Vice President, Information Security
$250k - $291kSpringHealth Behavioral Health & Integrated Care
Vice President, Information Security
Remote
Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage. Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners. As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.
Reporting to the CISO, the Vice President, Information Security will lead Spring Health's Security Operations and Application/Product Security functions, ensuring the protection of company assets, customer data, and critical systems while enabling business growth and innovation. This leader will provide strategic and hands-on direction across threat detection and response, vulnerability management, application and cloud security, secure software development, security architecture, incident response, compliance execution, audit readiness, and enterprise customer-facing security strategy.
The VP, Information Security will partner closely with the CISO, Engineering, Product, Legal, Compliance, Sales, Customer Success, and enterprise customers to strengthen Spring Health's security posture and embed security into product and engineering decision-making. This leader will help mature Spring's operational, product security, and compliance capabilities, support customer trust with large enterprise clients, and ensure Spring remains resilient against evolving cyber threats while balancing security, regulatory obligations, innovation, and business velocity.
This is a remote position with frequent travel required for leadership on-sites in NYC and occasional travel to our other offices in San Francisco and Seattle.
What You'll Do
- Lead Spring Health's Security Operations and Application/Product Security functions, including threat detection, vulnerability management, incident response, application security, cloud security, and secure SDLC practices.
- Develop and execute the roadmap for Security Operations and Application/Product Security in alignment with Spring Health's broader information security strategy.
- Partner closely with the CISO, Engineering, Product, Legal, Compliance, Sales, Customer Success, and IT to strengthen Spring Health's security posture while enabling business growth and innovation.
- Own the day-to-day execution of Spring Health's information security compliance programs, partnering with the CISO, Legal, Privacy, and Compliance teams to maintain audit readiness and strong control discipline.
- Serve as a senior security leader in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, technical diligence, and customer escalations.
- Build scalable processes, artifacts, and technical narratives that help enterprise customers understand and trust Spring Health's security practices.
- Ensure customer-facing security and compliance materials accurately reflect Spring Health's controls, certifications, policies, remediation plans, and risk posture.
- Translate customer security requirements and recurring diligence themes into actionable product, engineering, and security priorities.
- Embed security throughout the software development lifecycle, including threat modeling, secure design reviews, secure code review, automated security testing, CI/CD controls, and vulnerability remediation.
- Provide security architecture review and guidance for new products, features, cloud environments, data flows, and third-party integrations.
- Own the Security Operations function and related tooling strategy, including SIEM, threat intelligence, endpoint detection and response, automation, alert triage, and response workflows.
- Lead the operational response to security incidents, including technical investigation, containment, remediation, executive updates, post-incident review, and partnership with Legal and Compliance on regulatory obligations.
- Oversee vulnerability management, penetration testing, responsible disclosure or bug bounty processes, and remediation programs across applications, cloud environments, and infrastructure.
- Lead audit readiness and certification execution for information security programs, including evidence collection, technical control validation, remediation tracking, and partnership with the CISO, Legal, Privacy, and Compliance teams on frameworks such as HITRUST, SOC 2, ISO 27001, HIPAA, and PCI DSS.
- Build, mentor, and develop high-performing Security Operations and Application/Product Security teams.
- Manage budgets, technology investments, vendor relationships, and tooling strategy for Security Operations and Application/Product Security.
- Drive a security culture across Engineering, Product, and business teams that enables innovation while maintaining appropriate risk controls.
What Success Looks Like
- A documented Security Operations and Application/Product Security roadmap is in place with clear milestones, KPIs, ownership, and measurable progress.
- Strong technical control and compliance outcomes that support successful audits, certifications, customer reviews, and ongoing regulatory readiness.
- Compliance programs are operationally well-run, with clear ownership, timely evidence collection, effective remediation tracking, and strong partnership across Security, Legal, Privacy, Engineering, Product, and IT.
- Reduced organizational risk through proactive threat detection, vulnerability remediation, and security architecture, and effective technical security controls.
- High levels of security resilience demonstrated through effective incident response and crisis management.
- Security is embedded in the SDLC, development teams have clear security requirements, tooling, and a consistent process for security review.
- Enterprise client security questionnaires and audits are handled efficiently, with documented repeatable processes that reduce friction for the Sales and Customer Success teams.
- Meaningful improvements in security awareness and accountability across the organization.
- Executive leadership, customers, partners, and regulators have confidence in the company's security posture.
- A highly engaged, high-performing security team with strong retention
What You'll Bring
- 12+ years of progressive experience in Information Security, with at least 5 years in a senior leadership role.
- Demonstrated experience building and leading multi-functional security teams, especially across Security Operations, Application/Product Security, cloud security, vulnerability management, and incident response.
- Demonstrated ability to communicate security risk to executive engineering, product, and customer audiences, translating technical issues into business impact, customer impact, and clear mitigation plans.
- Strong working knowledge of HIPAA and healthcare security requirements, with experience owning or operationally leading security compliance work in covered entity or business associate environments.
- Experience leading or supporting HITRUST CSF, SOC 2, ISO 27001, PCI DSS, and comparable certification programs through strong technical controls, remediation management, evidence support, audit readiness, and cross-functional partnership.
- Experience translating compliance requirements into practical security controls, engineering requirements, operational processes, and customer-facing narratives.
- One or more recognized industry certifications relevant to a role at this level preferred such as CISSP, CISM, CCISO, CRISC, or CISA.
- Experience building partnerships across the organization, enabling innovation in a safe and risk-aware way — a track record of being a business enabler, not a gatekeeper.
- Experience serving as a senior security leader in client-facing enterprise security reviews, audits, RFP/RFI responses, technical diligence, and customer escalations.
- Experience owning operational incident response programs and partnering with Legal, Compliance, and executive stakeholders on breach assessment, communications, and notification obligations.
- Strong working knowledge of cloud security principles and modern SaaS architecture security requirements.
- Track record of partnering effectively with executive leadership, Engineering, Product, Legal, Compliance, Sales, Customer Success, auditors, and enterprise customers.
- Deep knowledge of security operations, threat management, vulnerability management, and incident response.
- Strong expertise in cloud security, application security, identity and access management, and security architecture.
- Strategic mindset with strong business and risk management acumen.
- Ability to balance security requirements with customer experience, innovation, and business objectives.
The target base salary range for this position is $250,000 - $291,000, and is part of a competitive total rewards package including equity and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.
Benefits provided by Spring Health:
Note : We have even more benefits than listed here and below, your recruiter will provide more in-depth information as you continue in the interview process. Benefits are subject to individual plan requirements and eligibility criteria.
$275k - $290k
...’s worth paying for. About the Role:As Vice President, Cybersecurity and Deputy CISO, you will... ....You will:Lead and integrate core security functions, including security architecture... ...progressive experience in cybersecurity or information security, including leadership of large...SuggestedWork at officeLocal areaFlexible hours3 days per week- Endpoint Security Engineer At BNY, our culture allows us to run our company better and enables employees' growth and success.... ...Disabilities/Protected Veterans.**POSITION SUMMARY:** The Vice President, Information Security plays a pivotal role in safeguarding BNY's information...SuggestedWork at officeWorldwideFlexible hours
$251.9k - $314.9k
...LocationCINCINNATI GENERAL OFFICESJob DescriptionP&G is searching for a senior technical leader to join the company as the Vice President of Information Security - Identity, Data Protection & Governance. This role will lead the enterprise strategy for identity security, data...SuggestedFull timeWork at office- ...extraordinary journey today. Position Summary The Vice President of Information Technology leads the technology foundation that RPM Living... .... Responsibilities Own the enterprise information security program anchored to a recognized framework (NIST CSF 2.0...SuggestedWeekly payFull timeStart working todayLive inWork at officeNight shift
$250k - $350k
...where you and your unique viewpoint matter. Learn about the Danaher Business System which makes everything possible.The Vice President, Information Security - Manufacturing Plant Security, Product Security & Application Security is responsible for protecting Danaher’s...SuggestedFull timeRemote workWorldwide- We’re seeking a future team member for the role of Vice President, Information Security to join our information Security team. This role is located in Lake Mary, Florida or Pittsburg, PA.In this role, you’ll make an impact in the following ways: Lead the design, development...Work experience placementWorldwideFlexible hours
- WHO WE ARELed by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats... ...operational oversight and risk management.YOUR IMPACTAs a Vice President in the Risk Practices and Control Management Team within...Work at office
- We’re seeking a future team member for the role of Vice President, Cloud Security Engineer to join our Cloud Security team. This role is located in New York.In this role, you’ll make an impact in the following ways:Support implementation and continuous improvement of cloud...WorldwideFlexible hours
- ...business processes, technology solutions, products, and customer experiences Partner with Compliance, Enterprise Risk Management, Information Security, Technology, Data Governance, Legal, Internal Audit, and business leaders Identify, assess, monitor, and report privacy-...
- ...Vice President, Information SecurityWe're seeking a future team member for the role of Vice President, Information Security to join our information Security team. This role is located in Lake Mary, Florida or Pittsburg, PA.In this role, you'll make an impact in the following...Work experience placementFlexible hours
- ...Vice President, Information SecurityThe Vice President, Information Security provides executive leadership for the design, evolution, and operational oversight of security engineering capabilities that protect the organization’s systems, data, and digital services. This...
- ...Vice President, Deputy Chief Information Security Officer About the Company Pioneering cybersecurity solutions platform Industry Computer & Network Security Type Privately Held, VC-backed Founded 2012 Employees 1001-5000 Funding $26-$50 million...
- ...leadership for the IT Team, ensuring technology services are secure, reliable, and aligned with Nutmeg’s strategic priorities. This... ...models, and solutions with strategic and operational objectives. Information Security Operations & Technology Risk Oversee technology...Full time
- ...Vice President, Information SecurityDenver, CO; Atlanta, GAAbout ProcareFor over 30 years, Procare Solutions has been dedicated to empowering early... ...for young minds.A Little About the RoleThe VP Information Security is a senior leader responsible for establishing and...Shift work
$250k
...Vice President of Information Technology (VP of IT) Compensation: Up to $250K base + 30% target bonus Position Type: Full-Time | Newly Created... ...technology strategy, infrastructure design, and information security standards. Key Responsibilities Build and scale the U.S....Full time- ...Vice President, Cloud Security EngineerWe're seeking a future team member for the role of Vice President, Cloud Security Engineer to join our Cloud Security team. This role is located in New York.In this role, you'll make an impact in the following ways:Support implementation...Flexible hours
$138.3k - $148.95k
...Associate Vice President for Information Technology ServicesPosition Title: Associate Vice President for Information Technology ServicesDepartment... ...and validate the enterprise's compliance with ITS security policies, which includes but is not limited to Sarbanes Oxley...Full timeWork at officeLocal areaRemote workRelocationFlexible hoursAfternoon shift$226k - $339.7k
...seeking a strategic and highly technical Vice President to lead our global Cyber Exposure... ...defense capabilities, shape long-term security architecture strategy, and lead large-scale... ...This role reports directly to the Chief Information Security Officer (CISO) and partners closely...Full timeWork at office- ...more details.Role Overview:MUFG is seeking a highly motivated Security Engineer to design, develop, and deploy autonomous agents that... ...EngineerMicrosoft Certified: Azure AI Engineer AssociateCertified Information Systems Security Professional (CISSP)“Visa sponsorship/support...Full timeWork experience placementWork at officeLocal areaRemote work1 day per week
- ...TN, E-3, etc.). Applicants requiring visa sponsorship to start employment with Eversource will not be considered.Vice President, Chief Information Security OfficerJob DescriptionThe Vice President, Chief Information Security Officer (CISO) is the enterprise executive accountable...Full timeH1b
- ...is your chance to be part of something exceptional.What You’ll DoTechnology and security are inseparable from business success at Centric. As the executive responsible for both Information Systems and Cybersecurity, you will establish the strategic vision for how technology...Full time
$150k - $250k
WHO WE ARELed by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats... ...to manage risk portfolios.As the Vendor Risk Program Vice President, you will be part of or oversee a team that is responsible...- ...stewardship models aligned with HIPAA, CLIA, CAP, FDA, GxP, and GDPR.Provides strategic oversight to ensure compliance with privacy, information security, and consent management requirements for genetic and clinical data.Oversee protection and access controls for PHI and...Full timeTemporary workCasual workInternshipWork at officeMonday to FridayFlexible hoursDay shift3 days per week
$150k - $210k
...manage technology risk through modern, cloud-aligned and AI-informed security practices. CDRR executes first line of defence technology risk... ...information, please visit: .Employment Type:Full timeJob Level:Vice PresidentPosted Date:Apr 21, 2026ATS Job Description Test:...Temporary work- WHO WE ARELed by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure...
$245.5k - $393k
Worker TypeRegularJob DescriptionSummaryThe “Vice President of Cybersecurity & Chief Information Security Officer (CISO)” is a senior executive responsible for establishing, implementing, and maintaining AV’s enterprise vision, strategy, and cybersecurity program to ensure...Permanent employmentFull timeContract workWork experience placementFor subcontractorWork at office$260.5k - $325.6k
...constellation delivers an unprecedented dataset of empirical information via a revolutionary cloud-based platform to... ...Slovenia, and The Netherlands.About the Role: As the Vice President and Chief Information Security Officer (CISO), you will serve as a key executive and...Full timeContract workTemporary workWork experience placementWork at officeLocal areaRemote workHome officeShift work3 days per week$219k - $268k
...Full Time Vice President Information TechnologyJoin Lunds & Byerlys as a Full Time Vice President Information Technology and take the next exciting... ..., business systems, application development, information security, and IT support, while ensuring technology investments...Full timeContract workWork at office$200k - $250k
...scale (GTM) Instrument deployment, usage, and outcome data to inform roadmap and pricing decisions Own AI success metrics... ...just be able to find another role that could be a perfect fit! Security and Privacy Requirements Responsible for Granicus information...Remote workHome officeFlexible hours- ...Vice President of Information TechnologyThe Vice President of Information Technology serves as First State Bank and Trust's internal owner of the... ...to carry personal accountability for the reliability, security, and performance of the Bank's technology, including work...Bank staffRelocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vice President, Information Security. Be the first to apply!
- vp customer success United States
- vice president development United States
- vice president real estate development United States
- vice president communications United States
- vice president manufacturing United States
- vp safety United States
- vp controller United States
- vp of benefits and total rewards United States
- vice president research United States
- vice president tax United States

