Chief Information Security Officer (CISO)
$299k - $344kSpring Health
Our mission: e liminating every barrier to mental health.
Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage.
Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners. As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health’s enterprise-wide information security, technology risk, compliance, and IT strategy. This leader will ensure the protection of company assets, customer data, member data, provider data, and critical systems while enabling business growth, innovation, and operational scale.
Reporting to the Chief Technology Officer, the CISO will lead the company’s Information Security, Compliance/GRC, and IT functions, including Security Operations, Application/Product Security, cloud and infrastructure security, identity and access management, third-party risk, incident response, enterprise compliance, corporate IT, and business technology operations. This leader will manage and partner closely with senior security and IT leaders, including the VP, Information Security.
The CISO will serve as a trusted advisor to executive leadership and the Board on cybersecurity risk, regulatory readiness, enterprise resilience, customer trust, and technology risk. They will play a critical role in Spring Health’s next phase of scale, including the integration of Alma, enterprise customer growth, AI transformation, international expansion, and readiness for future public-company expectations.
This leader will be responsible for building a security and IT organization that enables the business, supports product velocity, protects sensitive healthcare data, and earns the trust of customers, members, providers, partners, regulators, and employees.
Please note that this is a hybrid role based in either New York City or San Francisco , with an expectation to be in the office 2–3 days per week. Candidates must be based in the NYC or SF metro areas or able to relocate independently within 90 days of their start date. Frequent travel will be required for leadership meetings and to visit various office locations.
What You'll Do
- Develop and execute Spring Health’s enterprise-wide information security, compliance, technology risk, and IT strategy in alignment with company priorities, growth plans, and regulatory obligations.
- Lead the Information Security, Compliance/GRC, and IT organizations, including Security Operations, Application/Product Security, cloud and infrastructure security, enterprise compliance, corporate IT, identity and access management, and business technology operations.
- Partner closely with the CTO, executive leadership team, Legal, Privacy, Compliance, Product, Engineering, Sales, Customer Success, People, Finance, and other stakeholders to ensure security and IT enable the business rather than create unnecessary friction.
- Serve as a trusted advisor to executive leadership and the Board on cybersecurity risks, technology risk, regulatory readiness, incident response, enterprise resilience, customer trust, and security investments.
- Build and scale a high-performing organization across security, compliance, and IT, including developing leaders, clarifying ownership, improving operating rhythms, and ensuring the team has the right structure, capabilities, and culture for Spring’s next stage of growth.
- Oversee enterprise security operations, including threat detection, vulnerability management, incident response, security monitoring, endpoint security, SIEM strategy, threat intelligence, and resilience exercises.
- Ensure Spring Health’s Application/Product Security and cloud security programs are deeply embedded in the software development lifecycle, including secure architecture, threat modeling, automated testing, vulnerability remediation, and security review processes.
- Own the enterprise compliance and information security risk management program, including risk assessments, risk registers, risk treatment plans, control frameworks, policy governance, and executive reporting.
- Ensure successful compliance outcomes across applicable frameworks and regulations, including HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other healthcare, privacy, and security requirements.
- Partner with Legal and Privacy on data protection, privacy, regulatory obligations, Business Associate Agreements, customer commitments, breach assessment, notification obligations, and evolving healthcare security requirements.
- Lead security and IT strategy related to the Alma integration, including systems, data flows, access controls, compliance obligations, enterprise risk, provider/member/customer data protection, and long-term operating model decisions.
- Define and govern Spring Health’s AI security strategy, including enterprise AI guardrails, approved tool usage, data classification, model/tool risk assessment, secure AI adoption, and protection of sensitive healthcare and business data.
- Oversee corporate IT and business technology operations, including employee technology experience, endpoint management, access lifecycle, SaaS governance, corporate applications, IT service delivery, and operational excellence.
- Serve as a senior executive sponsor in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, customer escalations, and technical diligence with large enterprise buyers.
- Build scalable customer trust processes, security narratives, artifacts, and evidence practices that reduce friction for Sales and Customer Success while maintaining strong risk discipline.
- Lead the organization’s response to significant security incidents, including technical response, executive communication, customer communication, legal/compliance partnership, regulatory considerations, post-incident review, and remediation.
- Manage security, compliance, and IT budgets, vendor relationships, tooling strategy, cyber insurance engagement, external audit partnerships, and key technology investments.
- Establish security, compliance, and IT metrics that give executive leadership and the Board clear visibility into risk posture, program maturity, operational performance, and investment priorities.
- Drive a company-wide culture of security, privacy, accountability, and responsible innovation.
What Success Looks Like
- A clear, enterprise-wide security, compliance, and IT strategy is in place with defined priorities, milestones, KPIs, ownership, and executive/Board visibility.
- The Security, Compliance/GRC, and IT teams have a clear operating model, strong leadership, healthy collaboration, and the right structure to support Spring’s scale post-Alma.
- Spring Health maintains strong regulatory and compliance outcomes, including successful audits, certifications, customer reviews, and healthcare compliance obligations.
- Security and IT are viewed as business enablers by Product, Engineering, Sales, Customer Success, Legal, Compliance, People, Finance, and executive leadership.
- Alma integration work is progressing with clear security, compliance, IT, data, access, and risk-management priorities.
- AI adoption is supported by clear security guardrails, practical governance, and scalable controls that enable innovation while protecting sensitive data.
- Enterprise customer security reviews, audits, RFPs/RFIs, and escalations are handled efficiently and credibly, with repeatable processes that reduce friction and build customer trust.
- Security is embedded in product and engineering workflows, with clear requirements, tooling, review processes, and accountability across the SDLC.
- Incident response, crisis management, business continuity, and operational resilience programs are tested, understood, and effective.
- Corporate IT provides a strong employee experience while maintaining disciplined access management, endpoint security, SaaS governance, and operational controls.
- Executive leadership, customers, partners, auditors, regulators, and the Board have confidence in Spring Health’s security, compliance, and IT posture.
What You'll Bring
- 15+ years of progressive experience across Information Security, cybersecurity, IT, technology risk, or related disciplines, with significant experience in executive security leadership roles.
- Demonstrated experience leading multi-functional security organizations across Security Operations, Application/Product Security, cloud security, GRC/compliance, identity and access management, incident response, and third-party risk.
- Experience leading or closely partnering with IT, corporate technology, business applications, employee technology, endpoint management, SaaS governance, and access lifecycle functions.
- Deep working knowledge of HIPAA and hands-on experience leading security and compliance programs in a covered entity or business associate environment.
- Experience owning or overseeing HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other relevant third-party security, privacy, and compliance programs.
- Strong understanding of healthcare technology, sensitive data environments, enterprise customer expectations, and the security/compliance requirements that come with serving large employers, health plans, providers, members, and partners.
- Demonstrated ability to communicate cybersecurity and technology risk to executive and Board-level audiences, translating technical issues into business, financial, customer, and regulatory impact.
- Experience leading security and/or IT through M&A integration, divestitures, major business transformation, IPO readiness, public-company readiness, or other high-complexity operating environments.
- Experience building and scaling high-performing teams, including hiring, developing leaders, clarifying operating models, and driving accountability across multiple functions.
- Strong technical fluency across cloud security, application security, identity and access management, security architecture, threat management, vulnerability management, incident response, and modern SaaS architecture.
- Practical experience developing AI security strategy, enterprise AI governance, data classification practices, and guardrails for safe AI adoption.
- Experience serving as an executive security leader in customer-facing enterprise security reviews, audits, RFP/RFI responses, technical diligence, and customer escalations.
- Experience partnering effectively with Legal, Privacy, Compliance, Engineering, Product, Sales, Customer Success, People, Finance, and executive leadership.
- Strong business judgment and ability to balance security, compliance, customer trust, employee experience, product velocity, innovation, and operational efficiency.
- One or more recognized industry certifications relevant to a role at this level preferred, such as CISSP, CISM, CCISO, CRISC, CISA, or similar credentials.
The target base salary range for this position is $299,000 - $344,000 , and is part of a competitive total rewards package including equity and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.
Benefits provided by Spring Health:
Note : We have even more benefits than listed here and below, your recruiter will provide more in-depth information as you continue in the interview process. Benefits are subject to individual plan requirements and eligibility criteria.
- Health, Dental, Vision benefits start on your first day at Spring. You and your dependents also receive access to One Medical accounts HSA and FSA plans are also available, with Spring contributing up to $1K for HSAs, depending on your plan type.
- Employer sponsored 401(k) match of up to 2% for retirement planning
- A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
- We offer competitive paid time off policies including vacation, sick leave and company holidays.
- At 6 months tenure with Spring, we offer parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.
- Access to Noom , a weight management program—based in psychology, that’s tailored to your unique needs and goals.
- Access to fertility care support through Carrot , in addition to $4,000 reimbursement for related fertility expenses.
- Access to Wellhub , which connects employees to the best options for fitness, mindfulness, nutrition, and sleep in one subscription
- Access to BrightHorizons , which provides sponsored child care, back-up care, and elder care
- Up to $1,000 Professional Development Reimbursement a year.
- $200 per year donation matching to support your favorite causes.
Not sure if you meet every requirement? Research shows that women and people from historically underrepresented communities often hesitate to apply for roles unless they meet every qualification compared to other similarly-qualified candidates. At Spring Health, we are committed to fostering a workplace where everyone feels valued, empowered, and supported to Thrive. If this role excites you, we encourage you to apply.
Our privacy policy:
Spring Health is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex, marital status, ancestry, disability, genetic information, veteran status, gender identity or expression, sexual orientation, pregnancy, or other applicable legally protected characteristic. We also consider qualified applicants regardless of criminal histories, consistent with applicable legal requirements. Spring Health is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you have a disability or special need that requires accommodation, please let us know.
$420k
...are we?Cohere is the leading security-first enterprise AI company.... ...and San Francisco, with key offices in London, New York City,... ...The OpportunityCohere seeks a Chief Information Security Officer who can help... ...:A proven track record as a CISO or SVP of Security in high-...SuggestedFull timeWork at officeLocal areaRemote workHome office$300k - $350k
...Chief Information Security Officer (CISO)The CISO is our chief protector. Our infrastructure, threat model, and customer expectations are more complex than a typical mobile carrier or a typical software company. Your challenge is to enable rapid product innovation without...SuggestedWork at officeImmediate start- ...Chief Information Security Officer (CISO)New York CityCAIS is the pioneer in democratizing access to and education about alternative investments and structured products for independent financial advisors, empowering them to engage and transact with leading asset managers...Suggested
$300k - $375k
...build the future of global investing! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening... ...build out teams to support ambitious growth goals. The CISO will also represent security to senior leadership and the...SuggestedFull timeWork at officeWorldwide$250.44k - $375.67k
...Americas Regional Chief Information Security Officer (CISO) New York, United States; San Jose, California, United States Who We Are At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading...Suggested- ...Compass International Holdings seeks a seasoned Chief Information Security Officer to own and evolve the enterprise security program. This executive role balances security strategy with technology and business, protecting the platform, agents, buyers, sellers, and sensitive...
- ...Chief Information Security Officer (CISO) & Head of Information TechnologyAt Trustly, we're building a smarter, faster, and more secure financial future by revolutionizing the world of payments. As a global leader in Open Banking Payments, we are establishing Pay by Bank...Contract workWork at officeWorldwideFlexible hours
$350k - $400k
...Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that ensures...Full timeContract work$350k - $400k
...Group Chief Information Security Officer Organization: Location: New York, NY Description: Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be...Contract workLocal areaShift work- ...Chief Information Security Officer (CISO) About the Company Popular provider of workplace mental health solutions Industry Mental Health Care Type Privately Held, VC-backed Founded 2016 Employees 1001-5000 Funding $200+ million Categories...
- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...
- ...place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together. Summary The Chief Information Security Officer (CISO), working in collaboration with and in support of the firm’s strategic initiatives, is a senior executive...Work at officeRemote workRelocationVisa sponsorshipRelocation package
- ...Fire Department, City of New York (FDNY), seeks a full-time Chief Information Security Officer in the Bureau of Technology Development & Systems. The... ...more) such as Security+, CISSP, CISA, CISM, CySA+, CRISC, C-CISO, SSCP, CASP, CEH, GIAC #J-18808-Ljbffr New York City...Full timeLocal area
$150k - $200k
...Chief Information Security Officer (CISO) Vistrada is looking to hire strong Chief Information Security Officers (CISO). The CISO will provide strategic cybersecurity guidance and oversight to Vistrada clients by leading and managing their cybersecurity programs to...Full timeWork experience placementRemote workFlexible hours- Join to apply for the Chief Information Security Officer role at ButterflyMX Get AI-powered advice on this job and more exclusive features. Our Mission... ...and do small, and We are tenacious. Role Overview As our CISO, you’ll lead and scale a small, talented security team...Full timeRemote workWorldwideFlexible hours
- ...Deputy Chief Information Security OfficerOur top-notch Information Security team quickly finds and responds... ...are not limited to:Serve as acting CISO when required, ensuring uninterrupted... ...institutional policies.Proficiency in Microsoft Office Suite including Word, Excel, Power...Work at officeImmediate startRemote workFlexible hours
- ...firm's work is distinguished by a unique combination of precision and vision. Based in New York, the Deputy Chief Information Security Officer (Deputy CISO) serves as the second-in-command of the information security organization, partnering with the CISO to define and...Local areaImmediate startFlexible hoursShift work
- ...Deputy Chief Information Security Officer (CISO) About the Company Industry-leading cybersecurity platform Industry Computer & Network Security Type Privately Held, VC-backed Founded 2019 Employees 201-500 Funding $200+ million Categories...
- ...Deputy Chief Information Security Officer (CISO), Security Technology About the Company Popular provider of revenue cycle management solutions Industry Hospital & Health Care Type Privately Held, Private Equity-backed Founded 2003 Employees...
- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories...Remote work
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...
- %PDF-1.6%ÓôÌá1 0 obj /Rotate 0/StructParents 2/Tabs/S/Type/Page/Group endobj2 0 obj streamH‰ìW[—ÓÈ~÷¯èG;ÇÖè.yápÎ2L’IB€Å‡!'Gµm#Á² ~«U—nÉÏ,$yÚ—YêKÕWU_}uöÇuùU=|xöôüò‰ŠÔ£GŸœ«ÙÇYy¡Ê|/ U%žŸ«4_{y® éÙkUÍofg›¯µÙÍ|Ï÷ááZ¾·ÎÕÊW=¦©—ª,ñ½ W›³«ù‡EäÅjþv±Ôüþz¹š_›ÿ™š×Õ?ì»O‹˜-¾¨«¥*õ £E‹...
- ...of at least 2 days in office per week. This role... ...performs business functions. Information Risk Governance (“IRG”)... ...information and cyber security risk by maintaining and... ...(ISO) serves as the Chief Information Security Officer... ...the direction of the CISO, the ISO translates the...Work at officeWork from homeFlexible hours2 days per week
$180k - $225k
...Job Description Sompo has a unique opportunity for an Information Security Officer to join our Information Security team. This role will manage and continuously modernize our Information Security program for global operations, while maintaining alignment with...Full timeFor contractorsFlexible hours$225k - $275k
...software businesses — each with its own security profile.The Platform Information Security Officer (PISO), Life Sciences Platform is... ...counterpart to the Global CISO across a global conglomerate of OpCos... ....This position reports to the Chief Information Security Officer (...Full timeContract workRemote work$225k - $275k
...priority for the platform.The Platform Information Security Officer (PISO), Diagnostics Platform is... ...operational counterpart to the Global CISO across a global conglomerate of OpCos.... ...footprint.This position reports to the Chief Information Security Officer (CISO) and...Full timeRemote work- ...Information Systems Security Officer (ISSO)Employment Type: Full-Time, ExperiencedDepartment: Information TechnologyCGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation...Full timeLocal area
- ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief...
$148.5k - $223.9k
....Location: New York, NYThe ExperienceAs a Manager, Office of the CISO, you serve as a trusted security, compliance, privacy, and risk advisor to Salesforce... ..., or Public Sector.You've worked within a Business Information Security Office, Office of the CISO, Customer Trust...Full timeWork at office- ...City, NJ / Chicago, IL / Brooklyn, NY / Houston, TXDrive the security of critical banking applications and platforms through hands-on... ...health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.Equal Opportunity Employer/Disability...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Information Security Officer (CISO). Be the first to apply!
- information security officer New York, NY
- information security officer iso New York, NY
- remote ciso New York, NY
- ciso New York, NY
- chief information security officer ciso New York, NY
- business information security officer New York, NY
- chief information security officer New York, NY
- information security compliance analyst New York, NY
- information security New York, NY
- information security analyst New York, NY


