Executive VP, Information Security & Risk

The Security Executive Council

United States

On-site

USD 250,000 - 288,500

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, Dental, Vision benefits
401(k) match
Paid time off
Parental leave
Professional development reimbursement

Job summary

Spring Health is seeking a VP, Information Security to define and lead the company's enterprise-wide security strategy, protecting assets and customer data while enabling growth. You will partner with executive leadership across legal, compliance, engineering, and product to embed security into decision-making and scale a high-performing security organization.

You will drive risk management, regulatory compliance (SOC 2, ISO 27001, HIPAA, GDPR), incident response, and cloud security, shaping

Qualifications

  • 12+ years of progressive experience in Information Security
  • 5+ years in a senior leadership role leading multi-functional security teams
  • Ability to communicate security risk to executive and board-level audiences
  • Deep working knowledge of HIPAA and hands-on compliance program management
  • Experience with HITRUST CSF, SOC 2, ISO 27001, and other security certification programs
  • Industry certifications relevant to senior security roles (CISSP, CISM, CCISO, CRISC, CISA)
  • Experience owning or contributing to incident response programs and regulatory breach notification obligations
  • Strong cloud security, application security, identity and access management skills
  • Track record of partnering with executives, auditors, regulators, and customers
  • Ability to balance security with customer experience, innovation, and business objectives

Responsibilities

  • Develop and execute the enterprise information security vision, strategy, and multi-year roadmap
  • Advise executive leadership and the Board on cybersecurity risks, trends, and investments
  • Establish security objectives, metrics, and reporting aligned with business priorities
  • Drive a security culture with clear risk communications to leadership and the Board
  • Own enterprise information security risk management including risk assessments and treatment plans
  • Ensure compliance with SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, GDPR, and CCPA
  • Oversee security audits, policy development, and remediation initiatives
  • Manage BAA program across customers and vendors
  • Maintain and test Incident Response and Business Continuity programs
  • Lead SOC, threat detection, vulnerability management, and incident response
  • Embed security in SDLC with threat modeling, secure code review, and automated testing
  • Provide guidance for secure cloud infrastructure and product security
  • Oversee vulnerability management, penetration testing, and remediation programs
  • Build and mentor high-performing security teams; manage budgets and vendor relations
  • Partner with Engineering, Legal, Privacy, Product, Sales, IT, HR for security decisions
  • Serve as executive contact for cyber insurance underwriters, auditors, and regulators
  • Drive continuous improvement of security controls and risk management practices
  • Embed security requirements and tooling across development teams
  • Ensure enterprise client security questionnaires and audits are efficiently handled
  • Demonstrate strong retention in security team leadership

Skills

Security leadership
Risk & compliance
Cloud security
Executive communication
HIPAA/HITRUST knowledge
Security certifications (CISSP/CISM)
Incident response
Vendor risk management
Security architecture
Regulatory audits & standards

Job description

Spring Health is seeking a VP, Information Security to define and lead the company's enterprise-wide security strategy, protecting assets and customer data while enabling growth. You will partner with executive leadership across legal, compliance, engineering, and product to embed security into decision-making and scale a high-performing security organization.

You will drive risk management, regulatory compliance (SOC 2, ISO 27001, HIPAA, GDPR), incident response, and cloud security, shaping

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Strategic VP of Information Security & Risk
Strategic VP of Information Security & Risk

BBG Ventures, LLC • United States

Remote
USD 250,000 - 288,500
Health benefits
401(k) match
Professional development
+3
VP, Information Security & Risk Strategy
VP, Information Security & Risk Strategy

LCS company • Des Moines (IA), Northern (KY)

Hybrid
USD 171,000 - 214,000
Competitive pay and benefits
401(K) with company match
Paid parental leave
VP, Enterprise Information Security & Risk
VP, Enterprise Information Security & Risk

Lcs • Des Moines (IA)

On-site
USD 171,000 - 214,000
Medical insurance
Dental insurance
Life insurance
+3
VP, Information Security: Strategy, Risk & Compliance Leader
VP, Information Security: Strategy, Risk & Compliance Leader

Arbolsantarosa • Des Moines (IA)

On-site
USD 171,000 - 214,000
Medical, dental, life insurance
401(k) with company match
Paid parental leave
Executive Information Security Leader: Strategy & Risk
Executive Information Security Leader: Strategy & Risk

The Security Executive Council • Dallas (TX)

On-site
USD 150,000 - 200,000
Competitive salary
Health insurance
Retirement plan
Global Privacy & Data Protection Leader (US)
Global Privacy & Data Protection Leader (US)

Spring Health • United States

On-site
USD 236,000 - 290,000
Health benefits
401(k) match
Professional development
+1
Chief Security & Trust Officer
Chief Security & Trust Officer

Pivotal Health • Los Angeles (CA)

Hybrid
USD 180,000 - 250,000
Equity
Health, Dental, and Vision
401(k)
+2
Executive AVP, Application Security & DevSecOps
Executive AVP, Application Security & DevSecOps

CVS Health Corporation • Northern (KY)

Hybrid
USD 185,000 - 376,000
Medical, dental, and vision coverage
Paid time off
Retirement savings options
+2
Global VP, Product Security & Risk Strategy
Global VP, Product Security & Risk Strategy

Circle • New York (NY)

On-site
USD 317,000 - 365,000
CISO & Enterprise Security Leader: Strategy, Risk, Growth
CISO & Enterprise Security Leader: Strategy, Risk, Growth

Confidential • United States

Hybrid
USD 200,000 - 320,000