Chief Information Security Officer
Sword Health
Job Summary
Sword Health is seeking a Chief Information Security Officer (CISO) to create and manage a global, enterprise-wide security strategy and program. Reporting to the Chief Scientific Officer, the CISO will collaborate with Engineering, Product, Operations, and HR teams to develop strategies, policies, and frameworks for application security, compliance, and security operations. The role involves defining and driving the information security roadmap, architecting programs to enhance policies, ensuring security perimeter protection, responding to incidents, participating in security audits, and updating company-wide information security policies to align with industry best practices. The CISO will also lead company-wide security initiatives and training, and partner with commercial and customer success teams.
Must Have
- 10 years of experience in cybersecurity
- Experience building and leading security teams
- Experience with SOC 2, HITRUST, CMMC, or FedRAMP audits
- Ability to lead cross-functional teams
- Excellent communication and leadership skills
- Experience with IT risk management frameworks
- US Citizen
Good to Have
- Mentorship, leadership, and collaboration skills
- CISSP or CISM certifications
- Experience in digital health and healthcare
- Strong understanding of IL6 environments
- Experience in a high-growth company
- Knowledge of ITIL practices
- Experience building clinical informatics programs
- Functional knowledge of Epic EMR system
Perks & Benefits
- Comprehensive health, dental and vision insurance
- Life and AD&D Insurance
- Financial advisory services
- Supplemental Insurance Benefits
- Health Savings Account
- Equity shares
- Discretionary PTO plan
- Parental leave
- 401(k)
- Flexible working hours
- Remote-first company
- Paid company holidays
- Free digital therapist for you and your family
Job Description
What You'll be Doing:
- Define and drive Sword's information security roadmap, strategy, tactics, and execution
- Architect programs and processes that evaluate and enhance Sword's information security policies and ensure the security of Sword's security perimeter through monitoring, remediation, reporting, and auditing
- Partner with Sword's engineering and product teams during scoping and execution of all roadmap deliverables to ensure that security concerns are treated as first class product requirements
- Respond appropriately and effectively to security-related incidents and report back to key internal and external stakeholders
- Participate in externally requested security audits from partners
- Lead efforts to continuously review and update company-wide information security policies to align with industry best practices
- Oversee and coordinate security efforts across the company alongside Privacy, Engineering, Ops, HR, Product, and more
- Stay up to date with IT/Security industry trends and evaluate new solutions & techniques
- Launch company-wide security initiatives and training
- Partner with commercial and customer success teams to support customer acquisition and retention.
What You'll Need to Have:
- ~10 years of experience building and leading security teams focused on all aspects of cybersecurity, including identity management, software security, GRC, and security operations, with increasing responsibilities
- Overseen security teams and vendor management
- Experience leading SOC 2, HITRUST, CMMC, FedRAMP or similar audits and/or certifications
- Ability to lead and motivate cross-functional teams while thriving in a fast-paced growing company
- Self-motivation and drive to go above and beyond
- Excellent communication, interpersonal and leadership skills, able to communicate security concepts to both technical and nontechnical audiences
- Experience with IT risk management standards, practices, methods, and frameworks including ISO 27001, COBIT and NIST CSF
- Drive the implementation of an effective digital health program to enhance the patient experience and improve overall outcomes
- Expertise in healthcare financial management, including IT budgeting, financial planning, and operations.
- You must be a US Citizen
We'd Love to See:
- Superior level of mentorship, leadership, and collaboration
- Professional certifications such as CISSP, CISM, etc are preferred
- Prior experience in digital health and health care
- Strong understanding of IL6 (Impact Level 6) environments, with experience implementing security measures in such high-security areas.
- Experience in a high growth company
- Possesses a functional knowledge of ITIL practice
- Experience in building clinical informatics, digital health, and data analytics programs
- Demonstrated understanding of cyber security and potential threats/current landscape
- Functional knowledge of Epic Electronic Medical Records (EMR) system.