Vice President, Information Security and IT
Listed on 2026-09-27
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Project Manager, IT Consultant
Hi, we’re Gravie. Our mission is to create health benefits that actually benefit small and midsize businesses and their employees. Our innovative benefit solutions and services are developed and delivered by a diverse group of unique people. We encourage you to be your authentic self - we like you that way.
About the RoleWe are seeking a Vice President of Information Security and IT to build and lead the cybersecurity and corporate IT functions for a growing healthcare company. The VP will set the strategy and priorities for both functions, protecting company information while delivering reliable technology that enables our employees and the business.
The VP will lead the company’s cybersecurity, AI governance, and corporate IT functions. Cybersecurity includes HIPAA and ePHI security, threat detection and response, product and cloud security, and audits and certifications. AI governance will be developed in partnership with Legal, Compliance, Privacy, Product, and Engineering to support the safe and responsible use of AI. Corporate IT includes workforce technology, identity and access, endpoints, collaboration tools, business systems and applications, employee support, and the use of automation and AI to improve work across the company.
This is a player coach role for a leader with experience in healthcare and in a startup, scale-up, or similarly fast-moving environment. The successful candidate will be able to set direction, work through uncertainty, communicate clearly with executives and the Board, and stay closely involved in important security and IT work.
ResponsibilitiesSet the cybersecurity and corporate IT strategies, priorities, and plans based on the company’s goals, regulatory requirements, and risks.
Establish clear security policies and controls, and work with the Enterprise Risk Management team to identify, track, report, and address cybersecurity risks.
Lead the HIPAA Security Rule program and protect ePHI and other sensitive information from collection through disposal, including risk analysis, data classification, safeguards, remediation, and audit readiness.
Build the company’s capabilities in threat detection and response, identity security, security architecture and engineering, product and cloud security, vulnerability management, vendor security, security awareness, and physical security standards.
Partner with Product, Engineering, and Platform teams to build security into software, cloud environments, APIs, integrations, and production systems.
Lead AI governance, including rules for acceptable use, review and approval of AI tools, data-handling requirements, risk assessments, and ongoing monitoring.
Lead the response to significant security incidents and set requirements for cyber resilience and technology recovery. Work with ERM and business continuity owners on crisis planning and recovery testing.
Oversee HITRUST, SOC 2, applicable cybersecurity requirements, internal and external audits, regulatory reviews, and customer security assessments.
Keep executive leadership and the Board informed about material risks, significant incidents, program performance, and investment needs, and represent the security program with customers, auditors, and regulators.
Work with leaders across the company to improve business processes and productivity through business applications, integrations, automation, and AI.
Manage security and IT budgets, vendors, technology investments, team development, and performance, with clear measures for risk reduction, service quality, reliability, and cost.
Significant cybersecurity experience, including senior leadership of a company wide security program.
Direct cybersecurity leadership experience in a HIPAA regulated…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).