Remote job
Senior Manager, Information Security and Compliance
Job details
About this role
Role overview Join a recently public, clinical-stage biopharmaceutical organization as a Senior Manager of Information Security and Compliance, reporting to the Senior Director of IT. The role partners closely with the IT leader to own and operate the technical security posture while weaving compliance and quality into every control. It is a hands-on position that blends endpoint, identity, network, and cloud security engineering with practical enforcement of SOX, GxP, HIPAA, and SOC2 obligations in a lean, high-impact environment.
Responsibilities - Design, deploy, and operate security controls spanning endpoint protection, identity platforms, network defenses, and cloud infrastructure, covering EDR, MDR, and software or extension governance. - Own the endpoint security roadmap, including migrating off legacy tools onto a modern EDR/MDR stack. - Build and enforce identity and access controls across identity providers and connected systems, applying least-privilege, access recertification, and privileged access management. - Collaborate with cloud architecture to embed guardrails, segmentation, logging, and posture management into AWS multi-account environments. - Translate SOX ITGC, GxP, HIPAA, and SOC2 requirements into technical controls and repeatable operating practices that align with validated-system and change control needs. - Lead incident response, direct MSP contractors and consultants, and serve as technical lead for tooling evaluations, proofs of concept, and rollouts.
Requirements - Hands-on practitioner experience operating security tooling across endpoint, identity, and cloud environments. - Working knowledge of SOX, GxP, HIPAA, and SOC2 frameworks and how they map to technical controls. - Familiarity with QA and change control practices in regulated environments and the judgment to make controls satisfy both security and compliance goals. - Proficiency in scripting such as PowerShell or Python for automation and integration. - Comfort operating in a lean team, setting priorities independently, and directing external partners without relying on direct reports. - Strong communication skills and the ability to influence cross-functional teams without formal authority.
Nice to have - CISA (compliance and audit focus) and/or CISSP (security focus) certifications.
Benefits and work setup - Base salary range of $165,000–$195,000 depending on experience and qualifications. - Annual target bonus, equity, and a comprehensive benefits package. - On-site or hybrid role based in Cambridge, MA.