbursement, Mandated unconscious bias training, Unlimited vacation policy, Vision insurance, Wellness programs, Mental health benefits, Home-office stipend for remote employees, Diversity employee resource groups, Hiring practices that promote diversity, Employee resource groups, Employee-led culture committees, Quarterly engagement surveys, Hybrid work model, In-person all-hands meetings, Diversity recruitment program, Pay transparency, Wellness days, Meditation space, Mother's room, Personal development training, Flexible time off, Bereavement leave benefits, Company-wide vacation

Related Categories

Related Job Pages

More Risk Jobs

M&T Bank logo

Loss Mitigation Liaison I-20

M&T Bank

Headquartered in Buffalo, New York, M&T Bank is a community-focused bank that provides banking, insurance, investment, and mortgage financial services to more t

Risk6 days ago
OtherRemoteTeam 10,001

This role serves as the Single Point of Contact throughout the loss mitigation and foreclosure processes, managing communication with delinquent mortgage loan borrowers regarding their accounts and options. Primary duties involve handling inbound and outbound calls while ensuring strict adherence to all applicable state and federal laws and regulations.

United States
$23 - $38 / hour
M&T Bank logo

Loss Mitigation Liaison I-3

M&T Bank

Headquartered in Buffalo, New York, M&T Bank is a community-focused bank that provides banking, insurance, investment, and mortgage financial services to more t

Risk6 days ago
OtherRemoteTeam 10,001

This role serves as the Single Point of Contact throughout the loss mitigation process, managing interactions with delinquent mortgage loan borrowers regarding options or foreclosure status. Responsibilities include handling inbound/outbound calls while maintaining compliance, answering consumer questions, documenting contacts, and explaining loss mitigation outcomes or the foreclosure process.

United States
$23 - $38 / hour
OtherRemoteTeam 1-10Since 2021H1B No Sponsor

Chief Risk Officer leading digital banking risk governance

United States
$250K - $380K / year
OtherRemoteTeam 1-10Since 2021H1B No Sponsor

VP Trust & Safety leading fraud prevention and governance strategy at digital platform

United States
$200K - $290K / year