Senior Manager, Security Operations
Spring HealthAbout the role
Our mission: to eliminate every barrier to mental health.
At Spring Health, we’re on a mission to revolutionize mental healthcare by removing every barrier that prevents people from getting the help they need, when they need it. Our clinically validated technology, Precision Mental Healthcare, empowers us to deliver the right care at the right time—whether it’s therapy, coaching, medication, or beyond—tailored to each individual’s needs.
We proudly partner with over 450 companies, from startups to multinational Fortune 500 corporations, as a leading provider of mental health service, providing care for 10 million people. Our clients include brands you use and know like Microsoft, Target, and Delta Airlines, all of whom trust us to deliver best-in-class outcomes for their employees globally. With our innovative platform, we’ve been able to generate a net positive ROI for employers and we are the only company in our category to earn external validation of net savings for customers.
We have raised capital from prominent investors including Generation Investment, Kinnevik, Tiger Global, Northzone, RRE Ventures, and many more. Thanks to their partnership and our latest Series E Funding, our current valuation has reached $3.3 billion. We’re just getting started—join us on our journey to make mental healthcare accessible to everyone, everywhere.
Reporting to the Senior Manager, Security and partnering with Engineering, the Manager, Security Operations will own the application security management functions including vulnerability management, penetration testing, threat modeling and secure application design. This is a full time position that is fully remote.
What you’ll be doing:
- Build and lead a global SecOps function (people, process, tech), including hiring plans, on-call rotations, and MSSP governance; publish a multi-year SecOps roadmap.
- Detection engineering & threat-led defense: roadmap for detections, adversary emulation
- Familiarity with AI risk, security and safety. Help prepare the org to operate an ISO/IEC 42001 AI management system
- Regulatory-grade incident response: lead enterprise incidents, exec/Board comms, postmortems, and regulator/customer notifications for HIPAA/GDPR; coordinate forensics and eDiscovery.
- Healthcare posture: ensure HITRUST control implementation and audit readiness; map SecOps controls to payer/provider customer requirements.
- Metrics & maturity: define NIST Cyber Security Framework aligned maturity targets; publish quarterly risk and performance reports.
- Mentor and guide security engineers, fostering professional growth and development through one-on-ones, coaching and real-time feedback
- Collaborate closely with cross-functional teams, consulting on security requirements and ensuring timely, high-quality delivery
What success looks like in this role:
- Reduced Mean Time To Detect, Mean Time To Respond, Mean Time To Contain
- Decreased False Negative Rate for security alerts
- Improved coverage of monitoring tools
- Commitment to team development
- Define and drive security related KPIs, including detection engineering, alert precision, and detection coverage
- Incident readiness: perform regular tabletops, training sessions, and incident postmortem after actions
- Meet SLAs for patching and incident response. Backlog burn-down based on risk
- Foster relationships with other internal teams as well as MSSP vendors
What we expect from you:
10-14 years of information security experience in a fast-moving, high growth environment, with 4-6 years leading a SecOps / SOC or IR teams
- Have a demonstrated track record of building high-quality security programs and cross-functional collaboration within a highly regulated environment
- Own a 24×7 global SOC (in-house + MSSP) with follow-the-sun coverage; set detection strategy, playbooks, and budgets; report risk and response posture to execs/Board.
- Integrate AI risk into SecOps: stand up controls and monitoring aligned to the NIST AI RMF and plan toward ISO/IEC 42001 certification/readiness for AI-enabled or AI-developed features.
- Healthcare + international compliance at scale: align SecOps with HIPAA/HITECH/HITRUST, SOC 2, ISO 27001, GDPR/UK GDPR, and data-residency requirements; partner wi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s