Chief Technology & Cybersecurity Officer

Posted 18 days ago

confidentialSan Jose (CA)
Computer and Information Systems ManagersComputer Systems Design Services

SENIORITY

Director

Apply

About the role

Chief Technology & Cybersecurity OfficerAbout the CompanyPioneering provider of telephonic behavioral health servicesIndustryHospital & Health CareTypePrivately HeldFounded1992Employees201-500CategoriesMental HealthAddiction TreatmentOutpatientHealth CareConsulting & Professional ServicesMedicineHealthcareHospitals & ClinicsSpecialtiesmental health triagecall centerbehavioral healthself-help appand provider networkAbout the RoleThe Chief Technology & Cybersecurity Officer (CTCO) is a strategic, hands-on technology and security leader responsible for leading the technology strategy, cybersecurity program, infrastructure, product technology direction, vendor security oversight and compliance readiness. The CTCO is responsible for ensuring that our information systems are scalable, secure, resilient, and aligned with the needs of healthcare, public-sector, higher education, and enterprise customers. This position also serves as our Security Officer as defined by HIPAA. Responsibilities Technology Strategy & Leadership Develop and execute the organization's technology strategy in alignment with business goals, customer needs, compliance obligations, and product growth. Serve as the senior technology advisor to executive leadership, helping translate technical risks and opportunities into business decisions. Provide leadership across internal IT, cloud infrastructure, data systems, software platforms, cybersecurity, and technology vendor relationships. Evaluate current systems, architecture, tools, and processes and recommend improvements for scalability, reliability, interoperability, security, and cost effectiveness. Partner with product, operations, clinical, compliance, and customer success teams to ensure technology supports our service offerings. Help guide build-versus-buy decisions, platform modernization, integrations, and technology roadmap priorities. Establish technology governance practices appropriate for a healthcare organization serving commercial, higher education, and government-adjacent customers. Cybersecurity, Privacy & Compliance Lead the organization's information security program, including security strategy, policies, risk assessments, controls, incident response, vendor risk management, and employee security awareness. Ensure technology and security practices support HIPAA requirements and customer expectations related to protected health information, privacy, confidentiality, availability, and breach prevention. Lead readiness efforts related to GovRAMP, NIST, SOC 2, HITRUST, or similar security and compliance frameworks, as applicable to customer and market needs. Develop and maintain security policies, standards, procedures, and documentation required for customer audits, RFPs, security questionnaires, and compliance reviews. Oversee security monitoring, vulnerability management, access controls, endpoint protection, cloud security, backup and recovery practices, and incident response planning. Partner with legal, compliance, People Services, and operations teams on privacy, data retention, business continuity, disaster recovery, and security incident response. Lead or coordinate tabletop exercises, risk reviews, vendor assessments, and remediation plans. Support sales and customer-facing teams by responding to security questionnaires, participating in customer security reviews, and clearly explaining the organization's security posture. Infrastructure, Operations & Reliability Oversee the reliability, availability, and security of technology systems supporting 24/7 mission-critical operations. Ensure appropriate disaster recovery, business continuity, backup, monitoring, and escalation processes are in place. Manage cloud platforms, SaaS systems, telecommunications-related technology, identity and access management, and internal IT systems either directly or through staff and vendors. Establish appropriate service levels, operational metrics, and technology performance reporting. Identify and reduce technology risks that could affect service continuity, customer trust, compliance, or clinical operations. Product & Data Support Partner with product and business leaders on the technology direction of our digital product offerings. Advise on secure software development practices, data architecture, integrations, authentication, privacy-by-design, and customer-specific security needs. Lead the organization's strategy for the responsible evaluation, adoption, and governance of artificial intelligence, machine learning, automation, and emerging technologies. Establish AI governance practices that address privacy, security, HIPAA compliance, bias, transparency, vendor oversight, data use, clinical risk, and customer trust. Partner with executive, clinical, compliance, legal, product, and operations leaders to identify appropriate AI-enabled opportunities that improve service quality, operational efficiency, workforce support, customer reporting, and user experience. Evaluate AI tools and vendors for security, privacy, data retention, model training practices, contractual protections, and alignment with healthcare and public-sector customer requirements. Ensure that AI solutions involving protected health information, crisis services, clinical workflows, or customer data are reviewed through appropriate risk, compliance, and ethical governance processes before implementation. Develop policies and guardrails for employee use of generative AI tools, including acceptable use, prohibited data sharing, documentation expectations, and review requirements. Support responsible use of AI in areas such as contact center operations, quality assurance, documentation support, analytics, fraud/risk detection, customer insights, product personalization, and administrative workflow automation. Help the organization distinguish between safe, practical AI use cases and high-risk applications that require additional oversight, validation, human review, or should not be pursued. Monitor evolving AI-related legal, regulatory, security, and customer expectations, particularly as they relate to healthcare, behavioral health, HIPAA-regulated data, and government-funded or public-sector programs. Promote a culture of innovation that balances AI-enabled efficiency with clinical quality, human judgment, privacy, accessibility, and the organization's mission.FunctionsInformation TechnologySkillsTechnology required

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this

Chief Technology & Cybersecurity Officer Jobs at confidential |...