avatar

Big Health is hiring a
Information Security Manager

👈 Back to all jobs

Read by 8 job seekers.

Remote - US

Our Mission
At Big Health, our mission is to help millions back to good mental health by providing fully digital, non-drug options for the most common mental health conditions. Our digital therapeutics — Sleepio for insomnia, Daylight for anxiety, and Spark Direct for depression — provide treatment anytime, anywhere. 

In pursuit of our mission, we’ve pioneered the first at-scale digital therapeutic business model, in partnership with some of the most prominent global healthcare organizations, including CVS Health and the UK’s NHS. Through product innovation, robust clinical evaluation, and a commitment to equity at scale, we are designing the next generation of medicine and the future of mental health care. 

Our Vision
Over the next 5-10 years, digital therapeutics (DTx) will transform the delivery of health care worldwide, providing access to safe and effective evidence-based treatments to billions. Big Health is in a prime position to take the lead in this transformation.

Big Health is a remote-first company, and this role can be based anywhere in the US. We encourage you to apply even if you don’t meet 100% of the job requirements.

Join us.

As our Information Security Manager, you will be responsible for developing and implementing comprehensive security policies and procedures, ensuring compliance with relevant regulations, and fostering a culture of security awareness across the organization in accordance with our company strategy.

Job Responsibilities:
  • Develop and execute a robust information security strategy aligned with organizational goals and industry best practices
  • Be an internal security expert for partner contracting, HITRUST, GDPR, NIST, HIPAA and other state and federal privacy and security requirements
  • Assess and prioritize security risks and formulate effective risk management strategies
  • Implementing comprehensive security policies and procedures, ensuring compliance with relevant regulations, and fostering a culture of security awareness across the organization as directed by our company HQ cyber security strategy
  • Collaborate with cross-functional teams to integrate security measures into business processes and applications
  • Establish and maintain information security policies, standards, and guidelines
  • Perform routine capability and maturity assessments and long-range planning, as well as evaluation of current and future-state toolsets and partnerships
  • Ensure compliance with relevant data protection laws, regulations, and industry standards
  • Coordinate and participate in security audits, assessments, and certification processes
  • Work closely with legal to address any security-related legal and regulatory requirements
  • Develop and maintain an incident response plan to address security incidents promptly and effectively
  • Lead incident response efforts, including investigation, containment, and resolution
  • Conduct post-incident analysis and implement corrective actions
  • Evaluate the security posture of vendors and third-party partners
  • Establish and maintain a robust vendor risk management program to ensure the security of third-party relationships
  • Oversee the selection, implementation, and maintenance of security technologies
  • Work closely with the IT and infrastructure teams to ensure that security controls are integrated seamlessly into the technology infrastructure for internal tools and systems, as well as for existing products
  • Assist in security-related documentation (RFPs, PPTs, etc.)

  • Required Skills and Experience:
  • Bachelor's or Master's degree in information security, cybersecurity, or a related field
  • Industry-recognized certifications such as CISSP/HCISPP, CISM, or CISA
  • Minimum of 5 years of experience in information security management
  • Strong understanding of relevant data protection laws, regulations, and industry standards
  • Excellent communication and leadership skills
  • Ability to collaborate with diverse teams and drive a culture of security awareness

  • Because we are on a mission to bring millions back to good mental health, we believe it’s essential to reflect the diversity of those we intend to serve. We’re an equal opportunity employer dedicated to building a culturally and experientially diverse team that leads with empathy and respect.

    Additionally, we will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance. Big Health participates in E-Verify and will provide the federal government with Form I-9 information from all new employees to confirm that they are authorized to work in the U.S. Big Health does not use E-Verify to pre-screen applicants.

    Estimated Salary range:

    Our salary intelligence, powered by our AI algorithms, has calculated an estimated range for this position between $95,000 - $150,000 . Please note that the actual salary for this position may vary, as it is dependent on various factors including but not limited to experience, location, and market dynamics.

    See more jobs at Big Health

    Related jobs

    Application package

    Need some help with your application? Check out our resume templates to help you prepare for your next job application.

    Buy resume templates