远程工作雷达

信息安全部主管

Head of Information Security

开发工程职能支持限定地区(需当地身份)
公司Accumulus Technologies
薪资$200,000 - $260,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

关于Accumulus Technologies

Accumulus Technologies帮助生命科学公司减少监管摩擦,缩短时间线,降低产品开发和生命周期管理中的执行风险,实现可衡量且具有变革性的投资回报率。我们支持全面的监管参与——策略、提交和生命周期管理,涵盖CMC、临床和非临床内容、标签、承诺、批准后变更以及依赖/协作模式。我们的重点是商业影响:更快的审批、更顺畅的批准后变更执行、更少的意外情况,以及承诺与团队实际交付能力之间的更紧密对齐。我们的客户衡量我们带来的价值达数千万美元。

职位描述
Accumulus Technologies正在寻找一位信息安全主管,负责公司企业运营和Accumulus平台的信息安全职能。该职位直接向首席运营官汇报,并在重大安全事项上直接向高管领导层和董事会报告。这位领导者将制定安全战略,监督治理、风险和合规工作,并代表Accumulus的安全立场与客户、监管机构和其他外部利益相关者进行沟通。

您将领导网络安全、产品安全和GRC团队。与工程、产品、DevOps、IT、法律和商业部门合作,您将把业务优先级和安全风险转化为可行的路线图,建立明确的控制责任,并对团队的交付成果负责。

这是一个战略性且亲力亲为的领导机会,适合一位兼具技术判断力、运营纪律性和清晰沟通能力的安全领导者,以保护业务、维持保证承诺并建立客户信任。

职责

  • 负责企业及产品信息安全战略、计划和年度目标;制定优先级路线图,并与首席运营官协调安全资源和投资需求。
  • 负责Accumulus在云基础设施、产品安全、身份管理、漏洞管理、检测与响应以及安全架构等方面的技朮安全能力的发展,根据关键业务和网络风险优先安排投资。
  • 领导并发展网络安全和产品安全团队;设定优先级、绩效期望和内部员工及外部供应商的责任。
  • 监督GRC计划及审计协调、证据收集等工作的执行。
查看英文原文

About Accumulus Technologies

Accumulus Technologies helps life sciences companies reduce regulatory friction, shorten timelines, and lower execution risk across product development and lifecycle management—delivering measurable and transformational ROI. We support the full spectrum of regulatory engagements—strategy, submissions, and lifecycle management—spanning CMC, clinical and nonclinical content, labeling, commitments, post-approval changes, and reliance/work-sharing models. Our focus is commercial impact: faster approvals, smoother post-approval change execution, fewer surprises, and tighter alignment between commitments and what teams can deliver. Our clients measure the value we bring in the tens of millions.
Job Description
Accumulus Technologies is seeking a Head of Information Security to lead the company’s information security function across corporate operations and the Accumulus Platform. Reporting directly to the Chief Operating Officer, with direct access to executive leadership and the Board on material security matters, this leader will set security strategy, oversee governance, risk, and compliance, and represent Accumulus’ security posture to customers, regulators, and other external stakeholders.
You will lead the CyberDefense, Product Security, and GRC teams. Working with Engineering, Product, DevOps, IT, Legal, and Commercial, you will translate business priorities and security risks into a practical roadmap, establish clear control ownership, and hold teams accountable for delivery.
This is a strategic and hands-on leadership opportunity for a security leader who combines technical judgment, operational discipline, and clear communication to protect the business, sustain assurance commitments, and build customer trust.
Responsibilities

  • Own the corporate and product information security strategy, program, and annual objectives; define a prioritized roadmap and align security resources and investment needs with the COO.
  • Own the evolution of Accumulus’ technical security capabilities across cloud infrastructure, product security, identity, vulnerability management, detection and response, and security architecture, prioritizing investment according to material business and cyber risk.
  • Lead and develop the CyberDefense and Product Security teams; set priorities, performance expectations, and accountability for internal staff and external providers.
  • Oversee the GRC program and delivery of audit coordination, evidence collection, policies, assessments, remediation tracking, and Vanta administration; retain accountability for program outcomes.
  • Maintain audit readiness and oversee required audits, certifications, and attestations, prioritizing current commitments and the effective operation of supporting controls.
  • Review material cyber risks, challenge risk ratings and treatment plans, approve security exceptions within delegated authority, and escalate business risk acceptance to executive leadership.
  • Partner with Engineering, Product, DevOps, and IT leadership to embed security in architecture, development, and operations; hold control owners accountable for effective safeguards and timely remediation.
  • Provide senior security direction during material incidents, authorize escalations, oversee lessons learned, and ensure incident response, disaster recovery, and business continuity capabilities are tested with accountable teams.
  • Resolve cross-functional security decisions affecting delivery, customer commitments, or business risk; escalate unresolved tradeoffs and investment needs to the COO and executive leadership.
  • Report security posture, material risks, incidents, remediation performance, emerging threats, and investment priorities to executive leadership and the Board, as appropriate.
  • Serve as Accumulus’ senior security representative with customers, prospects, regulators, auditors, partners, and insurers; clearly explain the company’s architecture, controls, certifications, risk posture, and regulatory environment.
  • Lead Accumulus’ customer security assurance program, including strategic customer and prospect discussions, due diligence, RFPs, and security assessments; establish a scalable response process and ensure timely, accurate responses.

Qualifications

  • Substantial progressive experience in information security, including leadership of a corporate or product security function and ownership of security strategy and program delivery.
  • Demonstrated ability to manage and develop internal security teams and hold external contractors or service providers accountable for results.
  • Required familiarity with Vanta and with ISO 27001, SOC 2, and HITRUST; practical experience overseeing GRC programs, audits, evidence readiness, and remediation.
  • Strong understanding of cloud and SaaS security, secure development, identity and access management, encryption, vulnerability management, monitoring, and incident response.
  • Experience assessing cyber risk, evaluating control effectiveness, governing security exceptions, and translating technical findings into business decisions.
  • Proven ability to lead customer security reviews and questionnaires and communicate security posture credibly to executives, auditors, regulators, and technical stakeholders.
  • Experience coordinating response, recovery, resilience testing, and follow-through on corrective actions.
  • Ability to prioritize competing demands, influence cross-functional teams, and make pragmatic, risk-based security decisions that support product delivery and commercial objectives while protecting the company’s security and assurance commitments.
  • Experience in SaaS, life sciences, or other regulated environments preferred; CISSP, CISM, or a comparable security certification is a plus.

Compensation and Benefits
• Base salary: $200,000 - $260,000/year
• Discretionary bonus of 22%.

  • 3% contribution to a 401(k), even if you do not make contributions.
  • Medical, dental, vision, short-term disability, long-term disability, and life insurance from day one.

• Unlimited vacation.
• Up to 16 weeks of parental leave.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

← 返回全部职位