VP, Information Security (Security Officer)
Spring Venture GroupAbout the role
Company Description
As a leader in Medicare health insurance distribution, Spring Venture Group guides people through one of their most important life decisions — finding the right insurance coverage. We are on a mission to be the most trusted partner for our customers and our people, enabling empowered decisions along the journey to health and financial well-being.
Spring Venture Group offers incredible culture, benefits, and fantastic income potential in a stable and successful work environment at a Medicare agency. This starts with a workplace that empowers people to do their best work. Come build a rewarding career and make a meaningful impact on peoples’ lives in an environment that values your determination. Join our diverse, inclusive team and get ready to crush your goals!
Job Description
The VP, Information Security (Security Officer) provides a variety of operational, compliance, and consultative functions. This role is responsible for managing the delivery of information security systems, software and services and is responsible for the continuous development and oversight of the company’s information security program, policies, procedures and technical systems in order to maintain the confidentiality, integrity and availability of all organizational information. This role will also work across IT and business department boundaries and fulfill a senior leadership role to drive cybersecurity operations initiatives such as Enterprise wide security programs & compliance, Incident management, Security awareness & training, security monitoring, vulnerability management, identity and access management, endpoint security, network security, security architecture and application security, as well as HITRUST compliance.
The essential duties for this role include, but are not limited to:
Holds the position of HIPAA Security Officer under 45 CFR 164.308 (https://www.law.cornell.edu/cfr/text/45/164.308).
Work closely with all leaders to achieve the overall security goals of the organization. Additionally, will coordinate with the Privacy Officer, as necessary.
Mature the information security vision and strategy and lead the information security function across the company for SVG in a manner that supports business imperatives and enables organizational objectives.
Engage with various stakeholders as part of the information security program, to ensure the consistent application of policies and standards across all technology projects, systems, and services, including customer contractual requirements, privacy, risk management, compliance, and business continuity management.
Manage a cost-efficient information security organization, consisting of direct reports and dotted line staff members. This includes hiring, training, staff development, performance management, vendor management, and annual performance reviews.
Handle the 3rd party risk management function, evaluating vendors on their capabilities related to privacy, security, business continuity, and disaster recovery.
Responsible for managing the delivery of information security systems, software and services and is responsible for the continuous development and oversight of the company’s information security program, policies, procedures and technical systems in order to maintain the confidentiality, integrity and availability of all organizational information.
Responsible for assessing security plans for existing vulnerabilities, prioritizing security strategies to best cover strategically important data, analyze reports generated by their threat monitoring systems and even run testing where they anticipate potential issues.
Helps lead the company in maintaining its HIPAA & HITRUST certifications, working with external auditors to address findings and maintain compliance.
Mature the incident response plans and procedures to ensure that business-critical services are recovered in the event of a security event, providing leadership, direction, support, and in-house consulting in these areas.
Engage with business units to conduct or manage periodic risk assessments to identify vulnerabilities, threat vectors, impact, and probability. Devise effective ways to mitigate those threats in alignment with the company's risk appetite/tolerance.
Performs reviews on major initiatives, projects, and changes, to determine the information security impact and provide relevant guidance and recommendations related to security requirements
Create a risk-based process for the assessment and mitigation of any information security risk related to vendors, contractors, and any other third parties.
Oversees the incident response program, working
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s