Location
Remote
Employment Type
Full time
Location Type
Remote
Department
Finance & Legal
InfoSec
Compensation
$225K - $285K . Offers Equity . Offers Bonus
Virta Health is on a mission to transform type 2 diabetes and weight-loss care. Current treatment approaches aren’t working-over half of US adults have either type 2 diabetes or prediabetes, and obesity rates are at an all-time high. Virta is changing this by helping people reverse their metabolic condition through innovations in technology, personalized nutrition, and virtual care delivery reinvented from the ground up. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. Join us on our mission to reverse diabetes and obesity in one billion people.
As
Vice President of Information Technology and Security, you will serve as a critical member of the leadership team, responsible for defining and executing the security and IT vision across the organization. You will lead efforts to architect and build secure, scalable systems that power our mission-critical applications, while ensuring that enterprise security and IT operations enable productivity and resilience at scale. This role combines deep technical acumen with strategic oversight and cross-functional leadership.You’ll be instrumental in enabling our AI efforts to scale securely, allowing developers to focus on solving complex problems without being encumbered by infrastructure or operational and legal risks. Your influence will span from product design to employee experience, making you a key decision-maker in the company’s long-term strategy.
We’d love to hear from you if you have:
+ Meet with executive leadership to understand company strategy, growth goals, IT and InfoSec pain points and AI priorities.
+ Identify departments currently using or planning to use AI (e.g., support automation, clinical ops, engineering, legal).
+ Review internal AI usage guidelines, current OpenAI or third-party LLM contracts, and any prior security assessments.
+ Conduct 1:1s with Security, IT, and cross-functional stakeholders (Product, Engineering, Data Science/AAa, Legal, Privacy, HR).
+ Audit enterprise tools, endpoints, cloud infrastructure, and integrations that interface with AI/ML workloads.
+ Inventory all known AI usage: internal tools, SaaS platforms with embedded AI, custom LLMs, and shadow AI adoption.
+ Review existing policies related to acceptable AI use, data classification, and PHI/PII handling in AI systems.
+ Identify risks around sensitive data exposure, model drift, and external AI API calls.
+ Assess current alignment with frameworks such as
NIST AI RMF, HIPAA, and HITRUST for AI governance.+ Develop a lightweight, business-friendly AI governance model: acceptable use, human-in-the-loop requirements, data inputs/outputs, and usage approvals.
+ Work with Legal and Privacy to address data residency, PHI exposure, and contractual guardrails for AI vendors.
+ Define clear lines of ownership for AI tooling and model integration into internal workflows.
+ Identify specific operational areas for AI enablement (e.g., Zendesk ticket classification, onboarding FAQs, coding support, reporting automation).
+ Prioritize use cases that reduce SaaS sprawl or eliminate manual effort (e.g., documentation, internal training).
+ Evaluate internal AI solutions vs. vendor platforms for optimal cost control.
+ Roll out quick-win security upgrades (SSO enforcement, device posture, GCP policy tightening).
+ Draft or revise security/IT policies (including AI usage, endpoint protection, access control).
+ Identify key automation opportunities in corporate IT (e.g., offboarding workflows, MDM enforcement, helpdesk triage with AI).
+ Launch initial AI pilots in prioritized departments (e.g., IT support automation, compliance reporting, auto-drafting engineering documentation).
+ Develop dashboards to track AI adoption, model usage, cost, and business impact.
+ Partner with Engineering/AAA to embed security into model pipelines (input validation, logging, hallucination handling).
+ Finalize and publish core security and AI usage policies; begin annual review cadences.
+ Implement monitoring controls for AI API usage, cost alerts, and sensitive data access.
+ Launch internal training on secure and responsible AI use for employees.
+ Deploy tooling to support onboarding/offboarding automation with least-privilege principles.
+ Enable frictionless employee experience (self-service support, AI-first helpdesk, unified endpoint management).
+ Close key audit gaps; initiate pre-certification steps for SOC 2 or HITRUST if needed.
+ Publish monthly Security & IT newsletters with transparency on risks, initiatives, and metrics.
+ Host “AI Office Hours†to encourage responsible experimentation and collect feedback.
+ Establish a cross-functional “AI Task Force†to guide innovation and policy.
Virta’s company values drive our culture, so you’ll do well if:
Virta has a location based compensation structure. Starting pay will be based on a
number of factors and commensurate with qualifications & experience. For
this role, the compensation range is $225,000-$285,000 plus bonus and equity.
Yearly based
Worldwide
Remote , United States