← All roles
VP

Vice President, Information Security and IT

Gravie · Healthcare · 201-500 employees

United States · Remote · full_time

CLI Career Level

VP-equivalent

Moderate confidence

Opportunity Score

71/100

Above average

High confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Sep 25, 2026 · Last verified yesterday · Sourced from LinkedIn — VP / Head of Security (US)

CLI Take

Scope matches the title

CLI reads this as a VP-equivalent mandate, consistent with how the employer has titled it. CLI's analysis of the posting describes a strategic build or transformation mandate, and it carries board-level exposure and carries HIPAA and HITRUST accountability. Scope language covers executive committee exposure. The reporting line and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

71/100 — above average opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: Scope language covers executive committee exposure. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

VP-equivalent — The employer lists this as “Vice President, Information Security and IT”. CLI reads it as VP-equivalent because the role shows board-level exposure expected, executive committee exposure, 201-500 employee organization.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • Board-level exposure is expected in the role.
  • The role carries more scope than the employer's title suggests.
  • Signals worth probing: This is a player coach role... with limited resources and changing priorities..

What to probe before applying

  • Scope language covers executive committee exposure.

Scoring components · Above average

Compensation versus comparable roles55 · weight 15%

The employer discloses a base range, but there is no comparable set to benchmark it against yet.

Reporting levelNot disclosed · excluded from the score

Reporting line: not disclosed.

Functional and geographic scope21 · weight 12%

Scope language covers executive committee exposure.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposure100 · weight 10%

Board-level exposure is expected in the role.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory58 · weight 10%

Employer profile: 201-500 employee organization, vc backed ownership, series d plus, revenue 50m 250m.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals75 · weight 5%

Signals worth probing: This is a player coach role... with limited resources and changing priorities..

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

$261,000 – $348,000 base salary, disclosed by employer

Sample size not yet sufficient for a market comparison

Tasked with managing security and IT budgets and technology investments.

See the full benchmark bands by level and region

The mandate

Build and lead both the cybersecurity and corporate IT functions for a growing healthcare company. The leader will serve as a 'player-coach,' setting strategy for HIPAA compliance, AI governance, and cloud security while overseeing workforce technology and IT service delivery.

This VP oversees a dual mandate covering Cybersecurity (threat detection, HIPAA, cloud/product security) and Corporate IT (workforce tech, identity, business systems). The role presents directly to the Board and manages the security and IT budgets.

Scope

  • Board-level exposure expected

Domains and regulation

  • Enterprise Security
  • Product Security
  • Cloud Security
  • Cyber Defense
  • Incident Response
  • Identity
  • GRC
  • Third-Party Risk
  • Compliance
  • Privacy
  • Physical Security
  • Resilience
  • DevSecOps
  • HIPAA
  • HITRUST
  • SOC 2

Requirements

Must have

  • Significant cybersecurity experience, including senior leadership of a company-wide security program.
  • Direct cybersecurity leadership experience in a HIPAA-regulated healthcare organization, with deep, practical knowledge of the HIPAA Security Rule and ePHI.
  • A record of building or improving a security program in a startup, scale-up, or other fast-moving organization.
  • Experience leading corporate IT for a distributed workforce, including business applications, endpoints, and identity.
  • Experience working with Product and Engineering teams in cloud-based software environments.
  • Practical experience with AI governance and using automation/APIs to improve productivity.

Preferred / bonus

  • Nothing listed as optional.

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Signals worth probing

Not stated in the posting: Specific reporting line (e.g., reports to CEO, COO, or CFO) not specified beyond board interaction.; Physical city location for the headquarters is not listed (stated as United States)..

About Gravie

Gravie is a health insurance technology company that provides defined-contribution benefit models and health plans to small and mid-sized employers. The company offers a flagship product called Comfort, which provides comprehensive coverage with zero-deductible primary and preventative care. For a security leader, the organization represents a high-growth fintech and healthtech environment handling sensitive PHI and financial data.

Industry
Healthcare
Headcount
201-500 employees
Headquarters
Minneapolis, MN
Founded
2013
Ownership
Venture backed
Funding
Series D or later · $360M raised
Revenue
$50M – $250M
Investors
General Catalyst, AXA Venture Partners, FirstMark Capital, New Enterprise Associates (NEA), GEHA Ventures

Full company profile for Gravie →

View original job description
Hi, we’re Gravie. Our mission is to create health benefits that actually benefit small and midsize businesses and their employees. Our innovative benefit solutions and services are developed and delivered by a diverse group of unique people. We encourage you to be your authentic self - we like you that way.About The RoleWe are seeking a Vice President of Information Security and IT to build and lead the cybersecurity and corporate IT functions for a growing healthcare company. The VP will set the strategy and priorities for both functions, protecting company information while delivering reliable technology that enables our employees and the business.The VP will lead the company’s cybersecurity, AI governance, and corporate IT functions. Cybersecurity includes HIPAA and ePHI security, threat detection and response, product and cloud security, and audits and certifications. AI governance will be developed in partnership with Legal, Compliance, Privacy, Product, and Engineering to support the safe and responsible use of AI. Corporate IT includes workforce technology, identity and access, endpoints, collaboration tools, business systems and applications, employee support, and the use of automation and AI to improve work across the company.This is a player coach role for a leader with experience in healthcare and in a startup, scale-up, or similarly fast-moving environment. The successful candidate will be able to set direction, work through uncertainty, communicate clearly with executives and the Board, and stay closely involved in important security and IT work.ResponsibilitiesSet the cybersecurity and corporate IT strategies, priorities, and plans based on the company’s goals, regulatory requirements, and risks.Establish clear security policies and controls, and work with the Enterprise Risk Management team to identify, track, report, and address cybersecurity risks.Lead the HIPAA Security Rule program and protect ePHI and other sensitive information from collection through disposal, including risk analysis, data classification, safeguards, remediation, and audit readiness.Build the company’s capabilities in threat detection and response, identity security, security architecture and engineering, product and cloud security, vulnerability management, vendor security, security awareness, and physical security standards.Partner with Product, Engineering, and Platform teams to build security into software, cloud environments, APIs, integrations, and production systems.Lead AI governance, including rules for acceptable use, review and approval of AI tools, data-handling requirements, risk assessments, and ongoing monitoring.Lead the response to significant security incidents and set requirements for cyber resilience and technology recovery. Work with ERM and business continuity owners on crisis planning and recovery testing.Oversee HITRUST, SOC 2, applicable cybersecurity requirements, internal and external audits, regulatory reviews, and customer security assessments.Keep executive leadership and the Board informed about material risks, significant incidents, program performance, and investment needs, and represent the security program with customers, auditors, and regulators.Work with leaders across the company to improve business processes and productivity through business applications, integrations, automation, and AI.Manage security and IT budgets, vendors, technology investments, team development, and performance, with clear measures for risk reduction, service quality, reliability, and cost.Experience And QualificationsSignificant cybersecurity experience, including senior leadership of a company-wide security program.Direct cybersecurity leadership experience in a HIPAA-regulated healthcare organization, with deep, practical knowledge of the HIPAA Security Rule and protecting ePHI in a covered entity or business associate environment.A record of building or improving a security program in a startup, scale-up, or other fast-moving organization with limited resources and changing priorities.Strong technical knowledge of cloud security, identity and access management, product and application security, information protection, incident response, vendor risk, and resilience.Experience working with Product and Engineering teams in cloud-based software environments.Experience with HITRUST, SOC 2, healthcare audits, and security reviews for enterprise customers.Experience leading corporate IT for a distributed workforce, including business applications, endpoints, identity, employee support, and IT service delivery.Practical experience with AI governance and with using business applications, automation, integrations, APIs, and AI tools to improve workflows and productivity across a company.Strong leadership and communication skills, including experience developing teams, managing budgets and vendors, handling major incidents, and presenting risks and recommendations to executives and the Board.A Little More About UsWe know healthcare. Our company was founded and is still led by industry veterans who have started and grown several market-leading companies in the space.We have raised money from top tier investors who share the same long-term vision as we do of building an industry defining company that will endure over the long run. We are well capitalized.Our clients love us. Customer satisfaction rates among employees using Gravie health plans consistently rank above 80% – nearly 40 points above the industry average.Our culture is unique. We tend to be non-hierarchical, merit-driven, opinionated but kind people who thrive working in a high-performance, fast-paced environment. People at Gravie care deeply about making a positive impact in the lives of the people we serve.BenefitsOur unique benefits program is the gravy, i.e., the special sauce that sets our compensation package apart. In addition to standard health and wellness benefits, Gravie’s package includes alternative medicine coverage, flexible PTO, up to 16 weeks paid parental leave, paid holidays, a 401k program, transportation perks, education reimbursement, and 2 days of paid paw-ternity leave.Job ApplicantsIf you apply for employment with Gravie, personal information collected via our applicant tracking vendor is subject to our standalone California Job Applicant Notice at Collection, accessible directly within the application workflow and separate from this Policy.Compensation Range: $261K - $348K

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.