Remotery

Vice President, Information Security

Posted Jul 25

This is a fully remote position, open to applicants in United States.

📋 Description

• Develop and implement the enterprise information security vision, strategy, and multi-year roadmap.

• Act as a trusted advisor to executive leadership and the Board regarding cybersecurity risks, trends, and investment opportunities.

• Set security objectives, metrics, and reporting mechanisms that align with business priorities.

• Foster a security-focused culture throughout the organization that promotes innovation while upholding necessary risk controls, effectively communicating risks and changes in the risk landscape to leadership, the Board, and key stakeholders in clear, business-relevant language.

• Own the enterprise information security risk management program, which includes formal risk assessments, risk registers, and risk treatment strategies.

• Ensure adherence to relevant frameworks and regulations, such as SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, GDPR, and CCPA.

• Supervise security audits, risk assessments, policy formulation, and remediation efforts.

• Manage the Business Associate Agreement (BAA) program across the customer and vendor landscape.

• Maintain and regularly test the enterprise Incident Response and Business Continuity programs.

• Promote ongoing enhancement of security controls and risk management practices.

• Oversee security operations, threat detection, vulnerability management, and incident response activities.

• Lead the security operations center (SOC) function, encompassing SIEM strategy, threat intelligence, and endpoint detection and response.

• Direct the organization’s response to security incidents, including executive communication, regulatory notification responsibilities, and post-incident analysis.

• Manage penetration testing, security evaluations, and resilience exercises.

• Collaborate with Engineering and Product leadership to integrate security throughout the software development lifecycle (SDLC), which includes threat modeling, secure code reviews, and automated security testing.

• Provide strategic guidance for the design and implementation of secure enterprise and cloud infrastructures, ensuring that security architecture principles are integrated into platform design, data flows, and technology decisions across the organization.

• Offer security architecture reviews and recommendations for new products, features, and third-party integrations.

• Supervise vulnerability management, penetration testing, and remediation initiatives across the platform and infrastructure.

• Build, mentor, and cultivate high-performing security teams.

• Manage security-related budgets, technology investments, and vendor partnerships.

• Lead third-party risk management and vendor security assessment initiatives.

• Demonstrated ability to collaborate closely with leadership across various departments, including Engineering, Legal, Privacy, Product, Sales, IT, HR, and others, acting as a trusted partner who facilitates business operations rather than obstructing them.

• Serve as the primary executive contact for cyber insurance underwriters, external auditors, and regulatory examiners.


⛳️ Requirements

• A minimum of 12 years of progressive experience in Information Security, including at least 5 years in a senior leadership capacity.

• Proven experience in building and leading cross-functional security teams, encompassing risk/compliance, application security, and/or security operations.

• Demonstrated capability to convey security risks to executive and board-level stakeholders, translating technical challenges into business and financial implications.

• Extensive working knowledge of HIPAA and practical experience managing compliance programs within a covered entity or business associate context.

• Familiarity with HITRUST CSF, SOC 2, ISO 27001, and other comparable third-party security certification programs.

• Possession of one or more recognized industry certifications pertinent to this level (CISSP, CISM, CCISO, CRISC, or CISA).

• Experience in fostering partnerships across the organization, enabling innovation in a secure and risk-aware manner — a history of being a business facilitator rather than a gatekeeper.

• Experience managing security responsibilities that involve client engagement, including enterprise security evaluations, vendor assessments, and RFP responses.

• Experience in owning or contributing to incident response initiatives, including regulatory breach notification responsibilities.

• Strong working knowledge of cloud security principles and the security requirements associated with modern SaaS architectures.

• Proven track record of effectively partnering with executive leadership, boards, auditors, regulators, and customers.

• In-depth knowledge of security operations, threat management, vulnerability management, and incident response.

• Strong expertise in cloud security, application security, identity and access management, and security architecture.

• Strategic mindset with solid business and risk management acumen.

• Ability to balance security demands with customer experience, innovation, and organizational objectives.


🏝️ Benefits

• Health, Dental, and Vision benefits commence on your first day at Spring. You and your dependents also gain access to One Medical accounts. HSA and FSA plans are available, with Spring contributing up to $1K for HSAs, based on your selected plan.

• Employer-sponsored 401(k) matching up to 2% to support retirement planning.

• An annual allowance of no-cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.

• We provide competitive paid time off policies, including vacation, sick leave, and company holidays.

• At 6 months of tenure with Spring, we offer parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.

• Access to Noom, a psychology-based weight management program tailored to your individual needs and goals.

• Access to fertility care support through Carrot, along with a $4,000 reimbursement for related fertility expenses.

• Access to Wellhub, which connects employees to the best options for fitness, mindfulness, nutrition, and sleep through a single subscription.

• Access to BrightHorizons, which provides sponsored child care, backup care, and elder care services.

• Up to $1,000 in Professional Development Reimbursement each year.

• Annual donation matching of $200 to support your preferred causes.

People also viewed

LimeJul 26

Senior Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security Engineer$120k/year
ApplyView job
ThreatscapeJul 26

Associate Consultant – Microsoft Security, Purview, Data Security and Governance, AI

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
GFT TechnologiesJul 26

Senior IT Security Project Manager

CR flagCosta Rica OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
BeyondTrustJul 26

VP, Product Management, AI Security – Strategy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
QuisitiveJul 26

Digital Security Coach

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
GEICOJul 25

Senior Field Security Investigator

US flagFlorida OnlyFull-timeCybersecurity / Security Engineer$3,200 – $5,000/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers