Senior Manager, Information Security and Compliance
Parabilis Medicines · Cambridge, MA · 2 days ago
On-siteInformation Technology$165k–$195k/yrFull-time
Key Responsibilities
- Implement, configure, and operate security controls across endpoint, identity, network, and cloud, including endpoint detection and response, managed detection and response, and software and extension controls.
- Own the endpoint security roadmap and drive execution across the environment, including migration off legacy tooling to a modern EDR/MDR stack.
- Design and enforce identity and access controls across Okta, Entra ID, and connected systems, including least-privilege access, access recertification, and privileged access management.
- Partner with Cloud Architecture to embed security into AWS multi-account infrastructure, including guardrails, network segmentation, logging, and posture management.
- Serve as the technical lead for security tooling evaluations, proofs of concept, and rollouts, staying hands-on where depth is required.
Compliance, Quality & Policy Integration
- Maintain intimate familiarity with Parabilis policies, SOPs, and QA guidance, and ensure all technical teams operate securely and within that framework.
- Translate SOX ITGC, GxP, HIPAA, and SOC2 requirements into practical, enforceable technical controls and repeatable operating practices.
- Partner with QA to align security controls with validated-system requirements, change control, and data integrity expectations.
- Own control documentation, evidence collection, and traceability to support internal reviews and external audits, and act as a primary technical point of contact during audit activity.
- Contribute to and enforce IT policy, working with the Sr. Director of IT to set standards and best practices across the organization.
Vendor & Consultant Management
- Manage security and compliance vendors, MSP contractors, and specialist consultants, directing their work to deliver defined outcomes on schedule.
- Own vendor risk assessment for new and existing technology partners, including privacy, data handling, and terms-of-service review in coordination with Legal and IT leadership.
- Hold vendors accountable to SLAs, security commitments, and contractual obligations, and escalate where performance or risk warrants.
Incident Response
- Own the security incident response process end to end, from detection and triage through containment, remediation, and post-incident review.
- Respond to security incident reports, coordinate the technical response across internal teams and vendors, and drive incidents to closure with clear documentation.
- Maintain and exercise incident response and business continuity runbooks, and feed lessons learned back into controls and policy.
- Support regulatory, legal, and breach-notification obligations in coordination with IT leadership, QA, and Legal when incidents carry compliance impact.
Collaboration & Influence
- Report to the Sr. Director of IT and work collaboratively with cross-functional teams across the organization to maintain the company's security and compliance posture across all systems.
- Act as a trusted advisor to Engineering, Research, Clinical, and Enterprise teams, embedding secure and compliant practices into how they build and operate.
- Communicate risk clearly to both technical and non-technical audiences, and advocate for pragmatic controls that enable the business rather than block it.