Chief Information Security Officer (CISO)
Spring Health66 · New York (Hybrid); San Francisco, CA (Hybrid)
About this role
## Chief Information Security Officer (CISO) ### About Spring Health Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We’re building a world where getting support is simple, personal, and built around the person—so care can continue through every job, move, health plan, and life stage. Our AI-native platform helps deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care, reaching more than 170 million people worldwide through leading employers, health plans, and partners. ### Role Overview The Chief Information Security Officer (CISO) will define, lead, and advance Spring Health’s enterprise-wide information security, technology risk, compliance, and IT strategy. This leader will protect company assets and sensitive data (including customer, member, provider data) and critical systems—while enabling business growth, innovation, and operational scale. Reporting to the Chief Technology Officer, the CISO will lead Information Security, Compliance/GRC, and IT functions, including Security Operations, Application/Product Security, cloud and infrastructure security, identity and access management, third-party risk, incident response, enterprise compliance, corporate IT, and business technology operations. The CISO will also serve as a trusted advisor to executive leadership and the Board on cybersecurity risk, regulatory readiness, enterprise resilience, customer trust, and technology risk—playing a critical role in Spring Health’s next phase of scale (including the integration of Alma, AI transformation, international expansion, and readiness for future public-company expectations). ### Hybrid Location Hybrid role based in **New York City or San Francisco** with an expectation to be in the office **2–3 days per week**. Candidates must be based in the NYC or SF metro areas or able to relocate independently within **90 days**. Frequent travel will be required for leadership meetings and to visit office locations. --- ## What You’ll Do - Develop and execute Spring Health’s enterprise-wide information security, compliance, technology risk, and IT strategy aligned to company priorities, growth plans, and regulatory obligations. - Lead Information Security, Compliance/GRC, and IT, including Security Operations, Application/Product Security, cloud and infrastructure security, enterprise compliance, corporate IT, identity and access management, and business technology operations. - Partner closely with the CTO, executive leadership, Legal, Privacy, Compliance, Product, Engineering, Sales, Customer Success, People, Finance, and other stakeholders to enable the business without unnecessary friction. - Advise executive leadership and the Board on cybersecurity risks, technology risk, regulatory readiness, incident response, enterprise resilience, customer trust, and security investments. - Build and scale a high-performing organization across security, compliance, and IT (develop leaders, clarify ownership, improve operating rhythms, and ensure the right structure/capabilities/culture). - Oversee enterprise security operations: threat detection, vulnerability management, incident response, security monitoring, endpoint security, SIEM strategy, threat intelligence, and resilience exercises. - Embed Application/Product Security and cloud security into the software development lifecycle (secure architecture, threat modeling, automate
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.