Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Chief Information Security Officer (CISO)

SpringHealth Behavioral Health & Integrated Care

Chief Information Security Officer (CISO)

Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage. Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners. As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.

The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health's enterprise-wide information security, technology risk, compliance, and IT strategy. This leader will ensure the protection of company assets, customer data, member data, provider data, and critical systems while enabling business growth, innovation, and operational scale.

Reporting to the Chief Technology Officer, the CISO will lead the company's Information Security, Compliance/GRC, and IT functions, including Security Operations, Application/Product Security, cloud and infrastructure security, identity and access management, third-party risk, incident response, enterprise compliance, corporate IT, and business technology operations. This leader will manage and partner closely with senior security and IT leaders, including the VP, Information Security.

The CISO will serve as a trusted advisor to executive leadership and the Board on cybersecurity risk, regulatory readiness, enterprise resilience, customer trust, and technology risk. They will play a critical role in Spring Health's next phase of scale, including the integration of Alma, enterprise customer growth, AI transformation, international expansion, and readiness for future public-company expectations.

This leader will be responsible for building a security and IT organization that enables the business, supports product velocity, protects sensitive healthcare data, and earns the trust of customers, members, providers, partners, regulators, and employees.

Please note that this is a hybrid role based in either New York City or San Francisco, with an expectation to be in the office 2–3 days per week. Candidates must be based in the NYC or SF metro areas or able to relocate independently within 90 days of their start date. Frequent travel will be required for leadership meetings and to visit various office locations.

What You'll Do

  • Develop and execute Spring Health's enterprise-wide information security, compliance, technology risk, and IT strategy in alignment with company priorities, growth plans, and regulatory obligations.
  • Lead the Information Security, Compliance/GRC, and IT organizations, including Security Operations, Application/Product Security, cloud and infrastructure security, enterprise compliance, corporate IT, identity and access management, and business technology operations.
  • Partner closely with the CTO, executive leadership team, Legal, Privacy, Compliance, Product, Engineering, Sales, Customer Success, People, Finance, and other stakeholders to ensure security and IT enable the business rather than create unnecessary friction.
  • Serve as a trusted advisor to executive leadership and the Board on cybersecurity risks, technology risk, regulatory readiness, incident response, enterprise resilience, customer trust, and security investments.
  • Build and scale a high-performing organization across security, compliance, and IT, including developing leaders, clarifying ownership, improving operating rhythms, and ensuring the team has the right structure, capabilities, and culture for Spring's next stage of growth.
  • Oversee enterprise security operations, including threat detection, vulnerability management, incident response, security monitoring, endpoint security, SIEM strategy, threat intelligence, and resilience exercises.
  • Ensure Spring Health's Application/Product Security and cloud security programs are deeply embedded in the software development lifecycle, including secure architecture, threat modeling, automated testing, vulnerability remediation, and security review processes.
  • Own the enterprise compliance and information security risk management program, including risk assessments, risk registers, risk treatment plans, control frameworks, policy governance, and executive reporting.
  • Ensure successful compliance outcomes across applicable frameworks and regulations, including HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other healthcare, privacy, and security requirements.
  • Partner with Legal and Privacy on data protection, privacy, regulatory obligations, Business Associate Agreements, customer commitments, breach assessment, notification obligations, and evolving healthcare security requirements.
  • Lead security and IT strategy related to the Alma integration, including systems, data flows, access controls, compliance obligations, enterprise risk, provider/member/customer data protection, and long-term operating model decisions.
  • Define and govern Spring Health's AI security strategy, including enterprise AI guardrails, approved tool usage, data classification, model/tool risk assessment, secure AI adoption, and protection of sensitive healthcare and business data.
  • Oversee corporate IT and business technology operations, including employee technology experience, endpoint management, access lifecycle, SaaS governance, corporate applications, IT service delivery, and operational excellence.
  • Serve as a senior executive sponsor in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, customer escalations, and technical diligence with large enterprise buyers.
  • Build scalable customer trust processes, security narratives, artifacts, and evidence practices that reduce friction for Sales and Customer Success while maintaining strong risk discipline.
  • Lead the organization's response to significant security incidents, including technical response, executive communication, customer communication, legal/compliance partnership, regulatory considerations, post-incident review, and remediation.
  • Manage security, compliance, and IT budgets, vendor relationships, tooling strategy, cyber insurance engagement, external audit partnerships, and key technology investments.
  • Establish security, compliance, and IT metrics that give executive leadership and the Board clear visibility into risk posture, program maturity, operational performance, and investment priorities.
  • Drive a company-wide culture of security, privacy, accountability, and responsible innovation.

What Success Looks Like

  • A clear, enterprise-wide security, compliance, and IT strategy is in place with defined priorities, milestones, KPIs, ownership, and executive/Board visibility.
  • The Security, Compliance/GRC, and IT teams have a clear operating model, strong leadership, healthy collaboration, and the right structure to support Spring's scale post-Alma.
  • Spring Health maintains strong regulatory and compliance outcomes, including successful audits, certifications, customer reviews, and healthcare compliance obligations.
  • Security and IT are viewed as business enablers by Product, Engineering, Sales, Customer Success, Legal, Compliance, People, Finance, and executive leadership.
  • Alma integration work is progressing with clear security, compliance, IT, data, access, and risk-management priorities.
  • AI adoption is supported by clear security guardrails, practical governance, and scalable controls that enable innovation while protecting sensitive data.
  • Enterprise customer security reviews, audits, RFPs/RFIs, and escalations are handled efficiently and credibly, with repeatable processes that reduce friction and build customer trust.
  • Security is embedded in product and engineering workflows, with clear requirements, tooling, review processes, and accountability across the SDLC.
  • Incident response, crisis management, business continuity, and operational resilience programs are tested, understood, and effective.
  • Corporate IT provides a strong employee experience while maintaining disciplined access management, endpoint security, SaaS governance, and operational controls.
  • Executive leadership, customers, partners, auditors, regulators, and the Board have confidence in Spring Health's security, compliance, and IT posture.

What You'll Bring

  • 15+ years of progressive experience across Information Security, cybersecurity, IT, technology risk, or related disciplines, with significant experience in executive security leadership roles.
  • Demonstrated experience leading multi-functional security organizations across Security Operations, Application/Product Security, cloud security, GRC/compliance, identity and access management, incident response, and third-party risk.
  • Experience leading or closely partnering with IT, corporate technology, business applications, employee technology, endpoint management, SaaS governance, and access lifecycle functions.
  • Deep working knowledge of HIPAA and hands-on experience leading security and compliance programs in a covered entity or business associate environment.
  • Experience owning or overseeing HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other relevant third-party security, privacy, and compliance programs.
  • Strong understanding of healthcare technology, sensitive data environments, enterprise customer expectations, and the security/compliance requirements that come with serving large employers, health plans, providers, members, and partners.
Vacancy posted 7 hours ago
Similar jobs that could be interesting for youBased on the Chief Information Security Officer (CISO) in San Francisco, CA vacancy
  • $250k

     ...Chief Information Security Officer The San Francisco, CA office of Lewis Brisbois, a full-service AmLaw 100 firm, is seeking a Chief Information...  ...Security Officer. The Chief Information Security Officer (CISO) is a senior executive responsible for developing, implementing... 
    Suggested
    Work at office

    Lewis Brisbois Bisgaard & Smith

    San Francisco, CA
    5 days ago
  • $260.5k - $325.6k

     ...unprecedented dataset of empirical information via a revolutionary cloud-based platform...  ..., and software engineering, our office is a truly inspiring mix of experts...  ...Role: As the Vice President and Chief Information Security Officer (CISO), you will serve as a key executive... 
    Suggested
    Full time
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work
    Home office
    Shift work
    3 days per week

    Planet Labs

    San Francisco, CA
    3 days ago
  • $250k - $350k

     ...aircraft, and field infrastructure. Security must protect those systems, customers...  ...to deliver safely and quickly.As Chief Information Security Officer, you will own company-wide security...  ...adoption.What You'll BringExperience as a CISO, VP of Security, or equivalent... 
    Suggested
    Local area

    Zipline

    South San Francisco, CA
    3 days ago
  •  ...how the HealthTech ecosystem connects. We're looking for a Security Lead to own our security governance, compliance, IT...  ...governance, compliance, and IT programs end-to-end.Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA — own the policy... 
    Suggested
    Live in

    NexHealth

    San Francisco, CA
    4 days ago
  •  ...become more extreme and confidential information about models and frontier AI labs...  ...and internal agents.  As METR’s CISO, you will own METR’s overall security posture, proactively planning...  ...also has a host of benefits: The office: Catered lunch and dinner daily; in... 
    Suggested
    H1b
    Work at office
    Work from home
    Home office
    Relocation package
    3 days per week

    METR

    Berkeley, CA
    3 days ago
  •  ...infrastructure This is a ground-floor opportunity to build a security organisation from scratch, setting policies, controls, and...  ...Responsibilities: Define and execute the company-wide information security and compliance strategy across infrastructure, cloud,... 
    Permanent employment
    Remote work
    Flexible hours
    San Francisco, CA
    more than 2 months ago
  •  ...budgets and overseeing operations of server systems risks by ensuring that systems and processes are in place to safeguard sensitive information pursuant to applicable law and best practices. Create and implement tools, metrics, policies and processes. Streamline... 

    Sales Demo - Juliet Rausch

    San Francisco, CA
    2 days ago
  • Telecommunications ManagerThe major duties of the Telecommunications Manager include, but are not limited to, the following:Managing, coordinating, and administrating operations of a communications centerDirect supervision of public safety dispatch supervisors and public...

    Department of the Interior

    San Francisco, CA
    8 hours ago
  •  ...Manager Of Communications CenterThis position acts as manager of the communications center which is located in the San Francisco Field Office Dispatch Operations Center of the United States Park Police. The Dispatch Operations Center operates 24-hours a day/ 7 days a week... 
    Work at office

    US Government Jobs

    San Francisco, CA
    1 day ago
  •  ...communications center which is located in the San Francisco Field Office Dispatch Operations Center of the United States Park Police....  ...statistics, computer science, telecommunications management, information systems management, business administration, industrial... 
    Permanent employment
    Full time
    Part time
    Work at office
    Immediate start
    Trial period
    Relocation package
    Shift work
    Weekend work
    Afternoon shift

    National Park Service

    San Francisco, CA
    4 days ago
  • Job description: Location: San Francisco, CA (on-site)Employment: Full-TimeAbout the RoleWe are looking for a Founding CTO, someone who wants to be the company's technical co-pilot. You will start hands-on, ship fast, and own the core architecture. As the company scales...
    Relocation

    Affinity Executive Search

    San Francisco, CA
    3 days ago
  • $191.1k - $320.6k

     ...strategic extension of the CRO's office — a trusted voice who can...  ...Architect role — it's a junior Chief Customer Officer: someone who...  ..., addressing platform/security/scale objections, and unblocking...  ...Candidate Privacy Statement for more information about how we use your... 
    Full time
    Work at office

    Salesforce

    San Francisco, CA
    1 day ago
  • $201.11k - $269.08k

     ...required to make them successful. They can engage credibly with Chief Data Officers, CIOs, Enterprise Architects, Data Governance leaders, and...  .... Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including... 
    Full time
    Work at office

    Salesforce

    San Francisco, CA
    3 days ago
  •  ...Field Chief Technology Officer (Field CTO) MinIO Bay Area MinIO is the data and memory foundation...  ...applications, and autonomous agents secure, persist, and unlock the full value...  ..., age, veteran status, genetic information, physical or mental disability, medical... 
    Flexible hours

    Minio, Inc.

    San Francisco, CA
    1 day ago
  •  ...headquartered in San Francisco, CA. and has an office in Cambridge, MA.  About the role:...  ...We are looking for an experienced IT & Security Administrator to support Lumafield's day...  ..., gender identity, disability, genetic information or veteran status.    Reach out if... 
    Work at office
    Flexible hours

    Lumafield

    San Francisco, CA
    a month ago
  • $119k - $299.93k

     ...of financial statements, internal controls, and other critical information, enhancing their credibility and reliability for various...  ...members. We evaluate these factors thoughtfully to establish a secure and trusted workplace for all.SummaryLocation: NY-New York; FL... 
    Full time
    H1b

    PwC

    San Francisco, CA
    4 days ago
  • Veriswap is seeking a driven individual for a role involving proactive planning and management of the CEO and CTO’s appointments. While mostly remote, some assistance is required in person near Palo Alto, CA. The ideal candidate will be highly organized with a zest for ...
    Remote job

    Veriswap

    San Francisco, CA
    3 days ago
  • $1,750 - $2,150 per month

     ...outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios...  ...For details about the interview process and platform information, please check: For any help or support, reach out to: support... 
    Hourly pay
    Full time
    Contract work
    Summer work
    Remote work

    Mercor

    San Francisco, CA
    more than 2 months ago
  • $124k - $280k

     ...Science, Business Administration/Management, Computer Science/Information Systems, Economics, Engineering, Finance, Financial Mathematics...  .... We evaluate these factors thoughtfully to establish a secure and trusted workplace for all.SummaryLocation: CA-San FranciscoType... 
    Full time
    H1b

    PwC

    San Francisco, CA
    1 day ago
  •  ...outcomes include 42% of food-insecure members becoming food-secure within six months, meaningful weight loss and HbA1c improvement...  ...to a pod-based operating model and brought on a strong Chief Product Officer who will be the CTO's closest counterpart in building and shipping... 
    Remote work
    Flexible hours

    Foodsmart

    San Francisco, CA
    3 days ago
  • $99k - $232k

     ...Science, Business Administration/Management, Computer Science/Information Systems, Economics, Engineering, Finance, Financial Mathematics...  .... We evaluate these factors thoughtfully to establish a secure and trusted workplace for all.SummaryLocation: CA-San Francisco... 
    Full time
    H1b

    PwC

    San Francisco, CA
    3 days ago
  •  ...cases such as LLM applications, integrations, data pipelines, and security. Act as a trusted advisor to ensure long-term success, not...  ...customer insights back to Product and Engineering teams to inform roadmap and prioritization. Identify gaps, opportunities, and... 
    Temporary work

    Openai

    San Francisco, CA
    1 day ago
  •  ...securitization)Work Location San FranciscoThe above locations are eligible offices for this role. The locations have been determined to foster in...  ..., we will collect the following categories of personal information from or about you: contact information, identifiers,... 
    Full time
    Work at office
    Local area
    Remote work
    Relocation
    Flexible hours

    Lending Club

    San Francisco, CA
    5 days ago
  • At BairesDev®, we've been leading the way in technology projects for over 15 years. We deliver cutting-edge solutions to giants like Google and the most innovative startups in Silicon Valley. Our diverse 4,000+ team, composed of the world's Top 1% of tech talent, works...
    Remote work
    Work from home
    Worldwide

    BairesDev

    San Francisco, CA
    1 day ago
  •  ...ownership over process. You enjoy building elite teams as much as building software. You’re comfortable making decisions with imperfect information. You want your fingerprints on every part of the company. Why This Role? Founding executive position with significant equity... 

    Eden Prescott

    San Francisco, CA
    4 days ago
  • $131.78k - $151.74k

     ...Analyzes the patient's posture, spin, and reflexes. Diagnoses any health problems by reviewing patient's medical history and information provided during observational questions and examination. Performs spinal adjustments and other bodily adjustments with the purpose... 

    North East Medical Services

    San Francisco, CA
    5 days ago
  • $170.6k - $234.2k

     ...range of consumer experiences and devices. The Business Information Security Officer (BISO) serves as the primary liaison between the Business Unit...  ...Cybersecurity organization. Operating on behalf of the CISO, the BISO embeds within the business to understand its strategy... 
    Full time
    Local area
    Worldwide
    Flexible hours

    Dolby

    San Francisco, CA
    7 hours ago
  •  ...Chief Information OfficerCIOSan Francisco, CAChemicalsJO-1901-1162As a key member of a growing team, the CIO will report to the COO. The ideal...  ...goals of the company and its subsidiaries; operate in a secure and compliant manner at all times; demonstrate value for money... 
    Work experience placement
    Flexible hours

    The Ceres Group

    San Francisco, CA
    4 days ago
  • $105.4k - $207.8k

     ...navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support...  ..., and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation... 
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    1 day ago
  • $68k - $133.9k

     ...change in complex environments. Qualifications Required: • Bachelor’s degree in Computer Engineering, Computer Science, Information Systems, Cyber Security, or another technical field • 1+ years of experience in infrastructure or application architecture across on-premise... 
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Chief Information Security Officer (CISO). Be the first to apply!