Auf einen Blick
- Aufgaben: Leite die Informationssicherheitsstrategie und schütze Unternehmenswerte und Kundendaten.
- Unternehmen: Spring Health, ein globales Unternehmen für psychische Gesundheit mit innovativer Technologie.
- Vorteile: Attraktives Gehalt, Gesundheitsleistungen, Homeoffice und Weiterbildungsmöglichkeiten.
- Weitere Informationen: Dynamisches Umfeld mit großartigen Entwicklungsmöglichkeiten und einem engagierten Team.
- Warum dieser Job: Gestalte die Zukunft der psychischen Gesundheit und schütze wichtige Daten.
- Qualifikationen: Mindestens 12 Jahre Erfahrung in der Informationssicherheit, davon 5 Jahre in Führungspositionen.
Our mission: e liminatingevery barrier tomental health.
Spring Health is a global mental health company on a mission to eliminate every barrier to mental health.
We’re building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage.
Our AI-native platform helps us deliver personalized support across self-guided tools, coaching, therapy, medication management, and specialty care.
With outcomes independently validated by JAMA Network Open and the Validation Institute, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners.
As an AI-native company, we believe technology should expand the reach, quality, and humanity of care.
Every Spring Health team member is expected to use AI tools thoughtfully, apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission.
The Vice President, Information Security is responsible for defining, leading and advancing the organization’s enterprise-wide information security strategy, ensuring the protection of company assets, customer data, and critical systems while enabling business growth and innovation.
The leader provides strategic direction across cybersecurity, risk management, compliance, security operations, cloud and application security, identity and access management, third-party risk, and incident response.
The VP, Information Security partners closely with executive leadership, technology, legal, compliance, and business stakeholders to strengthen the organization’s security posture, maintain regulatory compliance, and embed security into business and product decision-making.
The leader will build and scale a high-performing security organization, drive security program maturity, and ensure the company remains resilient against evolving cyber threats while supporting operational excellence and organizational objectives.
- What You’ll Do
- Security Strategy & Leadership
- Develop and execute the enterprise information security vision, strategy, and multi-year roadmap.
- Serve as a trusted advisor to executive leadership and the Board on cybersecurity risks, trends, and investments.
- Establish security objectives, metrics, and reporting mechanisms aligned with business priorities.
- Drive a security culture across the organization that enables innovation while maintaining appropriate risk controls, including effectively communicating risks and changes in the risk landscape to leadership, the Board, and key stakeholders in clear, business-relevant terms.
- Governance, Risk & Compliance
- Own the enterprise information security risk management program, including formal risk assessments, risk registers, and risk treatment plans.
- Ensure compliance with applicable frameworks and regulations, including SOC 2, ISO 27001, HIPAA, HITRUST, PCI DSS, GDPR, and CCPA.
- Oversee security audits, risk assessments, policy development, and remediation initiatives.
- Manage the Business Associate Agreement (BAA) program across the customer and vendor ecosystem.
- Maintain and test the enterprise Incident Response and Business Continuity programs.
- Drive continuous improvement of security controls and risk management practices.
- Security Operations & Incident Response
- Oversee security operations, threat detection, vulnerability management, and incident response functions.
- Own the security operations center (SOC) function, including SIEM strategy, threat intelligence, and endpoint detection and response.
- Lead the organization’s response to security incidents, including executive communication, regulatory notification obligations, and post-incident review
- Direct penetration testing, security assessments, and resilience exercises.
- Cloud, Infrastructure & Product Security
- Partner with Engineering and Product leadership to embed security throughout the software development lifecycle (SDLC), including threat modeling, secure code review, and automated security testing.
- Provide strategic direction for the design and implementation of secure enterprise and cloud infrastructure, ensuring security architecture principles are embedded in platform design, data flows, and technology decisions across the organization.
- Provide security architecture review and guidance for new products, features, and third-party integrations.
- Oversee vulnerability management, penetration testing, and remediation programs across the platform and infrastructure.
- Team & Program Leadership
- Build, mentor, and develop high-performing security teams.
- Manage security budgets, technology investments, and vendor relationships.
- Lead third-party risk management and vendor security assessment programs.
- Demonstrated ability to work closely with leadership across the organization, including Engineering, Legal, Privacy, Product, Sales, IT, HR, and others, serving as a trusted partner who enables the business rather than a barrier to it.
- Serve as the executive point of contact for cyber insurance underwriters, external auditors, and regulatory examiners.
- What Success Looks Like
- A documented, board-approved information security strategy is in place with defined milestones, KPIs, and accountability.
- Strong regulatory and compliance outcomes, including successful audits and certifications.
- Reduced organizational risk through proactive threat management, vulnerability remediation, and security controls.
- High levels of security resilience demonstrated through effective incident response and crisis management.
- Security is embedded in the SDLC, development teams have clear security requirements, tooling, and a consistent process for security review.
- Enterprise client security questionnaires and audits are handled efficiently, with documented repeatable processes that reduce friction for the Sales and Customer Success teams.
- Meaningful improvements in security awareness and accountability across the organization.
- Executive leadership, customers, partners, and regulators have confidence in the company’s security posture.
- A highly engaged, high-performing security team with strong retention
- What You’ll Bring
- 12+ years of progressive experience in Information Security, with at least 5 years in a senior leadership role.
- Demonstrated experience building and leading multi-functional security teams, including risk/compliance, application security, and/or security operations disciplines.
- Demonstrated ability to communicate security risk to executive and board-level audiences, translating technical issues into business and financial impact.
- Deep working knowledge of HIPAA and hands‑on experience managing compliance programs in a covered entity or business associate environment.
- Experience with HITRUST CSF, SOC 2, ISO 27001, and other comparable third‑party security certification programs.
- One or more recognized industry certifications relevant to a role at this level (CISSP, CISM, CCISO, CRISC, or CISA).
- Experience building partnerships across the organization, enabling innovation in a safe and risk‑aware way — a track record of being a business enabler, not a gatekeeper.
- Experience managing client‑facing security responsibilities, including enterprise security reviews, vendor assessments, and RFP responses.
- Experience owning or contributing to incident response programs, including regulatory breach notification obligations.
- Strong working knowledge of cloud security principles and modern Saa S architecture security requirements.
- Track record of partnering effectively with executive leadership, boards, auditors, regulators, and customers.
- Deep knowledge of security operations, threat management, vulnerability management, and incident response.
- Strong expertise in cloud security, application security, identity and access management, and security architecture.
- Strategic mindset with strong business and risk management acumen.
- Ability to balance security requirements with customer experience, innovation, and business objectives.
The target base salary range for this position is $250,000 - $288,500, and is part of a competitive total rewards package including equity and benefits.
Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations.
We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.
Benefits provided by Spring Health
Note
: We have even more benefits than listed here and below, your recruiter will provide more in-depth information as you continue in the interview process.
Benefits are subject to individual plan requirements and eligibility criteria.
- Health, Dental, Vision benefits start on your first day at Spring. You and your dependents also receive access to
One Medical accounts HSA and FSA plans are also available, with Spring contributing up to $1K for HSAs, depending on your plan type.
- Employer sponsored 401(k) match of up to 2% for retirement planning
- A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
- We offer competitive paid time off policies including vacation, sick leave and company holidays
- At 6 months tenure with Spring, we offer parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents.
- Access to
Noom , a weight management program—based in psychology, that’s tailored to your unique needs and goals.
- Access to
Carrot , in addition to $4,000 reimbursement for related fertility expenses.
- Access to
Wellhub , which connects employees to the best options for fitness, mindfulness, nutrition, and sleep in one subscription
- Access to
- Bright Horizons , which provides sponsored child care, back-up care, and elder care
- Up to $1,000 Professional Development Reimbursement a year.
- $200 per year donation matching to support your favorite causes.
Not sure if you meet every requirement?
Research shows that women and people from historically underrepresented communities often hesitate to apply for roles unless they meet every qualification compared to other similarly-qualified candidates.
At Spring Health, we are committed to fostering a workplace where everyone feels valued, empowered, and supported to Thrive.
If this role excites you, we encourage you to apply.
Our privacy policy: https://springhealth. com/privacy-policy/
Spring Health is proud to be an equal opportunity employer.
We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex, marital status, ancestry, disability, genetic information, veteran status, gender identity or expression, sexual orientation, pregnancy, or other applicable legally protected characteristic.
We also consider qualified applicants regardless of criminal histories, consistent with applicable legal requirements.
Spring Health is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans.
If you have a disability or special need that requires accommodation, please let us know.
#J-18808-Ljbffr
Vice President, Information Security Arbeitgeber: Spring Health
Spring Health ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern in Zürich eine flexible hybride Arbeitsumgebung bietet. Mit einem starken Fokus auf evidenzbasierte Therapie und einem unterstützenden multidisziplinären Team fördert das Unternehmen nicht nur die berufliche Weiterentwicklung, sondern auch eine positive Arbeitskultur, die auf Zusammenarbeit und Innovation abzielt. Die Möglichkeit, mit modernster Technologie zu arbeiten und gleichzeitig einen bedeutenden Beitrag zur psychischen Gesundheit der Gemeinschaft zu leisten, macht Spring Health zu einem attraktiven Arbeitsplatz für engagierte Fachkräfte.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Vice President, Information Security erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Spring Health kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Spring Health zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Spring Health.
Wir glauben, dass du diese Fähigkeiten brauchst, um Vice President, Information Security mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei Spring Health vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Spring Health könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Spring Health sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird Spring Health auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!