Director, Information Security + Compliance

Pelago•New York, NY
•$210,000 - $230,000•Hybrid

About The Position

Pelago's clients trust us with some of the most sensitive data a person has, and our SOC 2 Type II and HITRUST certifications are central to how we earn and keep that trust. We already hold both. The Director of Information Security & Compliance will keep that foundation strong as our business, data, and AI platform grow, setting Pelago's security strategy and leading the team that executes it. The hire we're looking for has owned accreditation outcomes in a regulated environment, is hands-on enough to do the work alongside a small team, and has the commercial judgment to make security something that accelerates deals rather than slowing engineering down. This is a hybrid role with a high-collaboration rhythm (3 days/week in our NYC office).

Requirements

  • Direct accountability for SOC 2 Type II and HITRUST outcomes.
  • Experience leading information security and compliance in healthcare, health tech, or another regulated industry; strong working knowledge of HIPAA.
  • Cloud security expertise in a modern stack (AWS, infrastructure as code, containers, CI/CD).
  • Working knowledge across GRC, security operations, application security, and identity and access management.
  • Player-coach leadership experience: hands-on in the work while building a team.
  • Sound judgment about risk in a commercial context, including when to accept risk and when to escalate.
  • Ability to communicate clearly with engineers, clients, auditors, executives, and the Board

Nice To Haves

  • Experience securing AI/LLM systems, agentic tools, or data used in model workflows.
  • Experience scaling a security program at a Series B or C company.
  • Certifications such as CISSP, CISM, CCSP, or HITRUST CCSFP.
  • Experience working with US health plans, PBMs, or large self-insured employers.

Responsibilities

  • Own SOC 2 Type II and HITRUST certification end to end, including audits, remediation, and recertification.
  • Develop and manage Pelago's security roadmap, budget, and tooling, and present key risks and recommendations to the executive team and Board.
  • Serve as the security lead in client security reviews, RFPs, questionnaires, and partner due diligence, partnering with Sales to position our security posture as a competitive advantage.
  • Maintain security policies and third-party vendor risk reviews, including reviews of new AI tools.
  • Automate evidence collection and implement continuous control monitoring so compliance scales with the business.
  • Own incident response, vulnerability management, and the penetration testing program.
  • Partner with Engineering on security monitoring, disaster recovery, secure design, and the security of our AI platform.
  • Partner with IT on identity and access management, and own the periodic access reviews our audits depend on.
  • Partner with Legal on the privacy program (HIPAA, GDPR, BAAs) and lead breach assessments.
  • Lead, coach, and grow the security team as a player-coach, building the case for and hiring the next people onto the team (1–2 direct reports today).
  • Set the bar for the function: clear ownership, sustainable on-call, career paths, and performance expectations.
  • Build security literacy across the company, from engineering to clinical, commercial, and operations teams.

Benefits

  • Generous and meaningful equity package
  • Full Medical, Dental, & Vision coverage
  • 401k Plan
  • Unlimited PTO Policy, 10 paid holidays, & company wide “Me Time” Days
  • Paid maternity, paternity & new parent leave
  • Flexible working environment
  • Annual Learning and Development stipend to support continued learning and career development
  • Wellness Reimbursement Program
  • Access to Reproductive & Family Planning Care
  • Substance Use Support for employees and family members
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service