Talent.com
Head of Technology Governance Risk Compliance (GRC) - (Hybrid - San Diego, CA or Acton, MA)
Head of Technology Governance Risk Compliance (GRC) - (Hybrid - San Diego, CA or Acton, MA)Insulet • San Diego, CA, US
No longer accepting applications
Head of Technology Governance Risk Compliance (GRC) - (Hybrid - San Diego, CA or Acton, MA)

Head of Technology Governance Risk Compliance (GRC) - (Hybrid - San Diego, CA or Acton, MA)

Insulet • San Diego, CA, US
8 days ago
Job type
  • Full-time
Job description

The Head of Technology (GRC) reports directly to the Chief Information Security Officer and plays a pivotal role within Insulet's Chief Technology Office (CTO). This executive will lead an enterprise-wide function that encompasses Information Security, Governance, Technology Risk, and Compliance (GRC), with strategic oversight of internal systems, customer-facing platforms, and clinical data environments. The role includes direct management of senior leaders and tight partnership with leadership across Finance, Global Operations, International Commercial, Product functions, along with other internal compliance and audit functions.

This position will be responsible for building Insulet's technology risk, compliance and resiliency strategy, proactively identifying and mitigating risks, and ensuring alignment with external auditors, regulators, and legal teams. The leader chairs the cross-functional Technology Risk Committee and regularly presents, alongside the CISO, to the Executive Leadership Team (ELT) and Board of Directors on compliance / regulatory status, governance, and technology risk posture.

The position requires a visionary leader who can formulate and implement a cohesive framework for data governance, business continuity, and technology risk management. This includes oversight of all technology risks—beyond cybersecurity and IT—such as AI usage, data protection, and technology adoption. This leader will influence and advise peers across CTO / R&D (e.g., Systems and Software Engineering), Finance (e.g., Audit and Accounting), Procurement, Regulatory, and Compliance, and will be customer-facing to communicate security controls and compliance adherence.

Responsibilities Governance & Policy Leadership

  • Setting the strategic direction of the Technology GRC organization and oversight of the team that d esign s , implement s , and maintai n s the IT GRC framework, including policies, standards, and controls aligned with business objectives and risk appetite.
  • Oversee s and sets the Insulet roadmap for our Information Security Management System (ISMS), ensuring alignment with ISO 27001 and other relevant frameworks.
  • Oversseeing self-assessments, escalating decisions and escalations per requirements, to driv e decisions, and risk reduction.
  • Govern Business C ontinuity Management Program a nd lead risk quantification efforts.

Risk Management

  • Design and implement a robust Three Lines of Defense (3LOD) framework, clearly delineating roles and responsibilities across business units, risk management, and internal audit to enhance accountability, risk ownership, and assurance effectiveness in alignment with industry best practices.
  • Lead risk assessments activities, integrating findings into Risk Register or into the Enterprise Risk Management (ERM) program.
  • Maintain and report on the risk register, risk treatment plans, and mitigation strategies.
  • Provide actionable, data-driven insights to executive leadership and the Board on risk posture and emerging threats.
  • Regulatory Compliance & Audit

  • Ensure compliance with HIPAA, HITECH, FDA cybersecurity guidance, SOX, GDPR, CMMC and other applicable regulations.
  • Oversee internal and external audits, including SOC 2, ISO 27001, and HITRUST certifications.
  • Serve as the primary liaison to auditors, regulators, and legal teams on cybersecurity compliance matters.
  • Third-Party & Supply Chain Risk

  • Lead the third-party risk management program, including vendor due diligence, contract reviews, and continuous monitoring.
  • Ensure supply chain security practices meet regulatory and industry expectations, including FDA and SEC guidance.
  • Security Awareness & Culture

  • Oversee enterprise-wide security awareness and training programs, including phishing simulations and compliance education.
  • Foster a culture of risk awareness and accountability across all levels of the organization.
  • Incident Response & Resilience

  • Govern the enterprise cyber incident response plan, including tabletop exercises and business continuity planning.
  • Ensure readiness for ransomware, data breaches, and other high-impact events.
  • Lead the development of an enterprise-wide Business Continuity Program (BCP), ensuring readiness for operational disruptions and alignment with risk management strategies.
  • Metrics & Reporting

  • Define and track key performance indicators (KPIs / KRI's ) and metrics for risk, quantification, compliance, and control effectiveness.
  • Deliver quarterly board updates, annual program reviews, and ad hoc reports on incidents, audits, and compliance status.
  • Strategic & External Engagement

  • Representing the organization in industry forums (e.g., H-ISAC), regulatory discussions, and peer collaborations.
  • Stay ahead of emerging technologies (e.g., AI, IoMT, cloud) and evolving regulatory landscapes to inform GRC strategy.
  • Develop budgets and resource requirements for direct reporting teams.
  • Participate in the development of team strategic plans, annual goal and delivery plans, and quarterly and monthly updates and retrospectives.
  • Required Leadership / Interpersonal Skills & Behaviors

  • Proven executive leader with a track record of building and scaling high-performing, cross-functional teams in complex, regulated environments.
  • Demonstrated ability to influence across the enterprise, including ELT and Board-level stakeholders, to drive alignment and accountability for risk and compliance outcomes.
  • Builds trust quickly and leads with integrity, transparency, and a collaborative mindset.
  • Skilled at navigating ambiguity and driving clarity in high-stakes, fast-paced environments.
  • Required Skills and Competencies

  • Deep expertise in security and risk frameworks and regulations, including NIST CSF, ISO 27001, SOC 2, HIPAA, HITRUST, FDA cybersecurity guidance, GDPR, and SOX.
  • Strong executive presence with the ability to translate complex risk and compliance issues into actionable business insights for C-level and Board audiences.
  • Experience leading enterprise-wide GRC programs that span cybersecurity, privacy, product security, and data governance.
  • Demonstrated success in maturing GRC capabilities through automation, metrics, and continuous improvement.
  • Managed and mentored teams of 15+ or more and held the title of a director or above.
  • Preferred

  • Advanced degree (e.g., MBA, MS in Cybersecurity, or related discipline).
  • Professional certifications such as CISSP, CISM, CISA, CRISC, or CIPP.
  • Experience with GRC platforms and automation tools (e.g., Archer, ServiceNow GRC, OneTrust).
  • Familiarity with cloud security compliance frameworks (e.g., CSA CCM, FedRAMP, HITRUST for cloud).
  • Experience integrating cybersecurity with enterprise risk management, privacy, and product lifecycle governance.
  • Demonstrated ability to apply a methodical, risk-based approach to evaluating and governing the use of AI technologies across the enterprise.
  • Education and Experience

  • 15–20+ years of progressive experience in information security, risk management, or IT audit, with at least 5 years in a senior GRC leadership role.
  • Proven experience leading global GRC teams and managing complex compliance programs in highly regulated industries (e.g., healthcare, medtech, financial services).
  • Additional Information

  • The position is hybrid at our Acton / SD / Bay Area office.
  • Travel is estimated at 25 % but will flex depending on business need s.
  • NOTE : This position is eligible for hybrid working arrangements (requires on-site work from our San Diego, CA or Acton, MA office; may work remotely other days). #LI-Hybrid

    Additional Information :

    The US base salary range for this full-time position is $217,275.00 - $325,912.50. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position in the primary work location in the US. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your Talent Acquisition Specialist can share more about the specific salary range for your preferred location during the hiring process. Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits.

    Insulet Corporation (NASDAQ : PODD), headquartered in Massachusetts, is an innovative medical device company dedicated to simplifying life for people with diabetes and other conditions through its Omnipod product platform. The Omnipod Insulin Management System provides a unique alternative to traditional insulin delivery methods. With its simple, wearable design, the tubeless disposable Pod provides up to three days of non-stop insulin delivery, without the need to see or handle a needle. Insulet's flagship innovation, the Omnipod 5 Automated Insulin Delivery System, integrates with a continuous glucose monitor to manage blood sugar with no multiple daily injections, zero fingersticks, and can be controlled by a compatible personal smartphone in the U.S. or by the Omnipod 5 Controller. Insulet also leverages the unique design of its Pod by tailoring its Omnipod technology platform for the delivery of non-insulin subcutaneous drugs across other therapeutic areas. For more information, please visit insulet.com and omnipod.com.

    We are looking for highly motivated, performance-driven individuals to be a part of our expanding team. We do this by hiring amazing people guided by shared values who exceed customer expectations. Our continued success depends on it!

    At Insulet Corporation all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

    #J-18808-Ljbffr

    Create a job alert for this search

    Head Of Technology • San Diego, CA, US

    Related jobs
    Head of Technical Recruiting

    Head of Technical Recruiting

    Genesis Molecular AI • San Diego, CA, United States
    Full-time
    Genesis Molecular AI is pioneering the use of AI and biophysics to transform drug discovery.Backed by leading investors such as a16z, NVIDIA (via NVentures) and Radical Ventures, we are growing tho...Show more
    Last updated: 22 hours ago • Promoted • New!
    Director, AI Security GRC Solutions

    Director, AI Security GRC Solutions

    KPMG US • San Diego, CA, US
    Full-time
    A leading consulting firm in San Diego is seeking an experienced Director, Cyber Security to develop commercial offerings in AI Governance, Risk, and Compliance. The ideal candidate will have over 8...Show more
    Last updated: 11 hours ago • Promoted • New!
    Head of AI / ML Tech Recruiting — Hybrid, Equity

    Head of AI / ML Tech Recruiting — Hybrid, Equity

    Menlo Ventures • San Diego, CA, United States
    Full-time
    A leading biotechnology firm is seeking a Head of Tech Recruiting to lead efforts in attracting top AI / ML talent.This role involves both strategic vision and hands-on execution, partnering with exe...Show more
    Last updated: 17 hours ago • Promoted • New!
    Global CISO for AI-Powered Health Tech

    Global CISO for AI-Powered Health Tech

    Confidential • San Diego, CA, US
    Full-time
    A mission-driven healthcare provider in San Diego is seeking a Chief Information Security Officer (CISO) to oversee global security strategy and compliance. The ideal candidate will have over 10 yea...Show more
    Last updated: 11 hours ago • Promoted • New!
    Information Technology

    Information Technology

    Veterans Prime, Inc. • Carlsbad, CA, United States
    Full-time
    Information Technology Careers Provide : .Constant Innovation and Technology.Are you interested in learning a skilled trade in the Information Technology industry that can develop into a life-long ca...Show more
    Last updated: 17 hours ago • Promoted • New!
    Global Head of GSI Alliances

    Global Head of GSI Alliances

    Canonical • San Diego, CA, United States
    Full-time
    Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise in...Show more
    Last updated: 30+ days ago • Promoted
    Head of Technical Recruiting

    Head of Technical Recruiting

    Menlo Ventures • San Diego, CA, United States
    Full-time
    Burlingame, CA, New York, NY, San Diego, CA, Remote.Genesis Molecular AI is pioneering the use of AI and biophysics to transform drug discovery. Backed by leading investors such as a16z, NVIDIA (via...Show more
    Last updated: 17 hours ago • Promoted • New!
    Director of Risk Management

    Director of Risk Management

    Family Health Centers of San Diego • San Diego, CA, United States
    Full-time
    Family Health Centers of San Diego.Family Health Centers of San Diego (FHCSD) is passionate about providing exceptional health care to all, especially underserved communities.Founded over 50 years ...Show more
    Last updated: 30+ days ago • Promoted
    Director, Central Corporate Compliance

    Director, Central Corporate Compliance

    Realty Income Corporation • San Diego, CA, United States
    Full-time +1
    The • •Director, Central Compliance • • will be responsible for leading Realty Income's global compliance efforts regarding general business compliance and ethics, including Code of Ethics, anti-trust...Show more
    Last updated: 5 days ago • Promoted
    Director Information Technology, Development Operations

    Director Information Technology, Development Operations

    ORIC Pharmaceuticals • San Diego, California, USA
    Full-time
    IT Business Partnership & Strategy.Serve as the primary IT partner for Phase 3 Development functions aligning technology solutions with business needs. Collaborate with Clinical Safety Regulator...Show more
    Last updated: 4 days ago • Promoted
    Global Head of Application Services

    Global Head of Application Services

    Rackspace Technology • San Diego, CA, United States
    Full-time
    Global Head of Application Services is a Leadership role and is responsible for managing the overall Application Services Business Globally for Rackspace Public Cloud. Driving business around Applic...Show more
    Last updated: 30+ days ago • Promoted
    Head of Mergers, Acquisitions, & Tuck-Ins (MAT)

    Head of Mergers, Acquisitions, & Tuck-Ins (MAT)

    Centura Wealth Advisory • San Diego, CA, United States
    Full-time
    Career Opportunities with Centura Wealth Advisory.Centura Wealth Advisory is seeking a dynamic and entrepreneurial leader to establish and lead its Mergers, Acquisitions, and Tuck-Ins (MAT) functio...Show more
    Last updated: 8 days ago • Promoted
    Head of Strategy and Product Management

    Head of Strategy and Product Management

    Biosero, Inc. • San Diego, CA, United States
    Full-time
    Our award-winning no-code software tools enable vital research to be done quickly while freeing scientists to address additional scientific challenges. Our solutions are placed in the top accounts w...Show more
    Last updated: 30+ days ago • Promoted
    Head of Search Arbitrage

    Head of Search Arbitrage

    Decido • Encinitas, CA, United States
    Full-time
    Decido is a 7‑year‑old performance marketing powerhouse that has generated over $100M in revenue.We specialize in building and scaling unique, high‑margin user acquisition businesses driven by crea...Show more
    Last updated: 30+ days ago • Promoted
    Head of UI & Platform Engineering — AI-Driven Experience

    Head of UI & Platform Engineering — AI-Driven Experience

    Teradata Group • San Diego, CA, United States
    Full-time
    A leading analytics and data firm in San Diego is seeking a strategic leader for UI / UX design.You will shape user experiences across platforms, driving innovation and leveraging AI technologies.The...Show more
    Last updated: 4 days ago • Promoted
    Information Technology_USA - USA_Analyst

    Information Technology_USA - USA_Analyst

    SysMind Tech • Carlsbad, CA, United States
    Full-time
    Please strictly adpersonre to tperson following resume naming convention : .ALL CAPS, NO SPACES B / T UNDERSCORES.PTN_US_GBAMSREQID_CANDIDATEBEELINEID. PTN_US_9999999_SKIPJOHNSON0413.Bill Rate market ra...Show more
    Last updated: 1 day ago • Promoted
    VP, SDLC Governance & Compliance

    VP, SDLC Governance & Compliance

    Banc of California • San Diego, CA, United States
    Full-time
    A leading bank in California is seeking a Vice President for Software Development Governance & Compliance.This role involves overseeing the SDLC governance, ensuring compliance with regulatory stan...Show more
    Last updated: 2 days ago • Promoted
    Director of Technology Platforms & Applications

    Director of Technology Platforms & Applications

    Cooley LLP • San Diego, CA, United States
    Full-time
    Cooley is seeking a Director of Technology Platforms & Applications to join the Technology Platforms and Applications team. The Director of Technology Platforms & Applications will play a key role i...Show more
    Last updated: 30+ days ago • Promoted