
Senior Manager, Information Security and Compliance
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in Massachusetts.
• Implement, configure, and manage security measures across endpoint, identity, network, and cloud environments.
• Take ownership of the endpoint security roadmap and facilitate the transition to an advanced EDR/MDR stack.
• Design and enforce identity and access controls across Okta, Entra ID, and associated systems.
• Collaborate with Cloud Architecture to integrate security within AWS multi-account infrastructures.
• Lead evaluations, proofs of concept, and implementations of security tools.
• Convert SOX ITGC, GxP, HIPAA, and SOC2 requirements into actionable technical controls and operational practices.
• Partner with QA on validated-system prerequisites, change management, and data integrity.
• Manage control documentation, evidence collection, audit traceability, and provide technical audit assistance.
• Oversee security and compliance vendors, managed service provider contractors, and specialized consultants.
• Conduct vendor risk assessments and ensure vendors adhere to SLAs and security commitments.
• Lead the security incident response process from detection and triage to containment, remediation, and post-incident analysis.
• Maintain and execute incident response and business continuity runbooks.
• Support regulatory, legal, and breach notification responsibilities.
• Advise Engineering, Research, Clinical, and Enterprise teams on secure and compliant methodologies.
• Communicate risk effectively and advocate for practical controls across both technical and non-technical audiences.
• Over 6 years of practical experience in technical security.
• Experience working in regulated compliance environments such as FDA/GxP, HIPAA, SOX, or SOC2.
• Ideally possess experience in life sciences, healthcare, or other audited sectors.
• Demonstrated hands-on expertise in endpoint security, including EDR/MDR.
• Proven experience in identity and access management using Okta and Entra ID.
• Proficient in AWS multi-account cloud security.
• Experienced in implementing and managing security controls while aligning them with compliance frameworks and audit standards.
• Background in leading incident response and overseeing security and compliance vendors and consultants.
• Familiarity with QA and change control practices in regulated settings.
• Ability to prioritize tasks autonomously, remain hands-on, and guide external partners.
• Proficient in PowerShell, Python, or similar scripting languages.
• Outstanding communication skills and ability to influence across cross-functional teams.
• Bachelor’s degree in Computer Science, Information Systems, or a related field is preferred.
• CISA and/or CISSP certification is preferred.
• Annual target bonus.
• Equity options.
• A comprehensive range of competitive benefits aimed at supporting employees' overall well-being.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.