Jobs · Information Technology · Massachusetts

Senior Manager, Information Security and Compliance

Parabilis Medicines · Cambridge, MA · 2 days ago
On-siteInformation Technology$165k–$195k/yrFull-time

Key Responsibilities

  • Implement, configure, and operate security controls across endpoint, identity, network, and cloud, including endpoint detection and response, managed detection and response, and software and extension controls.
  • Own the endpoint security roadmap and drive execution across the environment, including migration off legacy tooling to a modern EDR/MDR stack.
  • Design and enforce identity and access controls across Okta, Entra ID, and connected systems, including least-privilege access, access recertification, and privileged access management.
  • Partner with Cloud Architecture to embed security into AWS multi-account infrastructure, including guardrails, network segmentation, logging, and posture management.
  • Serve as the technical lead for security tooling evaluations, proofs of concept, and rollouts, staying hands-on where depth is required.

Compliance, Quality & Policy Integration

  • Maintain intimate familiarity with Parabilis policies, SOPs, and QA guidance, and ensure all technical teams operate securely and within that framework.
  • Translate SOX ITGC, GxP, HIPAA, and SOC2 requirements into practical, enforceable technical controls and repeatable operating practices.
  • Partner with QA to align security controls with validated-system requirements, change control, and data integrity expectations.
  • Own control documentation, evidence collection, and traceability to support internal reviews and external audits, and act as a primary technical point of contact during audit activity.
  • Contribute to and enforce IT policy, working with the Sr. Director of IT to set standards and best practices across the organization.

Vendor & Consultant Management

  • Manage security and compliance vendors, MSP contractors, and specialist consultants, directing their work to deliver defined outcomes on schedule.
  • Own vendor risk assessment for new and existing technology partners, including privacy, data handling, and terms-of-service review in coordination with Legal and IT leadership.
  • Hold vendors accountable to SLAs, security commitments, and contractual obligations, and escalate where performance or risk warrants.

Incident Response

  • Own the security incident response process end to end, from detection and triage through containment, remediation, and post-incident review.
  • Respond to security incident reports, coordinate the technical response across internal teams and vendors, and drive incidents to closure with clear documentation.
  • Maintain and exercise incident response and business continuity runbooks, and feed lessons learned back into controls and policy.
  • Support regulatory, legal, and breach-notification obligations in coordination with IT leadership, QA, and Legal when incidents carry compliance impact.

Collaboration & Influence

  • Report to the Sr. Director of IT and work collaboratively with cross-functional teams across the organization to maintain the company's security and compliance posture across all systems.
  • Act as a trusted advisor to Engineering, Research, Clinical, and Enterprise teams, embedding secure and compliant practices into how they build and operate.
  • Communicate risk clearly to both technical and non-technical audiences, and advocate for pragmatic controls that enable the business rather than block it.

Similar jobs