# Chief Information Security Officer (CISO) at Spring Health

- Company: Spring Health
- What the company does: Eliminating barriers to mental healthcare. Clinically-proven technology with world-class providers to deliver precisely what your employees need.
- Company website: https://www.springhealth.com
- Type: Startups
- Level: Principal and up
- Location: New York (Hybrid); San Francisco, CA (Hybrid)
- Work setup: Hybrid
- Pay: $299K to $344K base salary per year (USD)
- Posted: 2026-09-14
- Apply by: 2026-10-29
- Apply: https://job-boards.greenhouse.io/springhealth66/jobs/4721965005
- Page: https://www.1752.vc/careers/jobs/spring-health-chief-information-security-officer-ciso/

## About the role

The target base salary range for this position is $299,000 - $344,000 , and is part of a competitive total rewards package including equity and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.

## What they're looking for

- Develop and execute Spring Health’s enterprise-wide information security, compliance, technology risk, and IT strategy in alignment with company priorities, growth plans, and regulatory obligations
- Serve as a trusted advisor to executive leadership and the Board on cybersecurity risks, technology risk, regulatory readiness, incident response, enterprise resilience, customer trust, and security investments
- Oversee enterprise security operations, including threat detection, vulnerability management, incident response, security monitoring, endpoint security, SIEM strategy, threat intelligence, and resilience exercises
- Own the enterprise compliance and information security risk management program, including risk assessments, risk registers, risk treatment plans, control frameworks, policy governance, and executive reporting
- Ensure successful compliance outcomes across applicable frameworks and regulations, including HIPAA, HITRUST, SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, and other healthcare, privacy, and security requirements
- Serve as a senior executive sponsor in strategic enterprise customer conversations, including security reviews, audits, RFPs/RFIs, customer escalations, and technical diligence with large enterprise buyers

Tags: Technology
