远程工作雷达

信息安全副总裁

Vice President, Information Security

开发工程职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Spring Health
薪资$250,000 - $291,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间2026-07-06
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

### **我们的使命:消除心理健康的一切障碍**

Spring Health 是一家全球性的心理健康公司,致力于消除所有心理健康方面的障碍。我们正在打造一个世界,在这个世界中,获得支持变得简单、个性化,并以个人为中心,从而让护理能够贯穿每一个工作、每一次搬迁、每一份健康计划和人生阶段。

我们的 AI 原生平台帮助我们在自助工具、辅导、治疗、药物管理以及专科护理等方面提供个性化的支持。我们的成果已通过 JAMA Network Open 和 Validation Institute 独立验证,目前通过领先的雇主、健康计划和合作伙伴,Spring Health 已覆盖全球超过 1.7 亿人。

作为一家 AI 原生公司,我们认为技术应该扩大护理的覆盖面、质量和人性化。每位 Spring Health 的团队成员都应有意识地使用 AI 工具,将人类判断应用于 AI 输出,并以支持其角色和我们使命的方式持续提升 AI 熟练度。

向 CISO 汇报,信息安全副总裁将领导 Spring Health 的安全运营和应用/产品安全职能,确保公司资产、客户数据和关键系统的保护,同时促进业务增长和创新。这位领导者将在威胁检测与响应、漏洞管理、应用和云安全、安全软件开发、安全架构、事件响应、合规执行、审计准备以及企业客户安全策略方面提供战略和实际指导。

信息安全副总裁将与 CISO、工程、产品、法律、合规、销售、客户成功和企业客户紧密合作,加强 Spring Health 的安全态势,并将安全嵌入产品和工程决策中。这位领导者将帮助提升 Spring 的运营、产品安全和合规能力,通过大型企业客户建立信任,并确保 Spring 在平衡安全、监管义务、创新和业务速度的同时保持对不断演变的网络威胁的韧性。

这是一个远程职位,需要经常前往纽约市进行领导层现场会议,偶尔还需要前往旧金山和西雅图的其他办公室。

### **你将负责**

- 领导 Spring Health 的安全运营和应用/产品安全职能,包括威胁检测、漏洞管理、事件响应等

查看英文原文

### **Our mission: e** liminating every barrier to mental health.

Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage.

Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners.

As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.

Reporting to the CISO, the Vice President, Information Security will lead Spring Health’s Security Operations and Application/Product Security functions, ensuring the protection of company assets, customer data, and critical systems while enabling business growth and innovation. This leader will provide strategic and hands-on direction across threat detection and response, vulnerability management, application and cloud security, secure software development, security architecture, incident response, compliance execution, audit readiness, and enterprise customer-facing security strategy.

The VP, Information Security will partner closely with the CISO, Engineering, Product, Legal, Compliance, Sales, Customer Success, and enterprise customers to strengthen Spring Health’s security posture and embed security into product and engineering decision-making. This leader will help mature Spring’s operational, product security, and compliance capabilities, support customer trust with large enterprise clients, and ensure Spring remains resilient against evolving cyber threats while balancing security, regulatory obligations, innovation, and business velocity.

This is a remote position with frequent travel required for leadership on-sites in NYC and occasional travel to our other offices in San Francisco and Seattle.

### **What You'll Do**

- Lead Spring Health’s Security Operations and Application/Product Security functions, including threat detection, vulnerability management, incident response, application security, cloud security, and secure SDLC practices.
- Develop and execute the roadmap for Security Operations and Application/Product Security in alignment with Spring Health’s broader information security strategy.
- Partner closely with the CISO, Engineering, Product, Legal, Compliance, Sales, Customer Success, and IT to strengthen Spring Health’s security posture while enabling business growth and innovation.
- Own the day-to-day execution of Spring Health’s information security compliance programs, partnering with the CISO, Legal, Privacy, and Compliance teams to maintain audit readiness and strong control discipline.
- Serve as a senior security leader in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, technical diligence, and customer escalations.
- Build scalable processes, artifacts, and technical narratives that help enterprise customers understand and trust Spring Health’s security practices.
- Ensure customer-facing security and compliance materials accurately reflect Spring Health’s controls, certifications, policies, remediation plans, and risk posture.
- Translate customer security requirements and recurring diligence themes into actionable product, engineering, and security priorities.
- Embed security throughout the software development lifecycle, including threat modeling, secure design reviews, secure code review, automated security testing, CI/CD controls, and vulnerability remediation.
- Provide security architecture review and guidance for new products, features, cloud environments, data flows, and third-party integrations.
- Own the Security Operations function and related tooling strategy, including SIEM, threat intelligence, endpoint detection and response, automation, alert triage, and response workflows.
- Lead the operational response to security incidents, including technical investigation, containment, remediation, executive updates, post-incident review, and partnership with Legal and Compliance on regulatory obligations.
- Oversee vulnerability management, penetration testing, responsible disclosure or bug bounty processes, and remediation programs across applications, cloud environments, and infrastructure.
- Lead audit readiness and certification execution for information security programs, including evidence collection, technical control validation, remediation tracking, and partnership with the CISO, Legal, Privacy, and Compliance teams on frameworks such as HITRUST, SOC 2, ISO 27001, HIPAA, and PCI DSS.
- Build, mentor, and develop high-performing Security Operations and Application/Product Security teams.
- Manage budgets, technology investments, vendor relationships, and tooling strategy for Security Operations and Application/Product Security.
- Drive a security culture across Engineering, Product, and business teams that enables innovation while maintaining appropriate risk controls.

### **What Success Looks Like**

- A documented Security Operations and Application/Product Security roadmap is in place with clear milestones, KPIs, ownership, and measurable progress.
- Strong technical control and compliance outcomes that support successful audits, certifications, customer reviews, and ongoing regulatory readiness.
- Compliance programs are operationally well-run, with clear ownership, timely evidence collection, effective remediation tracking, and strong partnership across Security, Legal, Privacy, Engineering, Product, and IT.
- Reduced organizational risk through proactive threat detection, vulnerability remediation, and security architecture, and effective technical security controls.
- High levels of security resilience demonstrated through effective incident response and crisis management.
- Security is embedded in the SDLC, development teams have clear security requirements, tooling, and a consistent process for security review.
- Enterprise client security questionnaires and audits are handled efficiently, with documented repeatable processes that reduce friction for the Sales and Customer Success teams.
- Meaningful improvements in security awareness and accountability across the organization.
- Executive leadership, customers, partners, and regulators have confidence in the company's security posture.
- A highly engaged, high-performing security team with strong retention

### **What You'll Bring**

- 12+ years of progressive experience in Information Security, with at least 5 years in a senior leadership role.
- Demonstrated experience building and leading multi-functional security teams, especially across Security Operations, Application/Product Security, cloud security, vulnerability management, and incident response.
- Demonstrated ability to communicate security risk to executive engineering, product, and customer audiences, translating technical issues into business impact, customer impact, and clear mitigation plans.
- Strong working knowledge of HIPAA and healthcare security requirements, with experience owning or operationally leading security compliance work in covered entity or business associate environments.
- Experience leading or supporting HITRUST CSF, SOC 2, ISO 27001, PCI DSS, and comparable certification programs through strong technical controls, remediation management, evidence support, audit readiness, and cross-functional partnership.
- Experience translating compliance requirements into practical security controls, engineering requirements, operational processes, and customer-facing narratives.
- One or more recognized industry certifications relevant to a role at this level preferred such as CISSP, CISM, CCISO, CRISC, or CISA.
- Experience building partnerships across the organization, enabling innovation in a safe and risk-aware way — a track record of being a business enabler, not a gatekeeper.
- Experience serving as a senior security leader in client-facing enterprise security reviews, audits, RFP/RFI responses, technical diligence, and customer escalations.
- Experience owning operational incident response programs and partnering with Legal, Compliance, and executive stakeholders on breach assessment, communications, and notification obligations.
- Strong working knowledge of cloud security principles and modern SaaS architecture security requirements.
- Track record of partnering effectively with executive leadership, Engineering, Product, Legal, Compliance, Sales, Customer Success, auditors, and enterprise customers.
- Deep knowledge of security operations, threat management, vulnerability management, and incident response.
- Strong expertise in cloud security, application security, identity and access management, and security architecture.
- Strategic mindset with strong business and risk management acumen.
- Ability to balance security requirements with customer experience, innovation, and business objectives.

_The target base salary range for this position is **$250,000 - $291,000**, and is part of a competitive total rewards package including equity and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using [**Radford Global Compensation Database**](https://springhealth.link/jd-2022-09-radfordcomp) at minimum to ensure competitive and fair pay._

#### **Benefits provided by Spring Health:**

**Note**: We have even more benefits than listed [here](https://www.springhealth.com/careers#:~:text=Our%20perks%20%26%20benefits) and below, your recruiter will provide more in-depth information as you continue in the interview process. Benefits are subject to individual plan requirements and eligibility criteria.

- Health, Dental, Vision benefits start on your first day at Spring. You and your dependents also receive access to [**One Medical**](https://www.onemedical.com/membership/) accounts HSA and FSA plans are also available, with Spring contributing up to $1K for HSAs, depending on your plan type.
- Employer sponsored 401(k) match of up to 2% for retirement planning
- A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
- We offer competitive paid time off policies including vacation, sick leave and company holidays.
- At 6 months tenure with Spring, we offer parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.
- Access to [**Noom**](https://www.noom.com/) **,** a weight management program—based in psychology, that’s tailored to your unique needs and goals.
- Access to fertility care support through [**Carrot**](https://springhealth.link/jd-2023-07-carrotbenefit), in addition to $4,000 reimbursement for related fertility expenses.
- Access to [**Wellhub**](https://springhealth.link/jd-2023-07-gympassbenefit),  which connects employees to the best options for fitness, mindfulness, nutrition, and sleep in one subscription
- Access to [**BrightHorizons**](https://www.brighthorizons.com/), which provides sponsored child care, back-up care, and elder care
- Up to $1,000 Professional Development Reimbursement a year.
- $200 per year donation matching to support your favorite causes.

**Not sure if you meet every requirement?** . If this role excites you, we encourage you to apply.

**_Our privacy policy:_** [**_https://springhealth.com/privacy-policy/_**](https://springhealth.com/privacy-policy/)

_Spring Health is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex, marital status, ancestry, disability, genetic information, veteran status, gender identity or expression, sexual orientation, pregnancy, or other applicable legally protected characteristic. We also consider qualified applicants regardless of criminal histories, consistent with applicable legal requirements. Spring Health is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you have a disability or special need that requires accommodation, please let us know._

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级数据分析师 I,医学事务

Spring HealthUnited States$125,000 - $142,000/年permanent今天
其他限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

运营经理

Spring HealthUnited Statespermanent5 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

资深商业法律顾问

Spring HealthUnited States$184,000 - $211,500/年permanent5 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

管理咨询团队负责人

Spring HealthUnited States$90,000 - $100,000/年permanent6 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位