Back to Jobs
Gravie
Engineering & Architecture 7h ago

Vice President of Information Security and IT

Gravie
United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

CybersecuritySOC 2Cloud SecurityHITRUSTIncident ResponseAI GovernanceHIPAA

Want to know if you're a match for this job?

Calculate My Match Score

We are seeking a Vice President of Information Security and IT to build and lead the cybersecurity and corporate IT functions for a growing healthcare company. The VP will set the strategy and priorities for both functions, protecting company information while delivering reliable technology that enables our employees and the business.

About the Role

The VP will lead the company’s cybersecurity, AI governance, and corporate IT functions. Cybersecurity includes HIPAA and ePHI security, threat detection and response, product and cloud security, and audits and certifications. AI governance will be developed in partnership with Legal, Compliance, Privacy, Product, and Engineering to support the safe and responsible use of AI. Corporate IT includes workforce technology, identity and access, endpoints, collaboration tools, business systems and applications, employee support, and the use of automation and AI to improve work across the company.

This is a player-coach role for a leader with experience in healthcare and in a startup, scale-up, or similarly fast-moving environment. The successful candidate will be able to set direction, work through uncertainty, communicate clearly with executives and the Board, and stay closely involved in important security and IT work.

Responsibilities

  • Set the cybersecurity and corporate IT strategies, priorities, and plans based on the company’s goals, regulatory requirements, and risks.

  • Establish clear security policies and controls, and work with the Enterprise Risk Management team to identify, track, report, and address cybersecurity risks.

  • Lead the HIPAA Security Rule program and protect ePHI and other sensitive information from collection through disposal, including risk analysis, data classification, safeguards, remediation, and audit readiness.

  • Build the company’s capabilities in threat detection and response, identity security, security architecture and engineering, product and cloud security, vulnerability management, vendor security, security awareness, and physical security standards.

  • Partner with Product, Engineering, and Platform teams to build security into software, cloud environments, APIs, integrations, and production systems.

  • Lead AI governance, including rules for acceptable use, review and approval of AI tools, data-handling requirements, risk assessments, and ongoing monitoring.

  • Lead the response to significant security incidents and set requirements for cyber resilience and technology recovery. Work with ERM and business continuity owners on crisis planning and recovery testing.

  • Oversee HITRUST, SOC 2, applicable cybersecurity requirements, internal and external audits, regulatory reviews, and customer security assessments.

  • Keep executive leadership and the Board informed about material risks, significant incidents, program performance, and investment needs, and represent the security program with customers, auditors, and regulators.

  • Work with leaders across the company to improve business processes and productivity through business applications, integrations, automation, and AI.

  • Manage security and IT budgets, vendors, technology investments, team development, and performance, with clear measures for risk reduction, service quality, reliability, and cost.

Experience and Qualifications

  • Significant cybersecurity experience, including senior leadership of a company-wide security program.

  • Direct cybersecurity leadership experience in a HIPAA-regulated healthcare organization, with deep, practical knowledge of the HIPAA Security Rule and protecting ePHI in a covered entity or business associate environment.

  • A record of building or improving a security program in a startup, scale-up, or other fast-moving organization with limited resources and changing priorities.

  • Strong technical knowledge of cloud security, identity and access management, product and application security, information protection, incident response, vendor risk, and resilience.

  • Experience working with Product and Engineering teams in cloud-based software environments.

  • Experience with HITRUST, SOC 2, healthcare audits, and security reviews for enterprise customers.

  • Experience leading corporate IT for a distributed workforce, including business applications, endpoints, identity, employee support, and IT service delivery.

  • Practical experience with AI governance and with using business applications, automation, integrations, APIs, and AI tools to improve workflows and productivity across a company.

  • Strong leadership and communication skills, including experience developing teams, managing budgets and vendors, handling major incidents, and presenting risks and recommendations to executives and the Board.

How would you rate this job post?

See what other professionals think about this role.

banner

Gravie is a health insurance company that aims to simplify the process of finding and enrolling in health insurance plans. By leveraging technology and a consumer-centric approach, Gravie provides individuals, families, and employers with a range of health insurance options and personalized support. The company's platform allows users to compare plans, determine eligibility, and enroll in coverage, making the often complex and confusing process of buying health insurance more accessible and straightforward. Gravie also offers a range of tools and resources to help users navigate the healthcare system, including claims support, provider directories, and wellness programs. Additionally, Gravie's technology-enabled platform enables seamless integration with existing HR systems and benefits administration platforms, streamlining the administration of health benefits for employers. With a focus on innovation, customer satisfaction, and ease of use, Gravie is committed to making high-quality health insurance more affordable and accessible to everyone. The company's approach has resonated with consumers and employers alike, as it continues to expand its reach and build a reputation as a trusted and reliable partner in the health insurance industry. Gravie's mission is to empower individuals and families to take control of their healthcare and make informed decisions about their health and wellness. With its user-friendly platform, comprehensive support services, and commitment to customer satisfaction, Gravie is revolutionizing the way people interact with the healthcare system and making a positive impact on the lives of its users. Gravie's headquarters is located in Minneapolis, Minnesota, and its official website is https://www.gravie.com/careers/. The company operates in the health insurance industry, providing a range of services and support to individuals, families, and employers. Overall, Gravie is a leading provider of health insurance solutions, dedicated to providing high-quality, affordable, and accessible coverage to those who need it most.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More