Spring Health

Vice President, Information Security

$250K–$291KFull-time · Remote
✓ Verified live on the employer's own system · added 35 days ago
Save search
Senior · 12+ yrs exp

Requirements

Experience: 12+ years

Skills & tools

SecurityOperationsManagementSecure CloudSalesCustomer SuccessProgrammingSecure Design

Benefits — mentioned in this posting

Health, dental & vision401(k) / retirementPaid time offFamily / parental leaveTuition / education
Apply on company site ↗ See your fit → free

Full job description

- Lead Spring Health's Security Operations and Application/Product Security functions, including threat detection, vulnerability management, incident response, application security, cloud security, and secure SDLC practices.

- Develop and execute the roadmap for Security Operations and Application/Product Security in alignment with Spring Health's broader information security strategy.

- Partner closely with the CISO, Engineering, Product, Legal, Compliance, Sales, Customer Success, and IT to strengthen Spring Health's security posture while enabling business growth and innovation.

- Serve as a senior security leader in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, technical diligence, and customer escalations.

- Build scalable processes, artifacts, and technical narratives that help enterprise customers understand and trust Spring Health's security practices.

- Translate customer security requirements and recurring diligence themes into actionable product, engineering, and security priorities.

- Embed security throughout the software development lifecycle, including threat modeling, secure design reviews, secure code review, automated security testing, CI/CD controls, and vulnerability remediation.

- Provide security architecture review and guidance for new products, features, cloud environments, data flows, and third-party integrations.

- Own the Security Operations function and related tooling strategy, including SIEM, threat intelligence, endpoint detection and response, automation, alert triage, and response workflows.

- Lead the operational response to security incidents, including technical investigation, containment, remediation, executive updates, post-incident review, and partnership with Legal and Compliance on regulatory obligations.

- Oversee vulnerability management, penetration testing, responsible disclosure or bug bounty processes, and remediation programs across applications, cloud environments, and infrastructure.

- Partner with the CISO and Compliance team to support audit readiness and certification programs by ensuring technical security controls are well-designed, implemented, measured, and evidenced.

- Build, mentor, and develop high-performing Security Operations and Application/Product Security teams.

- Manage budgets, technology investments, vendor relationships, and tooling strategy for Security Operations and Application/Product Security.

- Drive a security culture across Engineering, Product, and business teams that enables innovation while maintaining appropriate risk controls.

- A documented Security Operations and Application/Product Security roadmap is in place with clear milestones, KPIs, ownership, and measurable progress.

- Strong technical control outcomes that support successful audits, certifications, customer reviews, and compliance readiness.

- Reduced organizational risk through proactive threat detection, vulnerability remediation, and security architecture, and effective technical security controls.

- High levels of security resilience demonstrated through effective incident response and crisis management.

- Security is embedded in the SDLC, development teams have clear security requirements, tooling, and a consistent process for security review.

- Enterprise client security questionnaires and audits are handled efficiently, with documented repeatable processes that reduce friction for the Sales and Customer Success teams.

- Meaningful improvements in security awareness and accountability across the organization.

- Executive leadership, customers, partners, have confidence in the company's security posture.

- A highly engaged, high-performing security team with strong retention

- 12+ years of progressive experience in Information Security, with at least 5 years in a senior leadership role.

- Demonstrated experience building and leading multi-functional security teams, including risk/compliance, application security, and/or security operations disciplines.

- Demonstrated ability to communicate security risk to executive engineering, product, and customer audiences, translating technical issues into business impact, customer impact, and clear mitigation plans.

- Strong working knowledge of HIPAA and healthcare security requirements, with experience partnering with Compliance and Legal in covered entity or business associate environments

- Experience supporting HITRUST CSF, SOC 2, ISO 27001, and - comparable certification programs through strong technical controls, remediations, evidence support, and audit partnerships.

- One or more recognized industry certifications relevant to a role at this level preferred such as CISSP, CISM, CCISO, CRISC, or CISA.

- Experience building partnerships across the organization, enabling innovation in a safe and risk-aware way - a track record of being a business enabler, not a gatekeeper.

- Experience serving as a senior security leader in client-facing enterprise security reviews, audits, RFP/RFI responses, technical diligence, and customer escalations.

- Experience owning operational incident response programs and partnering with Legal, Compliance, and executive stakeholders on breach assessment, communications, and notification obligations.

- Strong working knowledge of cloud security principles and modern SaaS architecture security requirements.

- Track record of partnering effectively with executive leadership, Engineering, Product, Legal, Compliance, Sales, Customer Success, auditors, and enterprise customers.

- Deep knowledge of security operations, threat management, vulnerability management, and incident response.

- Strong expertise in cloud security, application security, identity and access management, and security architecture.

- Strategic mindset with strong business and risk management acumen.

- Ability to balance security requirements with customer experience, innovation, and business objectives.

The target base salary range for this position is $250,000 - $291,000 , and is part of a competitive total rewards package including equity and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations.

We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.

More jobs at Spring Health

Similar jobs near Remote

Tell me when more Vice President, Legislative & Government Affairs . jobs post near Remote-GA We re-check every listing against the employer’s own board — no résumé needed.

Search Vice President, Information Security jobs near Remote → Browse all live jobs

This posting was published by Spring Health on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.