We are growing and are looking for a Senior Information Security Manager JD to join our mission to increase access to life-saving treatments.
The Role:
Lead and maintain all certification and compliance efforts, including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, and CIS benchmarks
Serve as the primary point of contact for all security questions and concerns, internal and external
Own global security awareness strategy and programs, including annual employee training, ongoing awareness campaigns, and phishing simulations
Respond to customer and prospect security questionnaires while maintaining agreed turnaround times
Oversee SOC (Security Operations Center) operations, including log source coverage, detection rule creation and tuning, and SLA/KPI management
Build and manage the Third-Party Risk Management, Business Continuity, and Disaster Recovery programs
Run the vulnerability steering committee across corporate and production environments
Manage vendor risk and the security risk register
Monitor and manage the company's external digital footprint using third-party attack surface management tools
Act as incident commander for security incidents - analyze, escalate, coordinate response, and drive remediation
Help design and execute the annual security roadmap
Manage the company Trust Center
Lead the internal security policy lifecycle - creation, updates, approvals, and distribution
Audit onboarding and offboarding processes from a security perspective
Requirements: 5+ years of experience in information security, with meaningful time in GRC, security operations, or a hybrid role
Hands-on experience leading or supporting SOC 2, ISO 27001, HIPAA, and GDPR certifications and audits
Strong understanding of SOC operations, SIEM tooling, detection engineering concepts, and incident response
Experience building or running a Third-Party Risk Management program
Experience acting as incident commander or lead responder for security incidents
Familiarity with vulnerability management programs across cloud and corporate environments
Strong written and verbal communication skills in English, able to represent security to customers, auditors, and executives
This position is open to all candidates.