Gravie logo

Vice President, Information Security and IT

Salary
$261K–$348K
USD
Hiring from
United States
Work type
Remote
Posted
Sep 24, 2026
Is this job info correct?

Hi, we’re Gravie. Our mission is to create health benefits that actually benefit small and midsize businesses and their employees. Our innovative benefit solutions and services are developed and delivered by a diverse group of unique people. We encourage you to be your authentic self - we like you that way.

About the Role

We are seeking a Vice President of Information Security and IT to build and lead the cybersecurity and corporate IT functions for a growing healthcare company. The VP will set the strategy and priorities for both functions, protecting company information while delivering reliable technology that enables our employees and the business.

The VP will lead the company’s cybersecurity, AI governance, and corporate IT functions. Cybersecurity includes HIPAA and ePHI security, threat detection and response, product and cloud security, and audits and certifications. AI governance will be developed in partnership with Legal, Compliance, Privacy, Product, and Engineering to support the safe and responsible use of AI. Corporate IT includes workforce technology, identity and access, endpoints, collaboration tools, business systems and applications, employee support, and the use of automation and AI to improve work across the company.

This is a player coach role for a leader with experience in healthcare and in a startup, scale-up, or similarly fast-moving environment. The successful candidate will be able to set direction, work through uncertainty, communicate clearly with executives and the Board, and stay closely involved in important security and IT work.

Responsibilities

  • Set the cybersecurity and corporate IT strategies, priorities, and plans based on the company’s goals, regulatory requirements, and risks.

  • Establish clear security policies and controls, and work with the Enterprise Risk Management team to identify, track, report, and address cybersecurity risks.

  • Lead the HIPAA Security Rule program and protect ePHI and other sensitive information from collection through disposal, including risk analysis, data classification, safeguards, remediation, and audit readiness.

  • Build the company’s capabilities in threat detection and response, identity security, security architecture and engineering, product and cloud security, vulnerability management, vendor security, security awareness, and physical security standards.

  • Partner with Product, Engineering, and Platform teams to build security into software, cloud environments, APIs, integrations, and production systems.

  • Lead AI governance, including rules for acceptable use, review and approval of AI tools, data-handling requirements, risk assessments, and ongoing monitoring.

  • Lead the response to significant security incidents and set requirements for cyber resilience and technology recovery. Work with ERM and business continuity owners on crisis planning and recovery testing.

  • Oversee HITRUST, SOC 2, applicable cybersecurity requirements, internal and external audits, regulatory reviews, and customer security assessments.

  • Keep executive leadership and the Board informed about material risks, significant incidents, program performance, and investment needs, and represent the security program with customers, auditors, and regulators.

  • Work with leaders across the company to improve business processes and productivity through business applications, integrations, automation, and AI.

  • Manage security and IT budgets, vendors, technology investments, team development, and performance, with clear measures for risk reduction, service quality, reliability, and cost.

Experience and Qualifications

  • Significant cybersecurity experience, including senior leadership of a company-wide security program.

  • Direct cybersecurity leadership experience in a HIPAA-regulated healthcare organization, with deep, practical knowledge of the HIPAA Security Rule and protecting ePHI in a covered entity or business associate environment.

  • A record of building or improving a security program in a startup, scale-up, or other fast-moving organization with limited resources and changing priorities.

  • Strong technical knowledge of cloud security, identity and access management, product and application security, information protection, incident response, vendor risk, and resilience.

  • Experience working with Product and Engineering teams in cloud-based software environments.

  • Experience with HITRUST, SOC 2, healthcare audits, and security reviews for enterprise customers.

  • Experience leading corporate IT for a distributed workforce, including business applications, endpoints, identity, employee support, and IT service delivery.

  • Practical experience with AI governance and with using business applications, automation, integrations, APIs, and AI tools to improve workflows and productivity across a company.

  • Strong leadership and communication skills, including experience developing teams, managing budgets and vendors, handling major incidents, and presenting risks and recommendations to executives and the Board.

A Little More About Us:

  • We know healthcare. Our company was founded and is still led by industry veterans who have started and grown several market-leading companies in the space.

  • We have raised money from top tier investors who share the same long-term vision as we do of building an industry defining company that will endure over the long run. We are well capitalized.

  • Our clients love us. Customer satisfaction rates among employees using Gravie health plans consistently rank above 80% – nearly 40 points above the industry average.

  • Our culture is unique. We tend to be non-hierarchical, merit-driven, opinionated but kind people who thrive working in a high-performance, fast-paced environment. People at Gravie care deeply about making a positive impact in the lives of the people we serve.

Benefits

Our unique benefits program is the gravy, i.e., the special sauce that sets our compensation package apart. In addition to standard health and wellness benefits, Gravie’s package includes alternative medicine coverage, flexible PTO, up to 16 weeks paid parental leave, paid holidays, a 401k program, transportation perks, education reimbursement, and 2 days of paid paw-ternity leave.

Job Applicants

If you apply for employment with Gravie, personal information collected via our applicant tracking vendor is subject to our standalone California Job Applicant Notice at Collection, accessible directly within the application workflow and separate from this Policy.

Similar jobs

Apply for this job