ForgeApply
Try it free

ForgeApply · Job listing

Vice President, Information Security

Springhealth66

Remote · US$250k – $291k

See all 63 open roles at Springhealth66

Tailor your resume for this Springhealth66 job in about a minute.

ForgeApply rewrites your resume for this exact posting, then autofills the application on Springhealth66's site with it. You review everything before it's sent. Free trial, no card required.

About this role

Our mission: e liminating every barrier to mental health.

Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. We're building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage.

Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care. With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners.

As an AI-native company, we believe technology should expand the reach, quality, and humanity of care. Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.

Reporting to the CISO, the Vice President, Information Security will lead Spring Health’s Security Operations and Application/Product Security functions, ensuring the protection of company assets, customer data, and critical systems while enabling business growth and innovation. This leader will provide strategic and hands-on direction across threat detection and response, vulnerability management, application and cloud security, secure software development, security architecture, incident response, compliance execution, audit readiness, and enterprise customer-facing security strategy.

The VP, Information Security will partner closely with the CISO, Engineering, Product, Legal, Compliance, Sales, Customer Success, and enterprise customers to strengthen Spring Health’s security posture and embed security into product and engineering decision-making. This leader will help mature Spring’s operational, product security, and compliance capabilities, support customer trust with large enterprise clients, and ensure Spring remains resilient against evolving cyber threats while balancing security, regulatory obligations, innovation, and business velocity.

This is a remote position with frequent travel required for leadership on-sites in NYC and occasional travel to our other offices in San Francisco and Seattle.

What You'll Do

• Lead Spring Health’s Security Operations and Application/Product Security functions, including threat detection, vulnerability management, incident response, application security, cloud security, and secure SDLC practices.

• Develop and execute the roadmap for Security Operations and Application/Product Security in alignment with Spring Health’s broader information security strategy.

• Partner closely with the CISO, Engineering, Product, Legal, Compliance, Sales, Customer Success, and IT to strengthen Spring Health’s security posture while enabling business growth and innovation.

• Own the day-to-day execution of Spring Health’s information security compliance programs, partnering with the CISO, Legal, Privacy, and Compliance teams to maintain audit readiness and strong control discipline.

• Serve as a senior security leader in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, technical diligence, and customer escalations.

• Build scalable processes, artifacts, and technical narratives that help enterprise customers understand and trust Spring Health’s security practices.

• Ensure customer-facing security and compliance materials accurately reflect Spring Health’s controls, certifications, policies, remediation plans, and risk posture.

• Translate customer security requirements and recurring diligence themes into actionable product, engineering, and security priorities.

• Embed security throughout the software development lifecycle, including threat modeling, secure design reviews, secure code review, automated security testing, CI/CD controls, and vulnerability remediation.

• Provide security architecture review and guidance for new products, features, cloud environments, data flows, and third-party integrations.

• Own the Security Operations function and related tooling strategy, including SIEM, threat intelligence, endpoint detection and response, automation, alert triage, and response workflows.

• Lead the operational response to security incidents, including technical investigation, containment, remediation, executive updates, post-incident review, and partnership with Legal and Compliance on regulatory obligations.

• Oversee vulnerability management, penetration testing, responsible disclosure or bug bounty processes, and remediation programs across applications, cloud environments, and infrastructure.

• Lead audit readiness and certification execution for information security programs, including evidence collection, technical control validation, remediation tracking, and partnership with the CISO, Legal, Privacy, and Compliance teams on frameworks such as HITRUST, SOC 2, ISO 27001, HIPAA, and PCI DSS.

• Build, mentor, and develop high-performing Security Operations and Application/Product Security teams.

• Manage budgets, technology investments, vendor relationships, and tooling strategy for Security Operations and Application/Product Security.

• Drive a security culture across Engineering, Product, and business teams that enables innovation while maintaining appropriate risk controls.

What Success Looks Like

• A documented Security Operations and Application/Product Security roadmap is in place with clear milestones, KPIs, ownership, and measurable progress.

• Strong technical control and compliance outcomes that support successful audits, certifications, customer reviews, and ongoing regulatory readiness.

• Compliance programs are operationally well-run, with clear ownership, timely evidence collection, effective remediation tracking, and strong partnership across Security, Legal, Privacy, Engineering, Product, and IT.

• Reduced org

Tailor your resume for this Springhealth66 role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)