Full-Time

Chief Information Security Officer

Updated on 4/8/2025

SimplePractice

SimplePractice

201-500 employees

HIPAA-compliant EHR and practice management software

Compensation Overview

$270k - $320k/yr

+ Bonus + Equity + Commission

Expert

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
Risk Management
Requirements
  • 12-15+ years of experience building and scaling information security, risk management and compliance programs within large, complex organizations
  • Previous experience as a CISO or equivalent at a SaaS company or healthcare provider. Preference given to candidates with prior experience in digital health and/or to candidates with Product Led Growth and small business customer base
  • Deep expertise in security, privacy and IT audit frameworks, such as HITRUST CSF and regulatory standards such as HIPAA and PCI
  • Extensive experience with risk management, incident response, crisis management threat intelligence and developing secure business practices
  • Strong experience in technical security areas including penetration testing, vulnerability management, mobile security, cloud security and network security
  • Experience with secure coding practices, identity and access management and security incident response
  • Strong communication skills with demonstrated ability to communicate complex surety concepts to executive leaders, to customers and other non-technical audiences
  • Experience working with high velocity software deployment environments
  • Demonstrated people management skills - ability to motivate, mentor and grow a small team of highly committed security professionals while balancing strategic vision and day-to-day operations
  • A passion for helping private practices thrive in the mental wellness space
  • Bachelor’s degree in a related field; advanced certifications such as CISSP, CISM or CISA preferred
Responsibilities
  • Create and own execution of the long-term cybersecurity and application security vision, strategy and roadmap, aligned with SimplePractice’s growth and product roadmap
  • Protect the privacy, availability, and integrity of client data
  • Establish proactive security measures to detect, prevent and mitigate cyberattacks (threat intelligence)
  • Partner with teams across the organization to establish and sustain a security-conscious culture, including the development and implementation of security policies, standards, guidelines and awareness programs
  • Provide thought leadership on contemporary security operations and be a market leader in establishing trust through security
  • Support GTM strategies to utilize security and compliance for commercial benefit
  • Anticipate strategic and scaling-related difficulties through collaborative long-term planning with key stakeholders, including identifying, assessing, and mitigating security risks.
  • Conduct ongoing evaluations of SimplePractice’s risk profile, identifying gaps and implementing a robust risk management framework
  • Oversee the management of enterprise-wide cybersecurity programs, including incident response and crisis management, 24x7 security operations, security architecture, security contingency plans and threat intelligence
  • Identify and mitigate security risks, recommending both technical and business controls to prevent vulnerabilities
  • Ensure compliance with applicable security regulations (such as HIPAA, HITRUST, PCI)
  • Obtain and maintain certifications that establish credibility in the marketplace. Deliver overall strategy for future certifications.
Desired Qualifications
  • Preference given to candidates with prior experience in digital health and/or to candidates with Product Led Growth and small business customer base
  • Advanced certifications such as CISSP, CISM or CISA preferred

SimplePractice offers HIPAA-compliant electronic health records (EHR) and practice management software for therapists and health professionals, focusing on improving administrative efficiency and patient care. Users pay a monthly subscription fee for core features like scheduling and billing, with optional add-ons such as Telehealth for video appointments and Wiley Planners for treatment planning. The company stands out by providing a comprehensive suite of tools specifically designed for health practitioners, along with an insurance add-on that simplifies claims processing. The goal of SimplePractice is to enhance practice management for clinicians while ensuring compliance with healthcare regulations.

Company Size

201-500

Company Stage

Acquired

Total Funding

N/A

Headquarters

Santa Monica, California

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • Expansion into psychiatry with ePrescribe broadens SimplePractice's market reach.
  • Partnership with Lucet enhances service offerings and opens new revenue streams.
  • Measurement-based care solution improves patient outcomes and attracts data-driven practitioners.

What critics are saying

  • Increased competition in psychiatry could impact SimplePractice's market share.
  • Integration challenges with Lucet may affect service delivery and customer satisfaction.
  • Departure of former CIO could disrupt IT strategy and operations.

What makes SimplePractice unique

  • SimplePractice offers HIPAA-compliant EHR and practice management software for health professionals.
  • The platform includes unique add-ons like Telehealth and Wiley Planners for enhanced services.
  • SimplePractice's subscription model provides flexibility with essential features and optional add-ons.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

401(k) Company Match

Unlimited Paid Time Off

Mental Health Support

Paid Parental Leave

Tuition Reimbursement

Company News

Yung Sidekick
Sep 21st, 2024
Simple Practice EHR Pricing and Reviews: What You Need to Know

Yung Sidekick'll look at the different features you get with each price plan, check out what real users say to see how it performs in the real world, and talk about how SimplePractice can team up with tools like Yung Sidekick to make therapy notes and session management better.

Fierce Healthcare
Aug 2nd, 2024
SimplePractice expands into psychiatry with prescription management tool

SimplePractice, an EHR and practice management platform, is expanding into the psychiatry space with the launch of a new prescription management tool.

Business Wire
Aug 1st, 2024
SimplePractice Expands Into the Psychiatry Space with the Launch of ePrescribe

SimplePractice expands into the psychiatry space with the launch of ePrescribe.

CNBC TV18
Dec 21st, 2023
Swiggy ties up with Simpl to introduce one-tap checkout

Swiggy has announced partnership with Simpl to offer an one-tap checkout experience to customers across food delivery platforms, Swiggy Instamart, and soon on Dineout, and Swiggy Genie.

Healthcare IT Today
Dec 10th, 2023
Bonus Features - December 10, 2023 - 84% of physicians still use manual processes to manage care transitions, 70% of executives prefer managed services for RCM, plus 26 more stories

Wellness platform SimplePractice is partnering with Lucet, which provides behavioral health services to insurers.