Security and Compliance Analyst
United States
Full Time Mid-level / Intermediate USD 120K - 140K
Pomelo Care
Pomelo is a virtual maternity care program that supplements traditional pregnancy care with unlimited, customized support. Ask a dietitian about prenatal vitamins, speak to a therapist about labor anxiety, or join a prenatal group. Become a...About us
Pomelo Care is a multi-disciplinary team of clinicians, engineers and problem solvers who are passionate about improving care for moms and babies. We are transforming outcomes for pregnant people and babies with evidence-based pregnancy and newborn care at scale. Our technology-driven care platform enables us to engage patients early, conduct individualized risk assessments for poor pregnancy outcomes, and deliver coordinated, personalized virtual care throughout pregnancy, NICU stays, and the first postpartum year. We measure ourselves by reductions in preterm births, NICU admissions, c-sections and maternal mortality; we improve outcomes and reduce healthcare spend.
What you'll do
Pomelo Care is seeking a proactive and detail-oriented Security and Compliance Analyst to support the development and execution of our information security and Governance, Risk, and Compliance (GRC) program. In this role, you will collaborate across departments to help identify and mitigate cybersecurity risks, ensure regulatory compliance, and contribute to security and privacy initiatives. The ideal candidate has a solid foundation in information security or GRC, strong project management skills, and a passion for improving processes in a dynamic healthcare startup environment.
Key responsibilities will include:
- Support the implementation and maintenance of Pomelo Care’s information security and GRC program, including policies, standards, and procedures.
- Assist in performing security risk assessments and control evaluations across the organization.
- Track and coordinate remediation activities for identified risks or compliance gaps.
- Support third-party risk management activities, including vendor security reviews, user access reviews and due diligence assessments.
- Participate in internal and external audits (e.g., SOC 2, HITRUST), including evidence collection and responding to the auditor. inquiries.
- Help manage compliance with healthcare-specific regulations (e.g., HIPAA) and security frameworks.
- Support the development and project management of security compliance workflows, including implementation of technical and administrative controls
- Develop and maintain metrics and dashboards to communicate GRC program status to stakeholders.
- Document processes, workflows, and control narratives to support governance and compliance efforts.
- Manage GRC or security-related projects, ensuring timely and quality delivery.
- Provide support for security awareness and training initiatives.
Who you are
- Minimum 3 years of professional experience in GRC, cybersecurity, compliance, risk management, or a related field.
- Experience coordinating or managing projects, including developing plans, tracking progress, and collaborating with stakeholders.
- Excellent organizational skills and attention to detail.
- Strong written and verbal communication skills.
- Ability to work independently and prioritize multiple tasks in a fast-paced startup environment.
We'll be super excited if you have
- Bachelor’s degree in Computer Science, Information Security, Information Systems, Business, or a related discipline.
- Professional certification such as CISA, CRISC, Security+, PMP or similar.
- Experience in healthcare technology startups or familiarity with healthcare regulatory requirements (e.g., HIPAA, HITRUST).
- Experience with GRC tools and platforms, such as Vanta and MyCSF.
Why you should join our team
By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.
We strive to create an environment where employees from all backgrounds are respected. We also offer:
- Competitive healthcare benefits
- Generous equity compensation
- Unlimited vacation
- Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)
At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.
Our salary ranges are based on paying competitively for our company’s size and industry, and are one part of the total compensation package that also includes equity, benefits, and other opportunities at Pomelo Care. In accordance with New York City, Colorado, California, and other applicable laws, Pomelo Care is required to provide a reasonable estimate of the compensation range for this role. Individual pay decisions are ultimately based on a number of factors, including qualifications for the role, experience level, skillset, geography, and balancing internal equity. Given that this role is open to candidates of different skill levels, determining a salary range is challenging. A reasonable estimate of the current salary range is $120,000 to $140,000. We expect most candidates to fall in the middle of the range.
Potential Fraud Warning
Please be cautious of potential recruitment fraud. With the increase of remote work and digital hiring, phishing and job scams are on the rise with malicious actors impersonating real employees and sending fake job offers in an effort to collect personal or financial information.
Pomelo Care will never ask you to pay a fee or download software as part of the interview process with our company. Pomelo Care will also never ask for your personal banking or other financial information until after you have signed an offer of employment and completed onboarding paperwork that is provided by our People Operations team. All official communication with Pomelo Care People Operations team will come from domain email addresses ending in @pomelocare.com.
If you receive a message that seems suspicious, we encourage you to pause communication and contact us directly at careers@pomelocare.com to confirm its legitimacy. For your safety, we also recommend applying only through our official Careers page. If you believe you have been the victim of a scam or identity theft, please contact your local law enforcement agency or another trusted authority for guidance.
Tags: Audits Banking C CISA Compliance Computer Science CRISC Governance HIPAA HITRUST Privacy Risk assessment Risk management SOC SOC 2
Perks/benefits: Career development Competitive pay Equity / stock options Startup environment Team events Unlimited paid time off
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.