SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 299,000 - 344,000 / annual
Spring Health is a global mental health platform on a mission to eliminate barriers to mental health. The company operates an AI-native platform delivering personalized support across self-guided tools, coaching, therapy, medication management, and specialty care, reaching over 170 million people worldwide through employers, health plans, and partners.
The Chief Information Security Officer will report to the Chief Technology Officer and lead Spring Health's enterprise-wide information security, technology risk, compliance, and IT strategy. This executive role encompasses leadership of Information Security, Compliance/GRC, and IT functions including Security Operations, Application/Product Security, cloud and infrastructure security, identity and access management, third-party risk, incident response, enterprise compliance, corporate IT, and business technology operations.
Key responsibilities include developing and executing enterprise-wide security and IT strategy aligned with company growth and regulatory obligations; leading multi-functional security and IT organizations; serving as trusted advisor to executive leadership and the Board on cybersecurity risk, regulatory readiness, and enterprise resilience; building and scaling high-performing teams across security, compliance, and IT; overseeing enterprise security operations including threat detection, vulnerability management, and incident response; ensuring Application/Product Security and cloud security are embedded in the software development lifecycle; owning enterprise compliance and risk management programs; ensuring compliance across HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other healthcare and privacy requirements; partnering with Legal and Privacy on data protection and regulatory obligations; leading security and IT strategy for the Alma integration; defining and governing AI security strategy including enterprise AI guardrails and data classification; overseeing corporate IT and business technology operations; serving as executive sponsor in strategic enterprise customer conversations; building scalable customer trust processes; leading organizational response to significant security incidents; managing security, compliance, and IT budgets and vendor relationships; establishing security metrics for executive and Board visibility; and driving company-wide culture of security, privacy, and responsible innovation.
Success metrics include a clear enterprise-wide security, compliance, and IT strategy with defined priorities and KPIs; Security, Compliance/GRC, and IT teams with clear operating model and strong leadership; strong regulatory and compliance outcomes; security and IT viewed as business enablers; successful Alma integration with clear security and compliance priorities; AI adoption supported by clear security guardrails; efficient enterprise customer security reviews and audits; security embedded in product and engineering workflows; tested incident response and business continuity programs; strong employee experience with disciplined access management; and confidence from executive leadership, customers, partners, auditors, regulators, and the Board.
The role is hybrid based in either New York City or San Francisco, with expectation to be in office 2–3 days per week. Candidates must be based in NYC or SF metro areas or able to relocate independently within 90 days of start date. Frequent travel required for leadership meetings and office visits.
REQUIREMENTS:
- 15+ years of progressive experience in Information Security, cybersecurity, IT, technology risk, or related disciplines, with significant experience in executive security leadership roles
- Demonstrated experience leading multi-functional security organizations across Security Operations, Application/Product Security, cloud security, GRC/compliance, identity and access management, incident response, and third-party risk
- Experience leading or closely partnering with IT, corporate technology, business applications, employee technology, endpoint management, SaaS governance, and access lifecycle functions
- Deep working knowledge of HIPAA and hands-on experience leading security and compliance programs in a covered entity or business associate environment
- Experience owning or overseeing HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other relevant third-party security, privacy, and compliance programs
- Strong understanding of healthcare technology, sensitive data environments, enterprise customer expectations, and security/compliance requirements for serving large employers, health plans, providers, members, and partners
- Demonstrated ability to communicate cybersecurity and technology risk to executive and Board-level audiences, translating technical issues into business, financial, customer, and regulatory impact
- Experience leading security and/or IT through M&A integration, divestitures, major business transformation, IPO readiness, public-company readiness, or other high-complexity operating environments
- Experience building and scaling high-performing teams, including hiring, developing leaders, clarifying operating models, and driving accountability across multiple functions
- Strong technical fluency across cloud security, application security, identity and access management, security architecture, threat management, vulnerability management, incident response, and modern SaaS architecture
- Practical experience developing AI security strategy, enterprise AI governance, data classification practices, and guardrails for safe AI adoption
- Experience serving as executive security leader in customer-facing enterprise security reviews, audits, RFP/RFI responses, technical diligence, and customer escalations
- Experience partnering effectively with Legal, Privacy, Compliance, Engineering, Product, Sales, Customer Success, People, Finance, and executive leadership
- Strong business judgment and ability to balance security, compliance, customer trust, employee experience, product velocity, innovation, and operational efficiency
- One or more recognized industry certifications preferred: CISSP, CISM, CCISO, CRISC, CISA, or similar credentials