Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Chief Information Security Officer

SpringHealth Behavioral Health & Integrated Care

  • The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health’s enterprise-wide information security, technology risk, compliance, and IT strategy
  • This leader will ensure the protection of company assets, customer data, member data, provider data, and critical systems while enabling business growth, innovation, and operational scale
  • Reporting to the Chief Technology Officer, the CISO will lead the company’s Information Security, Compliance/GRC, and IT functions, including Security Operations, Application/Product Security, cloud and infrastructure security, identity and access management, third-party risk, incident response, enterprise compliance, corporate IT, and business technology operations
  • This leader will manage and partner closely with senior security and IT leaders, including the VP, Information Security
  • The CISO will serve as a trusted advisor to executive leadership and the Board on cybersecurity risk, regulatory readiness, enterprise resilience, customer trust, and technology risk
  • They will play a critical role in Spring Health’s next phase of scale, including the integration of Alma, enterprise customer growth, AI transformation, international expansion, and readiness for future public-company expectations
  • This leader will be responsible for building a security and IT organization that enables the business, supports product velocity, protects sensitive healthcare data, and earns the trust of customers, members, providers, partners, regulators, and employees
  • Develop and execute Spring Health’s enterprise-wide information security, compliance, technology risk, and IT strategy in alignment with company priorities, growth plans, and regulatory obligations
  • Lead the Information Security, Compliance/GRC, and IT organizations, including Security Operations, Application/Product Security, cloud and infrastructure security, enterprise compliance, corporate IT, identity and access management, and business technology operations
  • Partner closely with the CTO, executive leadership team, Legal, Privacy, Compliance, Product, Engineering, Sales, Customer Success, People, Finance, and other stakeholders to ensure security and IT enable the business rather than create unnecessary friction
  • Serve as a trusted advisor to executive leadership and the Board on cybersecurity risks, technology risk, regulatory readiness, incident response, enterprise resilience, customer trust, and security investments
  • Build and scale a high-performing organization across security, compliance, and IT, including developing leaders, clarifying ownership, improving operating rhythms, and ensuring the team has the right structure, capabilities, and culture for Spring’s next stage of growth
  • Oversee enterprise security operations, including threat detection, vulnerability management, incident response, security monitoring, endpoint security, SIEM strategy, threat intelligence, and resilience exercises
  • Ensure Spring Health’s Application/Product Security and cloud security programs are deeply embedded in the software development lifecycle, including secure architecture, threat modeling, automated testing, vulnerability remediation, and security review processes
  • Own the enterprise compliance and information security risk management program, including risk assessments, risk registers, risk treatment plans, control frameworks, policy governance, and executive reporting
  • Ensure successful compliance outcomes across applicable frameworks and regulations, including HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other healthcare, privacy, and security requirements
  • Partner with Legal and Privacy on data protection, privacy, regulatory obligations, Business Associate Agreements, customer commitments, breach assessment, notification obligations, and evolving healthcare security requirements
  • Lead security and IT strategy related to the Alma integration, including systems, data flows, access controls, compliance obligations, enterprise risk, provider/member/customer data protection, and long-term operating model decisions
  • Define and govern Spring Health’s AI security strategy, including enterprise AI guardrails, approved tool usage, data classification, model/tool risk assessment, secure AI adoption, and protection of sensitive healthcare and business data
  • Oversee corporate IT and business technology operations, including employee technology experience, endpoint management, access lifecycle, SaaS governance, corporate applications, IT service delivery, and operational excellence
  • Serve as a senior executive sponsor in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, customer escalations, and technical diligence with large enterprise buyers
  • Build scalable customer trust processes, security narratives, artifacts, and evidence practices that reduce friction for Sales and Customer Success while maintaining strong risk discipline
  • Lead the organization’s response to significant security incidents, including technical response, executive communication, customer communication, legal/compliance partnership, regulatory considerations, post-incident review, and remediation
  • Manage security, compliance, and IT budgets, vendor relationships, tooling strategy, cyber insurance engagement, external audit partnerships, and key technology investments
  • Establish security, compliance, and IT metrics that give executive leadership and the Board clear visibility into risk posture, program maturity, operational performance, and investment priorities
  • Drive a company-wide culture of security, privacy, accountability, and responsible innovation
  • What Success Looks Like:
  • A clear, enterprise-wide security, compliance, and IT strategy is in place with defined priorities, milestones, KPIs, ownership, and executive/Board visibility
  • The Security, Compliance/GRC, and IT teams have a clear operating model, strong leadership, healthy collaboration, and the right structure to support Spring’s scale post-Alma
  • Spring Health maintains strong regulatory and compliance outcomes, including successful audits, certifications, customer reviews, and healthcare compliance obligations
  • Security and IT are viewed as business enablers by Product, Engineering, Sales, Customer Success, Legal, Compliance, People, Finance, and executive leadership
  • Alma integration work is progressing with clear security, compliance, IT, data, access, and risk-management priorities
  • AI adoption is supported by clear security guardrails, practical governance, and scalable controls that enable innovation while protecting sensitive data
  • Enterprise customer security reviews, audits, RFPs/RFIs, and escalations are handled efficiently and credibly, with repeatable processes that reduce friction and build customer trust
  • Security is embedded in product and engineering workflows, with clear requirements, tooling, review processes, and accountability across the SDLC
  • Incident response, crisis management, business continuity, and operational resilience programs are tested, understood, and effective
  • Corporate IT provides a strong employee experience while maintaining disciplined access management, endpoint security, SaaS governance, and operational controls
  • Executive leadership, customers, partners, auditors, regulators, and the Board have confidence in Spring Health’s security, compliance, and IT posture
  • Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission
Benefits
  • Health, Dental, Vision benefits start on your first day at Spring Health. You and your dependents also receive an individual One Medical account which is valued at $199/year per user. HSA and FSA plans available
  • A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents
  • 10 allocated sick days per year
  • Flexible paid time off in addition to 12 paid holidays throughout the year
  • Access to Gympass, an on-demand virtual benefit that provides wellbeing coaching, and budget management
  • Spring Renewal: When you hit your four-year Springaversary, you’ll be awarded a four week, fully paid, sabbatical leave to renew and recharge
  • 4-4.5 months of fully paid parental leave
  • Spring Health provides team members and their families with sponsored access to Bright Horizons® child care, back-up care, and elder care
  • Access to fertility care support through Carrot, in addition to $4,000 reimbursement for related fertility expenses
  • Our People team benchmarks all salaries using the Radford Global Compensation Database for technology and life sciences industries. Radford benchmarks salaries with 3,589 global firms, 6.5 million employees, and 98 countries across the globe. We do this to ensure all of our team members are paid equally and competitively
  • On top of competitive and benchmarked salary, Spring Health offers incentive pay (based on role), and equity that begins vesting as we celebrate your first year with the company!
  • Employer sponsored 401(k) match of up to 2% after 90 days of employment
  • Flexible work arrangements: 66% of Spring Health team members work fully remote while 33% work in a hybrid model from our New York City offices
  • Focus Fridays: no meetings, no distractions, just time for you to get work done
  • Focus Weeks: In Spring 2023, we held our first ever Focus Week, we canceled all non-essential meetings, minimized distractions, and you, our team members, to dive into the key work that gets chopped up or deprioritized during the regular day-to-day. We saw a 36% jump in the average energized score after those five days of flow state work and are finalizing a plan for quarterly Focus Weeks for team members
  • Up to $1,000 Professional Development Reimbursement per calendar year
  • $200 per year donation matching to support your favorite causes

Experience serving as an executive security leader in customer-facing enterprise security reviews, audits, RFP/RFI responses, technical diligence, and customer escalations15+ years of progressive experience across Information Security, cybersecurity, IT, technology risk, or related disciplines, with significant experience in executive security leadership rolesStrong technical fluency across cloud security, application security, identity and access management, security architecture, threat management, vulnerability management, incident response, and modern SaaS architecturePractical experience developing AI security strategy, enterprise AI governance, data classification practices, and guardrails for safe AI adoptionExperience owning or overseeing HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other relevant third-party security, privacy, and compliance programsDemonstrated ability to communicate cybersecurity and technology risk to executive and Board-level audiences, translating technical issues into business, financial, customer, and regulatory impactStrong understanding of healthcare technology, sensitive data environments, enterprise customer expectations, and the security/compliance requirements that come with serving large employers, health plans, providers, members, and partnersExperience leading security and/or IT through M&A integration, divestitures, major business transformation, IPO readiness, public-company readiness, or other high-complexity operating environmentsOne or more recognized industry certifications relevant to a role at this level preferred, such as CISSP, CISM, CCISO, CRISC, CISA, or similar credentialsExperience partnering effectively with Legal, Privacy, Compliance, Engineering, Product, Sales, Customer Success, People, Finance, and executive leadershipExperience leading or closely partnering with IT, corporate technology, business applications, employee technology, endpoint management, SaaS governance, and access lifecycle functionsDemonstrated experience leading multi-functional security organizations across Security Operations, Application/Product Security, cloud security, GRC/compliance, identity and access management, incident response, and third-party riskDeep working knowledge of HIPAA and hands-on experience leading security and compliance programs in a covered entity or business associate environmentStrong business judgment and ability to balance security, compliance, customer trust, employee experience, product velocity, innovation, and operational efficiencyExperience building and scaling high-performing teams, including hiring, developing leaders, clarifying operating models, and driving accountability across multiple functions

#J-18808-Ljbffr
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Chief Information Security Officer in San Francisco, CA vacancy
  •  ...startup with the trust and stability of an FDIC-insured national bank. We are seeking a highly collaborative, hands-on Chief Information Security Officer (CISO) who wants to build, protect, and scale a digital banking infrastructure that serves millions of customers.... 
    Suggested
    Work at office
    Shift work

    Jobleads-US

    San Francisco, CA
    3 days ago
  • $250k

     ...The San Francisco, CA office of Lewis Brisbois, a full-service AmLaw 100 firm, is seeking a Chief Information Security Officer. The Chief Information Security Officer (CISO) is a senior executive responsible for developing, implementing, and overseeing a comprehensive... 
    Suggested
    Work at office

    Jobleads-US

    San Francisco, CA
    1 day ago
  •  ...Chief Information Security Officer (CISO) San Francisco Office · Full-time About Slash Slash is building the future of business banking, one industry at a time. We think businesses deserve financial infrastructure built around how they actually operate. That's why we... 
    Suggested
    Full time
    Work at office

    Slash Financial

    San Francisco, CA
    4 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Innovative provider of online banking payment solutions Industry Financial Services Type Privately Held, VC-backed Founded 2008 Employees 1001-5000 Specialties fintech e-commerce... 
    Suggested

    Confidential

    San Francisco, CA
    5 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup... 
    Suggested

    Confidential

    San Francisco, CA
    4 days ago
  •  ...embedded software, aircraft, and field infrastructure. Security must protect those systems, customers, partners, and the...  ...enabling engineering teams to deliver safely and quickly As Chief Information Security Officer, you will own company-wide security and privacy strategy... 

    Zipline

    San Francisco, CA
    3 days ago
  •  ...a high bar for itself — keep reading. About the Role Socure is seeking an experienced, executive-level Deputy Chief Information Security Officer (Deputy CISO) to report directly to the CISO. In this role, you will lead company-wide security, data governance, compliance... 

    Jobleads-US

    San Francisco, CA
    2 days ago
  •  ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014... 

    Confidential

    San Francisco, CA
    4 days ago
  •  ...Deputy Chief Information Security Officer (CISO) About the Company Innovative digital life insurance company Industry Insurance Type Privately Held, VC-backed Founded 2016 Employees 501-1000 Funding $6-$10 million Specialties life insurance... 

    Confidential

    San Francisco, CA
    3 days ago
  •  ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories... 
    Remote work

    Confidential

    San Francisco, CA
    2 days ago
  •  ...incidents become more extreme and confidential information about models and frontier AI labs...  ...METR’s CISO, you will own METR’s overall security posture, proactively planning against...  ...METR also has a host of benefits: The office: Catered lunch and dinner daily; in-office... 
    H1b
    Work at office
    Work from home
    Home office
    Relocation package
    3 days per week

    Jobleads-US

    Berkeley, CA
    4 days ago
  •  ...infrastructure This is a ground-floor opportunity to build a security organisation from scratch, setting policies, controls, and...  ...Responsibilities: Define and execute the company-wide information security and compliance strategy across infrastructure, cloud,... 
    Permanent employment
    Remote work
    Flexible hours
    San Francisco, CA
    more than 2 months ago
  • Telecommunications ManagerThe major duties of the Telecommunications Manager include, but are not limited to, the following:Managing, coordinating, and administrating operations of a communications centerDirect supervision of public safety dispatch supervisors and public...

    Department of the Interior

    San Francisco, CA
    3 days ago
  •  ...Of Communications Center This position acts as manager of the communications center which is located in the San Francisco Field Office Dispatch Operations Center of the United States Park Police. The Dispatch Operations Center operates 24-hours a day/ 7 days a week... 
    Work at office

    US Government Jobs

    San Francisco, CA
    4 days ago
  •  ...Varo Bank is seeking a hands-on Chief Information Security Officer to lead, protect, and scale our digital banking platform serving millions of customers. This executive role blends strategy with practical cybersecurity leadership across cloud-native infrastructure, threat... 

    Jobleads-US

    San Francisco, CA
    4 days ago
  •  ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief... 

    Confidential

    San Francisco, CA
    2 days ago
  •  ...Chief Talent Officer (CTO) About the Company Nationally recognized network of public charter schools Industry Education Management Type Non Profit Founded 2006 Employees 501-1000 Categories E-Learning EdTech Education Elementary... 

    Confidential

    San Francisco, CA
    4 days ago
  •  ...Varo Bank seeks a hands-on Chief Information Security Officer (CISO) to lead and scale a secure digital banking platform serving millions of customers. You will bridge executive strategy with technical architecture, shaping a proactive security stance across cloud infrastructure... 

    Jobleads-US

    San Francisco, CA
    3 days ago
  • $191.1k - $320.6k

     ...strategic extension of the CRO's office — a trusted voice who can...  ...Architect role — it's a junior Chief Customer Officer: someone who...  ..., addressing platform/security/scale objections, and unblocking...  ...Candidate Privacy Statement for more information about how we use your... 
    Full time
    Work at office

    Salesforce

    San Francisco, CA
    16 hours ago
  •  ...we collectively want to see. Position Overview The Chief Technology Officer (CTO) will play a pivotal role in leading Fathom's...  ...needed Establish frameworks for collecting critical information from AI companies to track standards Develop "audit the... 
    Immediate start

    Fathom

    San Francisco, CA
    3 days ago
  •  ...ownership Graph or large-scale data systems experience Team building potential Why is This a Great Opportunity: Benefits & Perks Health insurance Gym stipend Transportation to office In-person SF team environment Direct access to leading investors as active backers... 
    Full time
    Work at office
    Relocation
    Relocation package

    Affinity Executive Search

    San Francisco, CA
    4 days ago
  •  ...high-impact decisions with minimal bureaucracy Set the technical culture: high ownership, speed, and accountability Ensure security, compliance, and trust at scale Requirements You've built and scaled real systems—not just managed teams You think like... 

    Lenme

    San Francisco, CA
    18 hours ago
  • $82.6k - $162.8k

     ...outcomes for clients across industries. Qualifications Required: * BA/BS in Computer Engineering, Computer Science, Information Systems, Cyber Security, or equivalent demonstrated technical background * 2+ years of experience in infrastructure or application architecture... 
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    3 days ago
  •  ...Salesforce, Inc. is seeking a Field CTO in the San Francisco area to act as the technical and strategic extension of the CRO’s office, representing the company’s product vision and architecture to major customers and partners. This role blends deep technical credibility... 
    Work at office

    Jobleads-US

    San Francisco, CA
    4 days ago
  • $120k - $140k

     ...client’s environment, working closely with Security Engineering and broader security...  ...coverage. Leverage threat intelligence to inform investigations and detection tuning. Collaborate...  ...of in-person time together - in the office and with our clients - while continuing to... 
    Full time
    Work at office
    Remote work
    Flexible hours
    Shift work

    Control Risks

    San Francisco, CA
    2 days ago
  •  ...role in a quickly expanding forensics department. This position will include travel for on-site collection efforts as well as an in-office presence at the primary firm office which includes the forensics lab and data center. This firm prioritizes a lean-team approach... 
    Full time
    Work at office
    Remote work
    Flexible hours

    CGS Federal (Contact Government Services)

    San Francisco, CA
    2 days ago
  •  ...project methodologies, procedures, and processes. Manage directory services and configuration management projects. Manage security-related infrastructure and application projects. Build and lead motivated, collaborative, and productive cross-functional... 
    Contract work
    Work at office
    Local area

    Match Point Solutions

    San Francisco, CA
    2 days ago
  • Veriswap is seeking a driven individual for a role involving proactive planning and management of the CEO and CTO’s appointments. While mostly remote, some assistance is required in person near Palo Alto, CA. The ideal candidate will be highly organized with a zest for ...
    Remote job

    Veriswap

    San Francisco, CA
    1 day ago
  •  ...The San Francisco office of Lewis Brisbois is seeking a Chief Information Security Officer to lead the firm’s cybersecurity, privacy, and risk management programs. This executive will develop and execute an enterprise-wide security strategy protecting client information... 
    Work at office

    Jobleads-US

    San Francisco, CA
    1 day ago
  •  ...Socure seeks an executive Deputy Chief Information Security Officer to lead company-wide security, data governance, compliance, and risk programs across our fast-scaling organization. You will drive AI and data security initiatives, engage with the Board of Directors,... 

    Jobleads-US

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Chief Information Security Officer. Be the first to apply!