CareerMoonshot

Chief Information Security Officer (CISO)

Spring Health · San Francisco Bay Area

📍 New York (Hybrid); San Francisco, CA (Hybrid)💰 $299,000 - $344,000via greenhousePosted 2026-09-14
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Spring Health.
Our mission: e liminating  every barrier to  mental health. Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage. Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners. As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission. The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health’s enterprise-wide information security, technology risk, compliance, and IT strategy. This leader will ensure the protection of company assets, customer data, member data, provider data, and critical systems while enabling business growth, innovation, and operational scale. Reporting to the Chief Technology Officer, the CISO will lead the company’s Information Security, Compliance/GRC, and IT functions, including Security Operations, Application/Product Security, cloud and infrastructure security, identity and access management, third-party risk, incident response, enterprise compliance, corporate IT, and business technology operations. This leader will manage and partner closely with senior security and IT leaders, including the VP, Information Security. The CISO will serve as a trusted advisor to executive leadership and the Board on cybersecurity risk, regulatory readiness, enterprise resilience, customer trust, and technology risk. They will play a critical role in Spring Health’s next phase of scale, including the integration of Alma, enterprise customer growth, AI transformation, international expansion, and readiness for future public-company expectations. This leader will be responsible for building a security and IT organization that enables the business, supports product velocity, protects sensitive healthcare data, and earns the trust of customers, members, providers, partners, regulators, and employees. Please note that this is a hybrid role based in either New York City or San Francisco , with an expectation to be in the office 2–3 days per week. Candidates must be based in the NYC or SF metro areas or able to relocate independently within 90 days of their start date. Frequent travel will be required for leadership meetings and to visit various office locations.  What You'll Do Develop and execute Spring Health’s enterprise-wide information security, compliance, technology risk, and IT strategy in alignment with company priorities, growth plans, and regulatory obligations. Lead the Information Security, Compliance/GRC, and IT organizations, including Security Operations, Application/Product Security, cloud and infrastructure security, enterprise compliance, corporate IT, identity and access management, and business technology operations. Partner closely with the CTO, executive leadership team, Legal, Privacy, Compliance, Product, Engineering, Sales, Customer Success, People, Finance, and other stakeholders to ensure security and IT enable the business rather than create unnecessary friction. Serve as a trusted advisor to executive leadership and the Board on cybersecurity risks, technology risk, regulatory readiness, incident response, enterprise resilience, customer trust, and security investments. Build and scale a high-performing organization across security, compliance, and IT, including developing leaders, clarifying ownership, improving operating rhythms, and ensuring the team has the right structure, capabilities, and culture for Spring’s next stage of growth. Oversee enterprise security operations, including threat detection, vulnerability management, incident response, security monitoring, endpoint security, SIEM strategy, threat intelligence, and resilience exercises. Ensure Spring Health’s Application/Product Security and cloud security programs are deeply embedded in the software development lifecycle, including secure architecture, threat modeling, automated testing, vulnerability remediation, and security review processes. Own the enterprise compliance and information security risk management program, including risk assessments, risk registers, risk treatment plans, control frameworks, policy governance, and executive reporting. Ensure successful compliance outcomes across applicable frameworks and regulations, including HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other healthcare, privacy, and security requirements. Partner with Legal and Privacy on data protection, privacy, regulatory obligations, Business Associate Agreements, customer commitments, breach assessment, notification obligations, and evolving healthcare security requirements. Lead security and IT strategy related to the Alma integration, including systems, data flows, access controls, compliance obligations, enterprise risk, provider/member/customer data protection, and long-term operating model decisions. Define and govern Spring Health’s AI security strategy, including enterprise AI guardrails, approved tool usage, data classification, model/tool risk assessment, secure AI adoption, and protection of sensitive healthcare and business data. Oversee corporate IT and business technology operations, including employee technology experience, endpoint management, access lifecycle, SaaS governance, corporate applications, IT service delivery, and operational excellence. Se

More San Francisco Bay Area jobs

San Francisco Bay Area jobs · Browse all locations