Triplemoon Logo

Triplemoon

Virtual Chief Information Security Officer (vCISO)

Posted 26 Days Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead Triplemoon's information security and compliance program, ensuring HIPAA compliance and SOC 2 readiness. Oversee IT operations via MSP/MSSP, manage vendor risk, coordinate incident response and audits, maintain security policies and documentation, and advise leadership on cloud-first, remote workforce security.
The summary above was generated by AI

Location: Remote (United States)

Type: Fractional / Contract

Compensation: Competitive, based on experience and scope


About Triplemoon



Triplemoon is a digital health platform transforming family wellness by addressing critical gaps in mental, behavioral, and nutritional health. We partner with providers, employers and ultimately families to provide accessible, evidence-based mental health resources that improve patient outcomes, increase provider capacity, and boost clinic financials. With growing demand for tailored, mental health resources amidst a shortage of providers (with wait times exceeding 4-6 weeks), Triplemoon is uniquely positioned to solve a critical gap in care for families and clinics. As we grow our collaborative care offering we are adding to our team.


The Opportunity

Triplemoon is seeking a Virtual Chief Information Security Officer (vCISO) to oversee and continuously strengthen our information security, IT operations, and compliance posture. As a fully remote healthcare organization, we rely on secure, scalable technology systems to support our employees, patients, and provider partners.

This role combines strategic information security leadership with hands-on operational oversight. The ideal candidate will serve as Triplemoon's trusted security advisor, ensuring our systems remain secure, compliant, and audit-ready while providing responsive support to our growing remote workforce.

ResponsibilitiesInformation Security & Compliance
  • Own the strategy, design, implementation, and continuous improvement of Triplemoon's information security and compliance program.
  • Ensure ongoing compliance with HIPAA and healthcare security best practices.
  • Lead readiness efforts for future SOC 2 certification and other security frameworks as needed.
  • Develop, maintain, and document security policies, procedures, and controls.
  • Coordinate security incident response, investigation, remediation, and post-incident reviews.
  • Support customer security questionnaires, audits, and compliance requests.
  • Partner with leadership to identify, assess, and mitigateinformation security risks.
IT Operational Oversight
  • Manage and oversee an IT MSP or MSSP who can:
    • Implement security controls and compliance within SaaS vendors and IT systems
    • Provide tiered end-user support for hardware, software, and SaaS application issues
    • Provide device and asset management
    • Manage identity and access, including systems for onboarding and offboarding
  • Maintain system documentation, operating procedures, and technology standards.
  • Recommend and implement improvements to strengthen security, scalability, and user experience.
Vendor Risk Management
  • Conduct security reviews of third-party vendors and software platforms.
  • Maintain required security documentation, including BAAs, DPAs, SOC reports, and related compliance artifacts.
  • Monitor vendor compliance and support periodic risk assessments.
Qualifications
  • 7+ years of experience in information security, IT administration, compliance, or related roles.
  • Experience serving as a vCISO, security leader, or senior security consultant.
  • Strong knowledge of HIPAA Security Rule requirements and healthcare security best practices.
  • Experience preparing organizations for SOC 2 audits and other compliance frameworks.
  • Experience supporting early-stage startups or high-growth healthcare organizations.
  • Hands-on experience administering Google Workspace, identity management platforms, endpoint management tools, and SaaS environments.
  • Familiarity with remote workforce security and cloud-first technology environments.
  • Excellent documentation, communication, and stakeholder management skills.
  • Ability to operate independently while serving as a strategic advisor to company leadership.
Preferred Qualifications
  • Experience working with and configuring cloud-native SaaS stacks for regulatory compliance, such as Vanta, 1Password, Google Workspace, Rippling, and other cloud-based healthcare technology platforms.
Success in This Role

The successful vCISO will ensure that:

  • Triplemoon maintains a strong security and compliance posture.
  • Security controls are documented, monitored, and continuously improved.
  • Systems remain reliable and well-supported for a fully remote workforce.
  • Customer security reviews and audits are completed efficiently and confidently.
  • Triplemoon remains audit-ready and positioned for future compliance milestones, including SOC 2 readiness.
  • IT issues, including onboarding and offboarding, are handled securely and consistently.


Similar Jobs

54 Minutes Ago
In-Office or Remote
Senior level
Senior level
Artificial Intelligence • Fintech • Software • Financial Services
Own enterprise new-logo acquisition and expansion while personally closing complex, high-value deals and carrying an individual quota. Hire, coach, and develop Enterprise AEs and SDRs; establish forecasting, pipeline, conversion, and sales operating cadences. Partner with Marketing, Product, Customer Success, Partnerships, Legal, and Finance, while presenting performance and strategic recommendations to executives and the board.
Top Skills: ChallengerChorusCommand Of The MessageForce ManagementGongHubspotLinkedin Sales NavigatorMeddpiccOutreachSalesloftZoominfo
55 Minutes Ago
In-Office or Remote
Mid level
Mid level
Artificial Intelligence • Fintech • Software • Financial Services
Own vulnerability management across endpoints, servers, and cloud infrastructure; prioritize remediation and track SLA performance. Harden AWS environments, improve identity management, investigate cloud alerts, and support application security through SAST, DAST, dependency scanning, secure code reviews, and threat modeling. Resolve security tickets, document incidents and remediation, and lead security initiatives while collaborating with engineering, IT, and compliance.
Top Skills: AWSAws ConfigBashCloudtrailDastGuarddutyIamJIRALinearOwasp Top 10PythonQualysS3SastScaSecurity HubSnykSoc 2TenableVpcWiz
55 Minutes Ago
In-Office or Remote
Entry level
Entry level
Artificial Intelligence • Fintech • Software • Financial Services
Generates and qualifies new business opportunities through research, cold calls, email, and social outreach. The role conducts needs analysis, communicates product value, schedules sales meetings and demos, maintains CRM records, and collaborates with sales and marketing teams. It also requires staying informed about AI, industry trends, and competitors while meeting lead-generation targets.
Top Skills: Artificial IntelligenceCrm SoftwareHubspot

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account