Grow Therapy logo
Grow Therapy

Quality therapy that’s covered by insurance.

Staff TPM, Security Risk

RiskRiskFull TimeRemoteMid LevelTeam 201-500Since 2020H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

4 days ago

Salary

$152K - $189.8K / year

Seniority

Mid Level

English

Job Description

Staff TPM, Security Risk

Grow Therapy

About Us: Grow Therapy is on a mission to serve as the trusted partner for therapists growing their practice, and patients accessing high-quality care. Powered by technology, we are a three-sided marketplace that empowers providers, augments insurance payors, and serves patients. Following the mass increase in depression and anxiety, the need for accessibility is more important than ever. To make our vision for mental healthcare a reality, we’re building a team of entrepreneurs and mission-driven go-getters. Since launching in February 2021, we’ve empowered more than ten thousand therapists and hundreds of thousands of clients across the country and insurance landscape. We’ve raised more than $178mm of funding from Sequoia Capital, Transformation Capital, TCV, SignalFire, and others. The OpportunityWe are looking for a Security Risk Program Manager to take Grow Therapy's security risk program to the next level of maturity. Reporting directly to the Head of Security, you'll be part of a team focused on protecting Grow's patients, providers, employees, and business by embedding risk awareness into everyday decision-making. Your work will directly support Grow's mission to expand access to high-quality mental healthcare—safely, responsibly, and at scale. Your responsibilities will include building and maturing our enterprise risk management framework, driving audit readiness, shaping executive risk reporting, and partnering closely with teams across Legal, Compliance, Engineering, and Product. What You'll Be Doing - Build and mature Grow's enterprise security risk management program, including risk identification, assessment, prioritization, remediation tracking, and maintaining a comprehensive risk register that informs business decisions. - Lead the charge on AI risk management: Security sits within Grow’s Internal Foundations pillar, which is building company-wide infrastructure to support AI adoption. You’ll be in an incredible position to influence safe and thoughtful adoption of AI tooling at the enterprise level. - Own the third-party/vendor security risk management program, streamlining review workflows to support business velocity while ensuring robust security oversight of partners and vendors. - Drive audit readiness and external certifications (SOC 2, HIPAA-aligned assessments, HITRUST readiness) in close partnership with Legal and Compliance, reducing repeat findings and improving remediation timelines. - Develop and deliver executive-level risk reporting and readouts that translate technical and security risks into clear business impact, enabling leadership to make informed, risk-aware tradeoffs as the company scales. - Partner proactively across Security Engineering, Product, Engineering, and Operations to embed security and risk awareness into planning and decision-making cycles—positioning security as a strategic enabler rather than a gatekeeper. You'll Be a Good Fit If - You have deep experience building and operating security or enterprise risk management programs (not just managing projects) and a strong bias toward execution in fast-paced environments. - You bring strong knowledge of healthcare security, privacy, and compliance frameworks (HIPAA, SOC 2, HITRUST) and can navigate regulatory obligations without sacrificing speed or innovation. - You have exceptional stakeholder management and communication skills, including a track record of influencing senior leaders and translating complex risk concepts into actionable business guidance. - You are a strong program manager with a structured approach to prioritization, documentation, and cross-functional alignment. - Bonus: Experience scaling risk programs at high-growth or pre-IPO tech companies, prior ownership of vendor risk programs, or familiarity with GRC tooling and automation. Employment Type: Full Time, Exempt Base Compensation: The base compensation range for this position is $152,000–$189,750 USD Annually. The base compensation for this role will vary depending on several factors, including relevant experience, qualifications, and the candidate's working location. Location: This is a hybrid role with the expectation to work onsite from our NYC or San Francisco hub locations three days per week (Tuesday, Wednesday, and Thursday) and travel 2–3 times per year (e.g., company and department offsites). Full Time Employee Benefits: - Comprehensive Health Coverage: Medical, dental, and vision insurance, plus life and disability coverage. - Parental Leave & Family Support: Up to 18 weeks paid leave and a new child stipend. - Financial Wellness: 401(k) program and equity opportunities. - Meals & Home Office Support: Stipends for home office setup and ongoing funds for meals, with tailored perks for both remote and in-office employees. - Time Off to Recharge: Flexible PTO, 12 paid holidays, and a full winter break week. - Wellness & Development: Annual stipends to put towards personal & professional growth. - Mental & Physical Health Support: No-cost access to therapy through the Grow platform, weekly flexible hours for self-care (“Mental Health Mornings/Afternoons”) and memberships to leading wellness apps (such as One Medical, Headspace, and Talkspace). - Extra Perks: Pet insurance discounts, commuter benefits, and global travel assistance. Research shows that some groups hesitate to apply unless they meet every qualification. If you’re excited about this role but don’t check every box, we encourage you to apply. At Grow, we value diverse experiences, transferable skills, and the unique strengths each person brings. Grow Therapy is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. Use of AI Tools: By submitting your application, you acknowledge and consent to the use of automated tools as part of our recruitment process. Specifically, we use a third-party AI tool, Gem, to assist in the initial screening of resumes. This tool analyzes resumes based on role-specific criteria provided by our recruiters to identify potentially strong matches for the role. Importantly, no hiring decisions are made by the AI tool. All decisions about which candidates move forward are made by our human recruiting team after independent review.More information about Gem’s approach to compliance with California FEHA regulations on automated decision systems and New York Local Law 144 can be found on the Gem compliance website.We are committed to transparency and fairness in our hiring practices. If you have questions about how our AI tools work, or would like more information about how your application will be processed, please contact us at talentops@growtherapy.com. If you require an accommodation due to a disability, or have concerns about the use of AI in the hiring process, please also contact us. We are happy to provide assistance or offer an alternative method of participating in the recruitment process.

Related Categories

Related Job Pages

More Risk Jobs

Risk4 days ago
Full TimeRemoteTeam 501-1,000Since 1995H1B Sponsor

• Lead high profile client engagements, applying deep subject matter expertise and critical analysis skills for a wide range of IG and eDiscovery engagements • Collaborate with and support other information governance associates or 3rd party contractors to execute project tasks • Provide support for pre-sales activities, including conducting client and prospect presentations, demonstrations, solution design, etc. • Lead work streams for engagement deliverables, such as policy updates and harmonization • Information Lifecycle Management (ILM) strategy development • IG and eDiscovery technology implementation

United States
$113.0K - $140K / year
Citizens Financial Group logo

Senior Technology Risk Analyst – Monitoring and Testing

Citizens Financial Group

Founded in 1828 as a community bank, Citizens Financial Group, also known as simply Citizens and Citizens Bank, is one of the oldest financial institutions in t

Risk4 days ago
Full TimeRemoteTeam 17,000Since 1828

The Enterprise Technology & Security (ETS) Risk Senior Analyst leads the identification, assessment, and mitigation of technology-related risks, ensuring the organization's risk management practices are robust and effective. Serving as a key contributor within a first-line risk team, this role works directly with Risk Managers to execute control monitoring and testing that aligns with the bank's risk appetite framework, regulatory expectations, and industry standards. You will oversee end-to-end testing execution, apply advanced risk judgment, and mentor analysts to strengthen testing consistency and documentation quality. This role requires the ability to influence stakeholders through data-driven insights, proactively identify emerging risks, and drive continuous improvements in monitoring, analytics, and automation. This role requires strong professional judgment, high quality documentation, and timely communication to support a resilient control environment and informed risk decisions. The Senior Analyst applies deep knowledge of frameworks such as Cybersecurity Risk Institute (CRI) Profile, NIST 800-53, and NIST Cybersecurity Framework to assess risk and drive meaningful improvements in the bank's security and technology risk posture. Responsibilities - Lead planning and execution of control monitoring and testing across multiple complex technology and cybersecurity processes, ensuring adherence to methodology, timelines, and quality standards. - Independently perform and/or oversee control design and operating effectiveness testing; review workpapers and evidence for completeness, accuracy, and audit readiness. - Assess material controls and evaluate whether enhanced controls and remediation actions are effective to support issue validation and closure. - Ensure testing results are documented clearly and accurately in the system of record and supporting tools, producing audit-ready documentation suitable for QA, Internal Audit, and Regulatory review. - Proactively escalate significant control deficiencies, emerging risks, and delivery risks; drive follow-up with stakeholders to achieve timely resolution. - Lead issue validation testing to confirm remediation effectiveness and provide evidence-based recommendations to support issue closure. - Support and/or lead Risk and Control Self-Assessments (RCSAs), including creation and validation of process maps that reflect key processes, risks, and controls. - Lead identification and prioritization of opportunities to enhance testing through automation, data analytics, and improved key control metrics (KRIs/KCMs); partner with stakeholders to support implementation. - Strengthen continuous monitoring by refining metrics, improving coverage, and leveraging trend and anomaly analysis to increase risk signal and reduce noise. - Build and expand trusted relationships across business and technology stakeholders; influence outcomes through compelling, fact-based analysis and clear recommendations. - Mentor junior analysts on risk methodology, documentation standards, and analytical techniques. - Stay current on regulatory changes, emerging technology risks, and evolving industry frameworks. - Proactively pursue ongoing professional development, including relevant certifications, industry training, etc. to maintain current knowledge in a rapidly evolving field. Experience & Skills Required: - 5–7 years of progressive experience in IT risk management, information security, or internal audit. - Working knowledge of control frameworks including CRI Profile, NIST 800-53, NIST CSF, COBIT, and/or ITIL. - Experience conducting or supporting RCSAs, control testing, and risk assessments in a regulated environment. - Strong analytical and problem-solving skills with the ability to interpret complex data and translate findings into actionable recommendations. - Demonstrated ability to manage multiple concurrent priorities with minimal oversight. - Strong interpersonal and written communication skills; able to convey technical risk concepts to non-technical stakeholders. - Proficiency with GRC platforms (e.g., Archer), ITSM tools (e.g., ServiceNow, Jira), and security tools (e.g., Splunk, Qualys, DataDog, Wiz, and/or CyberArk). - Experience with cloud platforms such as AWS, Azure - Familiarity with reporting tools (Tableau, PowerBi) Preferred: - Experience in a regulated financial institution or banking environment. - Familiarity with cloud infrastructure risk, cyber recovery, or third-party risk management. - Prior experience responding to regulatory exams or supporting audit remediation. Education - Bachelor's degree in Information Technology, Cybersecurity, Business, or a related field required; Master's degree preferred. - One or more of the following certifications are preferred: - CISA (Certified Information Systems Auditor) - CRISC (Certified in Risk and Information Systems Control) - CISM (Certified Information Security Manager) - AWS Cloud Practitioner or Microsoft Azure Fundamentals Hours & Work Schedule - Hours per Week: 40 - Work Schedule: Monday-Friday - Hybrid: 4 days per week onsite, 1 day remote About Us Equal Employment Opportunity Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability. Equal Employment and Opportunity Employer Job Applicant Data Privacy Policy Background Check Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.

Rhode Island

Senior Risk Analyst

Attain Finance

Attain Finance is a North American consumer finance company headquartered in Greenville, South Carolina, with roots in the consumer credit market that extend for more than 50 years

Risk4 days ago

Title: Senior Risk Analyst Location: Canada Remote Department: Risk & Analytics Category Risk & Analytics Brand Attain Finance Remote Yes Location : Country CA Job Description: Overview Attain Finance is one of the largest, fastest growing full-spectrum consumer credit lenders in the United States and Canada. Our licensed, direct lending products and heightened customer service focus are at the core of what we offer. We have an upbeat, friendly and fast-paced environment. Our employees are excited to be a part of the Attain family, as evidenced by our low turnover rates and energized company culture. We’ve consistently grown well ahead of other loan lenders and are primed for continued growth and enduring success. Come and work for a company that has distinguished itself from competitors with quality product offerings, genuine customer service, robust operating systems, state-of-the-art call center, and a track record of new product innovation! At Attain Finance, managing risk is of the utmost importance to us. Our goal is to ensure we are providing access to money to underbanked consumers, while minimizing the company’s financial and regulatory risk exposure. Reporting to the Director of Risk Strategy, this team member utilizes cash flow, application, and bureau data to provide analysis across various aspects of the customer life cycle including underwriting, account management and/or collections. The incumbent will be responsible for developing, designing, analyzing, and implementing underwriting and portfolio management account risk strategies. As a member of our Risk Department, you will be a part of a very dynamic, learning-oriented risk team that thrives on innovation and opportunities to spearhead the deployment of new technologies for managing the growth of Attain’s lending portfolios. Responsibilities - Ability to develop underwriting strategies for the assigned loan portfolio as evidenced from improved performance (reduced defaults, increased receivables and/or revenue) and achieving desired business objectives - Interface with Modeling/Scoring team to deploy risk strategies based on new models to improve effectiveness of the model deployment - Develop dashboards to monitor and analyze portfolio and segment-level performance including performance of implemented strategies - Build and automate complex queries across database and create dynamic reports to enhance credit risk insights - Understand the data environment and be able to investigate issues to appropriately prioritize and set expectations for key reporting and analytical priorities - Coaches and mentors other analysts and acts as a thought leader within the analyst community - Work closely with internal groups to devise risk policies. Identify actionable insights, suggest recommendations, and influence the direction of the business by effectively communicating results to cross functional groups - Become familiar with assigned markets and products for use in developing/modifying underwriting strategies to meet business goals - Successfully manage multiple projects and timeline Qualifications BS/MS in a quantitative discipline (Statistics, math, qualitative social science, operation management, finance, ) or equivalent working experience - 4+ years of experience in credit risk or analytical experience in a related industry. Experience in Financial Services with emphasis on risk management/scoring of consumer lending products - Familiarity with data from credit bureaus and third-party data providers - Solid analytical skills and an understanding of how to utilize data to target improvements, solve problems, and tell a story - Strong organization skills and the ability to communicate effectively, both verbally and written - Exceptional problem-solving skills and ability to work effectively with minimal supervision - Comfortable working both independently and in a team environment - High proficiency with any of SQL/Snowflake/SAS - Knowledge of Python or R is a plus - Experience with A/B testing and data visualization (Sigma, Tableau) is a plus - Familiarity with statistical modeling techniques - Experience in Canadian consumer lending market is a plus Base Salary: $90,000 - $140,000 CAD The base salary range represents the low and high end of the anticipated salary range for this position based on the Canada average. The actual base salary offered for this full-time position will be determined by various factors, including but not limited to, location, skills, knowledge, competencies, and experience. All full-time salaried employees are eligible for the following benefits, starting on day one: Paid Time Off Program, Medical, Dental, Vision, Life Insurance, Disability, and other voluntary coverages. You will also be eligible to participate in our RRSP/DPSP program once you have completed 3 months of employment with a company match. Other company perks include access to the Employee Assistance Program, Emergency Relief Fund, Diversity and Inclusion Council, Tuition Reimbursement, Leadership and Development Programs. #Remote #AttainFinance

Canada
CAD 90K - CAD 140K / year
CRNCY (BZ) Limited logo

Credit Risk Analytics Specialist

CRNCY (BZ) Limited

Management & Strategic Development

Risk4 days ago
ContractRemoteTeam 51-200H1B No Sponsor

Role Description CRNCY Group is seeking a Credit Risk Analytics Specialist to help improve credit rule calibration and first-time loan sizing across our lending portfolio. The main objective of this role is to use historical application, loan, repayment, and collections data to determine whether our current underwriting rules are properly sizing first loans and approving the right customers. The role will focus on: - Identifying where we may be under-lending to strong customers. - Over-lending to higher-risk customers. - Creating adverse selection through our current rules. Over time, the role should help CRNCY move toward a more risk-based credit system, including: - Stronger customer segmentation. - Better loan amount calibration. - Improved performance measurement. - Risk-based pricing or variable rates. Qualifications - Experience helping a lender move from basic, rule-based underwriting to a more data-driven and risk-based credit model. - Worked in environments with basic, conditional, or one-size-fits-all credit rules while maintaining strong repayment discipline, low risk tolerance, and high recovery performance. Requirements - Improving underwriting in practical, step-by-step stages. - Using messy internal lending data to identify repayment patterns, customer risk, and affordability signals. - Calibrating loan amounts based on customer risk, income, payment capacity, and repayment behavior. - Introducing customer segmentation, scorecards, risk tiers, or probability-of-default models. - Testing credit rule changes in controlled increments before full rollout. - Using delinquency, default, collections, and repeat-borrowing data to improve underwriting decisions. - Supporting the move from flat pricing or one-size-fits-all offers toward risk-based pricing or variable rates. - Operating in markets where external credit bureau data, open banking, cashflow tools, or alternative data providers are non-existent or not fully integrated. Technical Skills Needed - SQL and Python to analyze application, loan, repayment, default, and collections data. - Credit risk modeling, including probability of default, first-payment default, scorecards, and customer risk segmentation. - First-loan sizing and affordability analysis, including payment-to-income rules and loan amount calibration. - Modeling techniques such as logistic regression, XGBoost, LightGBM, or similar practical machine learning methods. - Cohort analysis and portfolio performance tracking, including delinquency, default, expected loss, repeat borrowing, and collections outcomes. - Model validation and backtesting, including out-of-time testing and data leakage prevention. - Scenario testing and controlled experiments, including champion/challenger testing, A/B testing, Bayesian testing, causal inference, or Monte Carlo simulation. - Predictive customer value analysis, including repeat borrowing behavior, customer lifetime value, and risk-adjusted profitability. - Analytics and decisioning tools, such as BigQuery, Power BI, dbt, Taktile, Provenir, Alloy, Zoot, or similar platforms. What Success Looks Like - Clear customer risk segments. - Better first-loan amount bands. - Identification of under-lending pockets. - Recommendations for rule changes and approval thresholds. - Scenario analysis showing expected impact on approvals, defaults, collections, conversion, and profit. - Monitoring reports to track whether changes are working. - A practical roadmap toward risk-based pricing and scalable credit decisioning. What We Do Not Need We are not looking for a general business/process analyst, a research-heavy data scientist, or someone who depends on perfect external data, credit bureaus, open banking, or advanced AI tools to produce useful insights. The right person must be practical, hands-on, and able to work with the data we have today to solve the immediate first-loan sizing and underwriting calibration problem before moving into more complex modelling or long-term optimization. Compensation This is a contract-to-hire role with an expected hourly range of US$125–$175 per hour, depending on experience. Final compensation will be based on the candidate’s hands-on credit risk modeling experience, technical skillset, lending background, and ability to translate analysis into practical underwriting recommendations.

United States
$125 - $175 / hour