Chief Information Security Officer – CISO

Jobtailor

California (MO)

On-site

USD 320,000 - 420,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Spring Health seeks an experienced Chief Information Security Officer to define and lead enterprise-wide information security, privacy, and IT risk management. You will oversee Security Operations, Application/Product Security, cloud/infrastructure security, IAM, third-party risk, and incident response, partnering with Legal, Privacy, Compliance, Product, and Engineering.

The role requires deep HIPAA/HITRUST expertise, a track record of building high‑performing security teams, and strong

Qualifications

  • 15+ years of progressive experience across information security, cybersecurity, IT, or technology risk with significant executive leadership background.
  • Deep knowledge of HIPAA and relevant healthcare security/compliance requirements.
  • Experience leading HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA programs and related governance.

Responsibilities

  • Define, lead, and advance enterprise-wide information security and IT strategy.
  • Lead Information Security, Compliance/GRC, and IT functions including Security Operations, Application/Product Security, cloud and infrastructure security, IAM, third-party risk, incident response, and enterprise compliance.
  • Advise executive leadership and the Board on cybersecurity risk and security investments.
  • Oversee threat detection, vulnerability management, incident response, security monitoring, and resilience exercises.
  • Embed security and cloud security in the software development lifecycle and govern AI security strategy.

Skills

Information Security Leadership
Compliance/GRC Management
Cloud Security Strategy
Incident Response Management
Healthcare Technology Compliance
Executive Communication
Team Building

Tools

SIEM
Security Monitoring Tools
Endpoint Management

Job description

  • Define, lead, and advance Spring Health’s enterprise-wide information security, technology risk, compliance, and IT strategy
  • Lead Information Security, Compliance/GRC, and IT functions, including Security Operations, Application/Product Security, cloud and infrastructure security, identity and access management, third-party risk, incident response, enterprise compliance, corporate IT, and business technology operations
  • Partner with the CTO, executive leadership, Legal, Privacy, Compliance, Product, Engineering, Sales, Customer Success, People, Finance, and other stakeholders
  • Advise executive leadership and the Board on cybersecurity risk, technology risk, regulatory readiness, incident response, enterprise resilience, customer trust, and security investments
  • Build and scale a high-performing security, compliance, and IT organization
  • Oversee threat detection, vulnerability management, incident response, security monitoring, endpoint security, SIEM strategy, threat intelligence, and resilience exercises
  • Embed Application/Product Security and cloud security in the software development lifecycle
  • Own enterprise compliance and information security risk management, including assessments, risk registers, treatment plans, control frameworks, policy governance, and executive reporting
  • Ensure compliance across HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other requirements
  • Partner with Legal and Privacy on data protection, Business Associate Agreements, breach assessments, notifications, and healthcare security requirements
  • Lead security and IT strategy for the Alma integration
  • Define and govern AI security strategy, including AI guardrails, approved tool usage, data classification, model/tool risk assessment, and secure AI adoption
  • Oversee corporate IT and business technology operations, including employee technology experience, endpoint management, access lifecycle, SaaS governance, corporate applications, and IT service delivery
  • Sponsor strategic enterprise customer conversations, security reviews, audits, RFPs/RFIs, customer escalations, and technical diligence
  • Build scalable customer trust processes, security narratives, artifacts, and evidence practices
  • Lead significant security incident response, including technical, executive, customer, legal, compliance, regulatory, and remediation activities
  • Manage security, compliance, and IT budgets, vendors, tooling, cyber insurance, external audits, and technology investments
  • Establish security, compliance, and IT metrics for executive leadership and Board visibility
  • Drive company-wide security, privacy, accountability, and responsible innovation culture
Requirements
  • 15+ years of progressive experience across Information Security, cybersecurity, IT, technology risk, or related disciplines, with significant experience in executive security leadership roles
  • Experience leading multi-functional security organizations across Security Operations, Application/Product Security, cloud security, GRC/compliance, identity and access management, incident response, and third-party risk
  • Experience leading or closely partnering with IT, corporate technology, business applications, employee technology, endpoint management, SaaS governance, and access lifecycle functions
  • Deep working knowledge of HIPAA and hands‑on experience leading security and compliance programs in a covered entity or business associate environment
  • Experience owning or overseeing HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other relevant security, privacy, and compliance programs
  • Strong understanding of healthcare technology, sensitive data environments, enterprise customer expectations, and related security/compliance requirements
  • Ability to communicate cybersecurity and technology risk to executive and Board‑level audiences
  • Experience leading security and/or IT through M&A integration, divestitures, major business transformation, IPO readiness, public‑company readiness, or other high‑complexity environments
  • Experience building and scaling high‑performing teams, including hiring, developing leaders, clarifying operating models, and driving accountability
  • Strong technical fluency across cloud security, application security, identity and access management, security architecture, threat management, vulnerability management, incident response, and modern SaaS architecture
  • Practical experience developing AI security strategy, enterprise AI governance, data classification practices, and safe AI adoption guardrails
  • Experience serving as an executive security leader in customer‑facing enterprise security reviews, audits, RFP/RFI responses, technical diligence, and customer escalations
  • Experience partnering effectively with Legal, Privacy, Compliance, Engineering, Product, Sales, Customer Success, People, Finance, and executive leadership
  • Strong business judgment balancing security, compliance, customer trust, employee experience, product velocity, innovation, and operational efficiency
  • One or more relevant industry certifications preferred, such as CISSP, CISM, CCISO, CRISC, CISA, or similar credentials
  • Candidates must be based in the NYC or SF metro areas or able to relocate independently within 90 days of their start date
  • Frequent travel required for leadership meetings and visits to office locations
Core Competencies

Demonstrates extensive expertise in Information Security, Compliance, and IT strategy, with a strong focus on risk management, regulatory compliance, and building high‑performing teams. Proven ability to communicate complex cybersecurity concepts to executive leadership and drive enterprise‑wide security initiatives.

Highest‑signal resume keywords
  • Information Security Leadership
  • Compliance/GRC Management
  • Cloud Security Strategy
  • Incident Response Management
  • Healthcare Technology Compliance
Hard Skills
  • Security Operations
  • Application Security
  • Identity and Access Management
  • Vulnerability Management
  • Threat Detection
  • Risk Management
  • Data Classification
  • AI Security Strategy
  • SaaS Governance
  • Security Architecture
Soft Skills
  • Executive Communication
  • Team Building
  • Business Judgment
  • Stakeholder Collaboration
  • Accountability
Certifications & Qualifications
  • CISSP
  • CISM
  • CCISO
  • CRISC
  • CISA
Industry Keywords
  • HIPAA
  • HITRUST
  • SOC 2
  • ISO 27001
  • PCI DSS
  • GDPR
  • CCPA
  • Cybersecurity Risk
  • Technology Risk
  • Enterprise Compliance
Tools & Technologies
  • SIEM
  • Cyber Insurance
  • Security Monitoring Tools
  • Endpoint Management Solutions
  • Corporate Applications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager – Cybersecurity Fusion Center
Manager – Cybersecurity Fusion Center

Jobtailor • West Valley City (UT)

On-site
USD 190,000 - 240,000
VP – AI Security and Data Protection Governance and Controls
VP – AI Security and Data Protection Governance and Controls

Jobtailor • United States

On-site
USD 180,000 - 280,000
Technology Director – BISO
Technology Director – BISO

Jobtailor • North Carolina

On-site
USD 180,000 - 320,000
Director of Cyber Security
Director of Cyber Security

Jobtailor • Concord (MA)

Hybrid
USD 180,000 - 260,000
Information Security Officer
Information Security Officer

Jobtailor • Massachusetts

On-site
USD 200,000 - 320,000
Senior Manager, GRC
Senior Manager, GRC

Jobtailor • California (MO)

On-site
USD 130,000 - 165,000
Senior Director Information Security
Senior Director Information Security

EverCommerce • Denver (CO)

Hybrid
USD 180,000 - 240,000
Wellness stipend
Udemy training
401k with company match
+2
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Director I – Cybersecurity Operations, Incident Response
Director I – Cybersecurity Operations, Incident Response

Jobtailor • Kentucky

On-site
USD 150,000 - 210,000
Information Security Manager – Configuration Management
Information Security Manager – Configuration Management

Jobtailor • Minnesota

On-site
USD 150,000 - 190,000