Chief Information Security Officer (CISO)

Spring HealthSan Francisco, NY
Hybrid

About The Position

Spring Health is a global mental health company dedicated to removing barriers to mental healthcare. They are seeking a Chief Information Security Officer (CISO) to lead their enterprise-wide information security, technology risk, compliance, and IT strategy. The CISO will be responsible for protecting company assets, customer data, member data, provider data, and critical systems while supporting business growth and innovation. This role will oversee Information Security, Compliance/GRC, and IT functions, including Security Operations, Application/Product Security, cloud and infrastructure security, identity and access management, third-party risk, incident response, enterprise compliance, corporate IT, and business technology operations. The CISO will act as a trusted advisor to executive leadership and the Board on cybersecurity risk, regulatory readiness, and technology risk, playing a crucial role in the company's expansion, including AI transformation and international growth. The position is hybrid, requiring 2-3 days per week in the New York City or San Francisco office, with candidates needing to be based in or willing to relocate to these metro areas. Frequent travel will also be required.

Requirements

  • 15+ years of progressive experience across Information Security, cybersecurity, IT, technology risk, or related disciplines, with significant experience in executive security leadership roles.
  • Demonstrated experience leading multi-functional security organizations across Security Operations, Application/Product Security, cloud security, GRC/compliance, identity and access management, incident response, and third-party risk.
  • Experience leading or closely partnering with IT, corporate technology, business applications, employee technology, endpoint management, SaaS governance, and access lifecycle functions.
  • Deep working knowledge of HIPAA and hands-on experience leading security and compliance programs in a covered entity or business associate environment.
  • Experience owning or overseeing HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other relevant third-party security, privacy, and compliance programs.
  • Strong understanding of healthcare technology, sensitive data environments, enterprise customer expectations, and the security/compliance requirements that come with serving large employers, health plans, providers, members, and partners.
  • Demonstrated ability to communicate cybersecurity and technology risk to executive and Board-level audiences, translating technical issues into business, financial, customer, and regulatory impact.
  • Experience leading security and/or IT through M&A integration, divestitures, major business transformation, IPO readiness, public-company readiness, or other high-complexity operating environments.
  • Experience building and scaling high-performing teams, including hiring, developing leaders, clarifying operating models, and driving accountability across multiple functions.
  • Strong technical fluency across cloud security, application security, identity and access management, security architecture, threat management, vulnerability management, incident response, and modern SaaS architecture.
  • Practical experience developing AI security strategy, enterprise AI governance, data classification practices, and guardrails for safe AI adoption.
  • Experience serving as an executive security leader in customer-facing enterprise security reviews, audits, RFP/RFI responses, technical diligence, and customer escalations.
  • Experience partnering effectively with Legal, Privacy, Compliance, Engineering, Product, Sales, Customer Success, People, Finance, and executive leadership.
  • Strong business judgment and ability to balance security, compliance, customer trust, employee experience, product velocity, innovation, and operational efficiency.

Nice To Haves

  • One or more recognized industry certifications relevant to a role at this level preferred, such as CISSP, CISM, CCISO, CRISC, CISA, or similar credentials.

Responsibilities

  • Develop and execute Spring Health’s enterprise-wide information security, compliance, technology risk, and IT strategy in alignment with company priorities, growth plans, and regulatory obligations.
  • Lead the Information Security, Compliance/GRC, and IT organizations, including Security Operations, Application/Product Security, cloud and infrastructure security, enterprise compliance, corporate IT, identity and access management, and business technology operations.
  • Partner closely with the CTO, executive leadership team, Legal, Privacy, Compliance, Product, Engineering, Sales, Customer Success, People, Finance, and other stakeholders to ensure security and IT enable the business rather than create unnecessary friction.
  • Serve as a trusted advisor to executive leadership and the Board on cybersecurity risks, technology risk, regulatory readiness, incident response, enterprise resilience, customer trust, and security investments.
  • Build and scale a high-performing organization across security, compliance, and IT, including developing leaders, clarifying ownership, improving operating rhythms, and ensuring the team has the right structure, capabilities, and culture for Spring’s next stage of growth.
  • Oversee enterprise security operations, including threat detection, vulnerability management, incident response, security monitoring, endpoint security, SIEM strategy, threat intelligence, and resilience exercises.
  • Ensure Spring Health’s Application/Product Security and cloud security programs are deeply embedded in the software development lifecycle, including secure architecture, threat modeling, automated testing, vulnerability remediation, and security review processes.
  • Own the enterprise compliance and information security risk management program, including risk assessments, risk registers, risk treatment plans, control frameworks, policy governance, and executive reporting.
  • Ensure successful compliance outcomes across applicable frameworks and regulations, including HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other healthcare, privacy, and security requirements.
  • Partner with Legal and Privacy on data protection, privacy, regulatory obligations, Business Associate Agreements, customer commitments, breach assessment, notification obligations, and evolving healthcare security requirements.
  • Lead security and IT strategy related to the Alma integration, including systems, data flows, access controls, compliance obligations, enterprise risk, provider/member/customer data protection, and long-term operating model decisions.
  • Define and govern Spring Health’s AI security strategy, including enterprise AI guardrails, approved tool usage, data classification, model/tool risk assessment, secure AI adoption, and protection of sensitive healthcare and business data.
  • Oversee corporate IT and business technology operations, including employee technology experience, endpoint management, access lifecycle, SaaS governance, corporate applications, IT service delivery, and operational excellence.
  • Serve as a senior executive sponsor in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, customer escalations, and technical diligence with large enterprise buyers.
  • Build scalable customer trust processes, security narratives, artifacts, and evidence practices that reduce friction for Sales and Customer Success while maintaining strong risk discipline.
  • Lead the organization’s response to significant security incidents, including technical response, executive communication, customer communication, legal/compliance partnership, regulatory considerations, post-incident review, and remediation.
  • Manage security, compliance, and IT budgets, vendor relationships, tooling strategy, cyber insurance engagement, external audit partnerships, and key technology investments.
  • Establish security, compliance, and IT metrics that give executive leadership and the Board clear visibility into risk posture, program maturity, operational performance, and investment priorities.
  • Drive a company-wide culture of security, privacy, accountability, and responsible innovation.

Benefits

  • Health, Dental, Vision benefits start on your first day
  • Access to One Medical accounts
  • HSA and FSA plans available, with Spring contributing up to $1K for HSAs
  • Employer sponsored 401(k) match of up to 2%
  • Yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents
  • Competitive paid time off policies including vacation, sick leave and company holidays
  • Parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents (at 6 months tenure)
  • Access to Noom, a weight management program
  • Access to fertility care support through Carrot, in addition to $4,000 reimbursement for related fertility expenses
  • Access to Wellhub, which connects employees to fitness, mindfulness, nutrition, and sleep options
  • Access to BrightHorizons, which provides sponsored child care, back-up care, and elder care
  • Up to $1,000 Professional Development Reimbursement a year
  • $200 per year donation matching to support your favorite causes
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service