Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vice President, Information Security

$250k - $288.5k

SpringHealth Behavioral Health & Integrated Care

Vice President, Information Security

Remote

Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage. Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners. As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.

The Vice President, Information Security is responsible for defining, leading and advancing the organization's enterprise-wide information security strategy, ensuring the protection of company assets, customer data, and critical systems while enabling business growth and innovation. The leader provides strategic direction across cybersecurity, risk management, compliance, security operations, cloud and application security, identity and access management, third-party risk, and incident response.

The VP, Information Security partners closely with executive leadership, technology, legal, compliance, and business stakeholders to strengthen the organization's security posture, maintain regulatory compliance, and embed security into business and product decision-making. The leader will build and scale a high-performing security organization, drive security program maturity, and ensure the company remains resilient against evolving cyber threats while supporting operational excellence and organizational objectives.

What You'll Do

Security Strategy & Leadership

  • Develop and execute the enterprise information security vision, strategy, and multi-year roadmap.
  • Serve as a trusted advisor to executive leadership and the Board on cybersecurity risks, trends, and investments.
  • Establish security objectives, metrics, and reporting mechanisms aligned with business priorities.
  • Drive a security culture across the organization that enables innovation while maintaining appropriate risk controls, including effectively communicating risks and changes in the risk landscape to leadership, the Board, and key stakeholders in clear, business-relevant terms.

Governance, Risk & Compliance

  • Own the enterprise information security risk management program, including formal risk assessments, risk registers, and risk treatment plans.
  • Ensure compliance with applicable frameworks and regulations, including SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, GDPR, and CCPA.
  • Oversee security audits, risk assessments, policy development, and remediation initiatives.
  • Manage the Business Associate Agreement (BAA) program across the customer and vendor ecosystem.
  • Maintain and test the enterprise Incident Response and Business Continuity programs.
  • Drive continuous improvement of security controls and risk management practices.

Security Operations & Incident Response

  • Oversee security operations, threat detection, vulnerability management, and incident response functions.
  • Own the security operations center (SOC) function, including SIEM strategy, threat intelligence, and endpoint detection and response.
  • Lead the organization's response to security incidents, including executive communication, regulatory notification obligations, and post-incident review
  • Direct penetration testing, security assessments, and resilience exercises.

Cloud, Infrastructure & Product Security

  • Partner with Engineering and Product leadership to embed security throughout the software development lifecycle (SDLC), including threat modeling, secure code review, and automated security testing.
  • Provide strategic direction for the design and implementation of secure enterprise and cloud infrastructure, ensuring security architecture principles are embedded in platform design, data flows, and technology decisions across the organization.
  • Provide security architecture review and guidance for new products, features, and third-party integrations.
  • Oversee vulnerability management, penetration testing, and remediation programs across the platform and infrastructure.

Team & Program Leadership

  • Build, mentor, and develop high-performing security teams.
  • Manage security budgets, technology investments, and vendor relationships.
  • Lead third-party risk management and vendor security assessment programs.
  • Demonstrated ability to work closely with leadership across the organization, including Engineering, Legal, Privacy, Product, Sales, IT, HR, and others, serving as a trusted partner who enables the business rather than a barrier to it.
  • Serve as the executive point of contact for cyber insurance underwriters, external auditors, and regulatory examiners.
What Success Looks Like
  • A documented, board-approved information security strategy is in place with defined milestones, KPIs, and accountability.
  • Strong regulatory and compliance outcomes, including successful audits and certifications.
  • Reduced organizational risk through proactive threat management, vulnerability remediation, and security controls.
  • High levels of security resilience demonstrated through effective incident response and crisis management.
  • Security is embedded in the SDLC, development teams have clear security requirements, tooling, and a consistent process for security review.
  • Enterprise client security questionnaires and audits are handled efficiently, with documented repeatable processes that reduce friction for the Sales and Customer Success teams.
  • Meaningful improvements in security awareness and accountability across the organization.
  • Executive leadership, customers, partners, and regulators have confidence in the company's security posture.
  • A highly engaged, high-performing security team with strong retention
What You'll Bring
  • 12+ years of progressive experience in Information Security, with at least 5 years in a senior leadership role.
  • Demonstrated experience building and leading multi-functional security teams, including risk/compliance, application security, and/or security operations disciplines.
  • Demonstrated ability to communicate security risk to executive and board-level audiences, translating technical issues into business and financial impact.
  • Deep working knowledge of HIPAA and hands-on experience managing compliance programs in a covered entity or business associate environment.
  • Experience with HITRUST CSF, SOC 2, ISO 27001, and other comparable third-party security certification programs.
  • One or more recognized industry certifications relevant to a role at this level (CISSP, CISM, CCISO, CRISC, or CISA).
  • Experience building partnerships across the organization, enabling innovation in a safe and risk-aware way — a track record of being a business enabler, not a gatekeeper.
  • Experience managing client-facing security responsibilities, including enterprise security reviews, vendor assessments, and RFP responses.
  • Experience owning or contributing to incident response programs, including regulatory breach notification obligations.
  • Strong working knowledge of cloud security principles and modern SaaS architecture security requirements.
  • Track record of partnering effectively with executive leadership, boards, auditors, regulators, and customers.
  • Deep knowledge of security operations, threat management, vulnerability management, and incident response.
  • Strong expertise in cloud security, application security, identity and access management, and security architecture.
  • Strategic mindset with strong business and risk management acumen.
  • Ability to balance security requirements with customer experience, innovation, and business objectives.

The target base salary range for this position is $250,000 - $288,500, and is part of a competitive total rewards package including equity and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.

Benefits provided by Spring Health:

  • Health, Dental, Vision benefits start on your first day at Spring. You and your dependents also receive access to One Medical accounts HSA and FSA plans are also available, with Spring contributing up to $1K for HSAs, depending on your plan type.
  • Employer sponsored 401(k) match of up to 2% for retirement planning
  • A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
  • We offer competitive paid time off policies including vacation, sick leave and company holidays.
  • At 6 months tenure with Spring, we offer parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.
  • Access to Noom, a weight management program
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Vice President, Information Security in United States vacancy
  • $275k - $290k

     ...’s worth paying for. About the Role:As Vice President, Cybersecurity and Deputy CISO, you will...  ....You will:Lead and integrate core security functions, including security architecture...  ...progressive experience in cybersecurity or information security, including leadership of large... 
    Suggested
    Work at office
    Local area
    Flexible hours
    3 days per week

    The New York Times

    New York, NY
    5 days ago
  • $250k - $350k

     ...where you and your unique viewpoint matter. Learn about the Danaher Business System which makes everything possible.The Vice President, Information Security - Manufacturing Plant Security, Product Security & Application Security is responsible for protecting Danaher’s... 
    Suggested
    Full time
    Remote work
    Worldwide

    Danaher Corporation

    New York, NY
    1 day ago
  • We’re seeking a future team member for the role of Vice President, Cloud Security Engineer to join our Cloud Security team. This role is located in New York.In this role, you’ll make an impact in the following ways:Support implementation and continuous improvement of cloud... 
    Suggested
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    New York, NY
    2 days ago
  •  ...extraordinary journey today. Position Summary The Vice President of Information Technology leads the technology foundation that RPM Living...  .... Responsibilities Own the enterprise information security program anchored to a recognized framework (NIST CSF 2.0... 
    Suggested
    Weekly pay
    Full time
    Start working today
    Live in
    Work at office
    Night shift

    RPM Living

    Austin, TX
    2 days ago
  • WHO WE ARELed by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats...  ...operational oversight and risk management.YOUR IMPACTAs a Vice President in the Risk Practices and Control Management Team within... 
    Suggested
    Work at office

    Goldman Sachs

    Dallas, TX
    5 days ago
  • We’re seeking a future team member for the role of Vice President, Information Security to join our information Security team. This role is located in Lake Mary, Florida or Pittsburg, PA.In this role, you’ll make an impact in the following ways: Lead the design, development... 
    Work experience placement
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    Pittsburgh, PA
    2 days ago
  • $251.9k - $314.9k

     ...LocationCINCINNATI GENERAL OFFICESJob DescriptionP&G is searching for a senior technical leader to join the company as the Vice President of Information Security - Identity, Data Protection & Governance. This role will lead the enterprise strategy for identity security, data... 
    Full time
    Work at office

    Procter & Gamble

    Cincinnati, OH
    2 days ago
  • $219k - $268k

     ...Join Lunds & Byerlys as a Full Time Vice President Information Technology and take the next exciting step in your career! This onsite role has...  ...infrastructure, business systems, application development, information security, and IT support, while ensuring technology investments... 
    Full time
    Contract work
    Work at office

    Lunds and Byerlys

    Edina, MN
    1 day ago
  •  ...Vice President of Information Technology The Vice President of Information Technology serves as First State Bank and Trust's internal owner...  ...and to carry personal accountability for the reliability, security, and performance of the Bank's technology, including work... 
    Work experience placement
    Bank staff
    Relocation

    First State Bank and Trust

    Monticello, IL
    2 days ago
  •  ...Vice President, Cloud Security Engineer We're seeking a future team member for the role of Vice President, Cloud Security Engineer to join our Cloud Security team. This role is located in New York. In this role, you'll make an impact in the following ways:... 
    Flexible hours

    BNY

    Pittsburgh, PA
    3 days ago
  •  ...Explore Opportunities Information Technology Houston, TX Vice President, Information Security Houston, TX Vice President, Information Security Apply Now The Job was shared succesfully! Share Job Apply Now Share Job Job Description David... 
    Work at office
    Night shift

    David Weekley Homes

    Houston, TX
    1 day ago
  •  ...Vice President, Information Security Denver, CO; Atlanta, GA About Procare For over 30 years, Procare Solutions has been dedicated to empowering early childhood educators by providing products and services that enable them to focus on the care, safety and education... 
    Shift work

    ProCare Solutions LLC

    Atlanta, GA
    2 days ago
  •  ...leadership for the IT Team, ensuring technology services are secure, reliable, and aligned with Nutmeg’s strategic priorities. This...  ...models, and solutions with strategic and operational objectives. Information Security Operations & Technology Risk Oversee technology... 
    Full time

    Nutmeg State Financial Credit Union

    Rocky Hill, CT
    3 days ago
  • $250k

     ...Vice President of Information Technology (VP of IT) Compensation: Up to $250K base + 30% target bonus Position Type: Full-Time | Newly Created...  ...technology strategy, infrastructure design, and information security standards. Key Responsibilities Build and scale the U.S.... 
    Full time

    East 57th Street Partners

    Dallas, TX
    2 days ago
  •  ...Job Description Vice President of Information Technology Lead Technology Strategy, Innovation, and Transformation Our client in the...  ...support data-driven decision-making. Oversee information security, risk management, and technology governance programs.... 
    Remote work

    iMPact Business Group

    Kalamazoo, MI
    5 days ago
  • $150k - $250k

    WHO WE ARELed by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats...  ...to manage risk portfolios.As the Vendor Risk Program Vice President, you will be part of or oversee a team that is responsible... 

    Goldman Sachs

    New York, NY
    4 days ago
  •  ...is your chance to be part of something exceptional.What You’ll DoTechnology and security are inseparable from business success at Centric. As the executive responsible for both Information Systems and Cybersecurity, you will establish the strategic vision for how technology... 
    Full time

    Centric Software

    Campbell, CA
    3 days ago
  • $226k - $339.7k

     ...seeking a strategic and highly technical Vice President to lead our global Cyber Exposure...  ...defense capabilities, shape long-term security architecture strategy, and lead large-scale...  ...This role reports directly to the Chief Information Security Officer (CISO) and partners closely... 
    Full time
    Work at office

    Wolters Kluwer

    Chicago, IL
    1 day ago
  • $228.7k - $285.9k

     ...constellation delivers an unprecedented dataset of empirical information via a revolutionary cloud-based platform to...  ...and The Netherlands. About the Role: As the Vice President and Chief Information Security Officer (CISO), you will serve as a key executive and... 
    Full time
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work
    Home office
    Shift work
    3 days per week

    Planet

    Arlington, VA
    5 days ago
  • WHO WE ARELed by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure... 

    Goldman Sachs

    Dallas, TX
    4 days ago
  • $245.5k - $393k

    Worker TypeRegularJob DescriptionSummaryThe “Vice President of Cybersecurity & Chief Information Security Officer (CISO)” is a senior executive responsible for establishing, implementing, and maintaining AV’s enterprise vision, strategy, and cybersecurity program to ensure... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    For subcontractor
    Work at office

    AeroVironment

    Simi Valley, CA
    2 days ago
  •  ...more details.Role Overview:MUFG is seeking a highly motivated Security Engineer to design, develop, and deploy autonomous agents that...  ...EngineerMicrosoft Certified: Azure AI Engineer AssociateCertified Information Systems Security Professional (CISSP)“Visa sponsorship/support... 
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    3 days ago
  •  ...stewardship models aligned with HIPAA, CLIA, CAP, FDA, GxP, and GDPR.Provides strategic oversight to ensure compliance with privacy, information security, and consent management requirements for genetic and clinical data.Oversee protection and access controls for PHI and... 
    Full time
    Temporary work
    Casual work
    Internship
    Work at office
    Monday to Friday
    Flexible hours
    Day shift
    3 days per week

    Laboratory Corporation of America

    Burlington, NC
    4 days ago
  • $150k - $210k

     ...manage technology risk through modern, cloud-aligned and AI-informed security practices. CDRR executes first line of defence technology risk...  ...information, please visit: .Employment Type:Full timeJob Level:Vice PresidentPosted Date:Apr 21, 2026ATS Job Description Test:... 
    Temporary work

    Morgan Stanley

    New York, NY
    4 days ago
  •  ...TN, E-3, etc.). Applicants requiring visa sponsorship to start employment with Eversource will not be considered.Vice President, Chief Information Security OfficerJob DescriptionThe Vice President, Chief Information Security Officer (CISO) is the enterprise executive accountable... 
    Full time
    H1b

    Eversource Energy

    Berlin, CT
    4 days ago
  •  ...Vice President, Deputy Chief Information Security Officer About the Company Pioneering cybersecurity solutions platform Industry Computer & Network Security Type Privately Held, VC-backed Founded 2012 Employees 1001-5000 Funding $26-$50 million... 

    Confidential

    Pleasant Grove, UT
    1 day ago
  •  ...Vice President of GTM Operations About the Company Top provider of an enterprise process...  ...Software SaaS Software Information Technology & Services Technology...  ...third party risk management information security risk policy and procedure management... 

    Confidential

    Chicago, IL
    5 days ago
  •  ...Vice President, Artificial Intelligence About the Company Top provider of information security & analytics services Industry Computer & Network Security Type Public Company Founded 2000 Employees 1001-5000 Categories Enterprise Software... 

    Confidential

    San Bernardino, CA
    3 days ago
  •  ...Vice President of Information Security About the Company Leading GIS company providing high-res aerial imagery & analytics Industry Information Technology and Services Type Privately Held, Private Equity-backed Founded 2008 Employees 1001-50... 

    Confidential

    San Jose, CA
    5 days ago
  •  ...Vice President, Information Security, Manufacturing Plant Security, Product Security & Application Security About the Company Dynamic manufacturer & marketer of medical devices Industry Medical Devices Type Public Company Founded 1969 Employees... 

    Confidential

    Austin, TX
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vice President, Information Security. Be the first to apply!