Senior Director, Information Security and Compliance
Location
United States
Posted
2 days ago
Salary
$264K - $285K / year
Seniority
Mid Level
Job Description
Senior Director, Information Security and Compliance
Beeline Medicines
Title: Senior Director, Information Security & Compliance Location: United States Job Description: About Beeline Medicines: Beeline Medicines is a clinical‑stage biotechnology company focused on developing and delivering category-leading precision therapies to transform the lives of people living with autoimmune and inflammatory diseases. With a portfolio of potential best-in-class and first-in-disease therapeutic candidates that directly target key pathways governing dysregulated immunological and inflammatory responses, the Company is developing medicines that have the opportunity to provide durable, life-changing impact. Led by an established executive team and backed by world-class life science investors, each day Beeline Medicines is determined to bring the scientific rigor and operational excellence to get to what matters for patients – realizing a world where people with immune-mediated diseases can live life fully. Job Summary: The Senior Director, Information Security & Compliance is responsible for building, operating, and continuously improving the company's information security program. This role owns security governance, risk management, regulatory compliance, and security operations across all IT systems and data. The Senior Director establishes the security policy framework, manages relationships with managed security service providers, coordinates external security assessments, and ensures the company maintains a security and compliance posture appropriate for a clinical-stage biopharma preparing for public company obligations. This is a hands-on leadership role. At a company of this size, the Senior Director operates as a solo security practitioner with significant leverage through managed security partners (SentinelOne Vigilance MDR, Huntress ITDR/SIEM, Zscaler ZIA) and external assessment firms. The role reports to the VP of IT and works closely with Quality, Legal, Finance, and external auditors to ensure security controls satisfy SOX, GDPR, GxP, and FDA regulatory requirements. Work Arrangement & Location: Remote - This position is designated as remote; the incumbent will be expected to travel to Beeline Medicines’ offices on a periodic basis to support in-person collaboration, team engagement, and business operations. The frequency and scheduling of such visits will be determined at the company's discretion based on business need. Essential Duties and Responsibilities: - Security Governance & Policy. Own the information security policy framework, including development, maintenance, and periodic review of all security policies, standards, and procedures. Ensure policies align with NIST CSF 2.0, NIST SP 800-53, and applicable regulatory requirements (SOX, GDPR, GxP). Present the security posture and risk landscape to IT leadership and executive stakeholders. - Risk Management & Vendor Security. Lead IT risk management activities, including risk identification, assessment, treatment planning, and risk register maintenance. Conduct and coordinate vendor security risk assessments for third-party service providers. Support the company's broader enterprise risk management process with IT-specific risk inputs. - Compliance & External Assessments. Own IT General Controls (ITGCs) for SOX compliance readiness, including access controls, change management controls, computer operations, and audit evidence preparation. Coordinate with external SOX auditors, providing documentation, walkthroughs, and remediation of findings. Manage relationships with external firms performing penetration testing, NIST controls mapping, and security control assessments - Security Operations & MSSP Management. Manage the company's managed security service provider ecosystem, including SentinelOne Vigilance MDR (endpoint detection and response), Huntress (identity threat detection, SIEM), and Zscaler ZIA (network security). Define alert escalation procedures, review detection efficacy, and ensure coordinated incident response across all providers. - Incident Response. Own the security incident response program, including the incident response plan, tabletop exercises, breach notification procedures, and post-incident reviews. Serve as the primary technical incident coordinator, working with managed security providers for detection and containment and with Legal and the external DPO for regulatory notification obligations. - Identity & Access Governance. Design and enforce identity and access management controls in Microsoft Entra ID, including Conditional Access policies, privileged access governance, access reviews, and role-based access control. Ensure access controls satisfy SOX ITGC requirements, FDA 21 CFR Part 11 electronic access provisions, and GDPR data access minimization principles. - Security Awareness & Training. Own security awareness and training program execution in coordination with KnowBe4, including phishing simulation campaigns, security awareness training content, completion tracking, and remedial training for failed simulations. Maintain training records as audit evidence for SOX and GxP compliance. - Perform other duties and responsibilities as assigned Qualifications: - Education: Bachelor's degree in Information Security, Computer Science, Information Technology, or a related discipline; equivalent professional experience accepted. - 12+ years of progressive information security experience with at least 5 years in a security leadership role (Manager, Director, or equivalent) preferred. - Demonstrated experience building or significantly maturing an information security program, including policy development, risk management, and compliance framework implementation. - Experience with security frameworks: NIST CSF, NIST SP 800-53, ISO 27001, or equivalent. - Direct experience with SOX IT General Controls — either implementing ITGCs for IPO readiness or supporting ongoing SOX compliance at a public company. - Strong working knowledge of Microsoft 365 security controls, including Entra ID, Conditional Access, Defender, and Purview. - Demonstrated experience building or significantly maturing an information security program, including policy development, risk management, and compliance framework implementation. - Experience managing managed security service providers (MDR, MSSP, or similar) and coordinating external security assessments (penetration testing, controls testing, risk assessments). - Demonstrated experience building or significantly maturing an information security program, including policy development, risk management, and compliance framework implementation - Independent judgment and self-direction — this role operates as a solo security practitioner at a small company and must prioritize effectively without day-to-day supervision. - Strong written and verbal communication with the ability to translate security risks into business terms for executive and non-technical audiences. Salary Range: The expected salary range for this position varies by location and will be communicated based on the country or region in which the selected candidate is hired. Actual pay will be determined based on experience, qualifications, location, and other job-related factors permitted by applicable local law. A discretionary annual bonus and long-term incentive award (e.g., equity) may be available based on individual and Company performance. Salary Range $264,000 - $285,000 USD Benefits: We offer a comprehensive benefits package tailored to the country and region in which you are hired, in compliance with local laws and practices. Benefits may include, but are not limited to: - Competitive health and wellness coverage (structure and premiums vary by country) - Paid time off, public holidays, and additional leave entitlements in accordance with local requirements - Flexible work arrangements / hybrid schedule Benefits vary by location and are subject to eligibility requirements, local regulations, and plan terms. Specific benefit details applicable to your country or region will be provided during the offer process. Equal Employment Opportunity: Beeline Medicines is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, age, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. Reasonable Accommodation: If you require a reasonable accommodation to participate in the application or interview process. Privacy Upon submission of this form I understand that Beeline Medicines is based in the United States and personal data submitted in the form will be transferred and accessed in the U.S., Information about Beeline Medicines privacy practices can be found at Privacy Policy - Beeline Medicines.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Title: Security Engineer Location: Remote Department: Palo (Sales Operations) Full Time Experienced Job Description: Secur-Serv is a leading managed services provider of IT, print, and hardware services, with a security focus at the core of every service. Secur-Serv provides nationwide, on-site service to businesses of every size, focusing on the financial, manufacturing, transportation, and healthcare industries. Why Secur-Serv? Join Secur-Serv because we are committed to professional and personal growth, working with employees to develop a defined career path and helping them achieve their career goals with internal and external training. We empower our employees to innovate and be a part of solutions that improve processes, systems, and transformation. We recognize and provide an environment where each and every employee can make an impact.. - Explore new training opportunities through our LinkedIn Learning platform and partners to develop your skills and career. - Free wellness and mental health resources via our Employee Assistance Program (EAP) available which is all employees for help with life's stresses and up to three visits with a professional. This is a remote, work-from-home position, and all qualified candidates are encouraged to apply in the continental U.S., with the exception of candidates from California, Maryland, Colorado, Washington, New York, Illinois, or New Jersey. POSITION SUMMARY The Security Engineer designs, implements, and maintains secure network access solutions for our customer's (Palo Alto) enterprise environment. Will work closely with network, cloud, and IT operations teams to optimize performance, troubleshoot issues, and ensure compliance with organizational security standards. ESSENTIAL RESPONSIBILITIES - Follow all Secur-Serv requirements, policies, procedures, and management directions - Migrate customers from legacy firewall technologies to Palo Alto Networks platforms - Build custom security policies and application signatures, configured for our client’s needs - Take every opportunity to maintain proficiency and increase the level of knowledge on Palo Alto Networks SASE products, software, and services - Provide after-hours and weekend on-call support as needed to support maintenance activities - Analyze logs and events from the solution to perform initial troubleshooting and issue identification - Work with our Technical Assistance Center to troubleshoot and diagnose support cases - Maintain the Company's solution and provide mentorship on code upgrades and best practices - Ensure client needs are met and deliverables produced on time according to specified project deliverables and scope REQUIREMENTS - Bachelor’s degree in Computer Science, Electrical Engineering, Computer Engineering or a related technical field or equivalent background or military experience - Minimum 4 years’ experience in professional services - PCNSE, CCNA, CCNP, and/or CCIE certification - Project leadership experience - ability to drive organizations and resources to complete required tasks in service of end goals - Detailed technical experience in the installation, configuration, and operation of high-end firewall appliances - Strong understanding of LAN and WAN networking protocols and technologies, including switching, routing, firewalls and security solutions - Strong TCP/IP networking skills - Strong dynamic routing skills (BGP, OSPF, etc) - Experience working with Remote Access VPN solutions, IPSEC, PKI & SSL, TCP/IP, Authentication Protocols (LDAP, RADIUS, SAML, etc.) - Experience working with URL filtering - Experience working with Proxy and SSL Decryption - Experience working with Windows and MAC OS including (debugging, editing Windows Registries, Plist, etc.) - Experience with one or more of these vendors: Palo Alto Networks NGFW, Cisco, Checkpoint, Juniper (Netscreen), Fortinet products, Symantec/ Blue Coat, Zscaler - Good troubleshooting skills and ability to use tools like tcpdump & Wireshark - Application Delivery expertise – L7 SLB / Global SLB / Traditional Link LB - Application Performance Monitoring expertise – Response time metrics, Application identification - Packet capture analysis / fault isolation and remediation - In-depth knowledge and deployment experience of SD-WAN and Remote Access technologies - Network Security expertise (IPS/IDS, ZBFW, NGFW) - In-depth IP Routing protocol expertise (BGP, OSPF, EIGRP) - Implementation of Legacy WAN solutions (MPLS, Leased Line, Frame Relay, Satellite, Internet VPN, ECMP, DMVPN) - Global-scale network design - Demonstrable Virtualization experience (VMware/Microsoft/Citrix/Linux KVM) - Ability to work in a cross-functional environment which involves coordination with different teams such as Sales/Pre Sales/Product Management/Engineering - Good written and verbal communication skills with confirmed ability to communicate with senior leaders and technical peers - Desire to learn on your feet and thrive on the bleeding edge of networking. PREFERRED SKILLS/EXPERIENCE - Experience with Prisma Access - Experience with public clouds like AWS/GCP/Azure - Scripting and automation development experience PHYSICAL/MENTAL REQUIREMENTS - Sit Frequently at a desk - Frequent fine hand and finger movements (keyboard, writing, mouse movement) - Continual close visual acuity for reading - Hearing and Speaking for communication within and outside of company. - May be required to lift/push/pull up to 10 pounds for set up/movement of office equipment, - Mental Requirements – must be able to consistently: - Learn new tasks, - Remember Processes, - Maintain focus, - Complete tasks independently - Make timely decisions in the context of a workflow, - Ability to communicate effectively, - Able to adhere to process protocol in a timely manner WE ARE AN EQUAL OPPORTUNITY EMPLOYER. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Security Engineer
Lambda LabsLambda Labs is a forward-thinking technology company specializing in artificial intelligence (AI) and machine learning (ML) solutions. The company is committed
Title: Security Engineer Location: San Francisco Office (Fremont St); Bellevue, WA; San Jose Office (First St) Department: Data Center Business Job Description: Lambda, The Superintelligence Cloud, is a leader in AI cloud infrastructure serving tens of thousands of customers. Our customers range from AI researchers to enterprises and hyperscalers. Lambda's mission is to make compute as ubiquitous as electricity and give everyone the power of superintelligence. One person, one GPU. If you'd like to build the world's best AI cloud, join us. *Note: This position requires presence in our San Francisco/San Jose/Bellevue office location 4 days per week; Lambda’s designated work from home day is currently Tuesday. About the Role Lambda Security protects some of the world's most valuable digital assets: training data, model weights representing immense computational investments, and the sensitive inputs required to leverage best-of-breed AI models. We're responsible for securing every byte that powers breakthrough artificial intelligence. As a Security Engineer at Lambda, you'll touch many areas across the security program such as building detections, hardening infrastructure, reviewing designs, automating toil, and responding to incidents. Reporting to the Head of Security and partnering closely with Product Engineering, Data Center Operations and Engineering, IT, and embedded Technical Program Managers, your work shapes the security posture customers rely on. Security at Lambda directly enables customer trust and unlocks enterprise revenue. Our customers run billion-dollar training jobs and irreplaceable model weights on our infrastructure; our job is to make Lambda the safest place to build with AI. Over the next 12-18 months, you'll help deliver our 2026 security roadmap, expand detection coverage for AI-specific threats, help mature our incident response program, and ship security automation that other engineering teams adopt voluntarily. You'll also have direct access to LLMs hosted on Lambda's own infrastructure to push security operations beyond what's possible elsewhere. Security is a broad field, and we don't expect you to be an expert in everything our team does, but we do expect you to learn quickly, ship across domains, and support the specialists around you. If you enjoy moving between detection, architecture, and platform work and want to build security alongside the engineers you're protecting rather than from the outside then we'd love to talk. We value diverse backgrounds, experiences, and skills, and we are excited to hear from candidates who can bring unique perspectives to our team. If you do not exactly meet this description but believe you may be a good fit, please still apply and help us understand your readiness for this role. Your application is not a waste of our time. What You'll Do - Build and Tune Detections: Develop and refine detection content across our SIEM and EDR to catch threats targeting customer data, model weights, and infrastructure. - Respond to Incidents: Participate in on-call, lead investigations end-to-end, and turn each incident into automation, playbooks, or controls that prevent the next one. - Harden Systems Directly: Remediate vulnerabilities and security findings in production, partnering with engineering teams when fixes cross team boundaries. - Review Architectures and Code: Provide actionable security feedback on high-level designs and individual changes, and turn recurring review patterns into reusable standards. - Build Security Tooling: Ship Python or Go services that automate evidence collection, vulnerability triage, and other toil, using Lambda's hosted LLMs where they meaningfully accelerate the work. - Partner Across Engineering: Work with Product Engineering, Data Center Operations and Engineering, IT, and Legal to land security improvements at the moments they're cheapest to adopt. - Balance Strategic and Tactical: Recognize when to invest in a long-term fix versus when "good enough" is exactly that, and bias toward measurable forward progress. What We Think a Candidate Needs to Demonstrate to Succeed - 5+ years of demonstrated security engineering experience, either directly as a security engineer or as an engineer driving security outcomes. We also welcome equivalent backgrounds: significant formal security training paired with strong engineering experience. - A track record of working across security domains; for example, shipping detection work in one role and architecture, platform, or vulnerability management work in another. We don't expect mastery of every domain; we do expect demonstrated breadth and eagerness to learn. - Thrives in high-speed, high-ambiguity startup environments where priorities shift regularly and structure must be built while executing. - Strong hands-on Linux experience that showcases your ability to protect both our applications and the cloud we build underneath them. - Comfortable solving problems in Python, Go, or a similar language, with the discipline to ship production-grade tooling rather than only one-off scripts. - Excellent collaboration with technical teams both with and without authority (we're all on the same team!). Nice to Have - You've led or developed a meaningful component of a security program (detection & response, security architecture, platform/tooling, vulnerability management, GRC operations, etc.). - Experience driving or providing significant evidence for compliance audits such as SOC 2, ISO 27001, PCI-DSS, HIPAA/HITECH, or FedRAMP. - Significant experience operating large-scale production services (e.g., SRE across thousands of hosts) or with virtualization at scale (KVM, Hyper-V, Xen). - You've built or deployed critical security infrastructure such as SIEM, SOAR, EDR, IDS/IPS, or canary/honeypot systems. - Experience with AI/ML infrastructure security, model security, or protecting high-value computational workloads. - Enthusiasm about leveraging direct access to state-of-the-art LLMs to push security operations beyond the status quo, including through automated triage, intelligent alert correlation, AI-assisted code review. Salary Range Information The annual salary range for this position has been set based on market data and other factors. However, a salary higher or lower than this range may be appropriate for a candidate whose qualifications differ meaningfully from those listed in the job description. Compensation - San Francisco / San Jose$296K – $395K - Bellevue$266K – $356K
Senior Metrics Consultant
MetLifeMetLife is a leading insurance and financial services company based in New York, New York. The company and its affiliates specialize in employee benefits and li
Description and Requirements The Team You Will Join The Metrics & Reporting team is responsible for producing operational and leadership reporting primarily for the Regional Business Service & Implementation, Operations, Billing and Remittance teams. Acting as a trusted partner, the Metrics & Reporting team translates complex data from many different systems into clear, actionable insights. This team plays a critical part in ensuring leadership and operational teams have reliable, actionable insights while continuously improving how reporting is delivered. The Opportunity The Senior Metrics Consultant is an experienced data and reporting professional responsible for leading the ownership, optimization, and ongoing enhancement of enterprise reporting solutions. This role supports operational performance, leadership decision-making, and continuous improvement by delivering accurate, scalable, and business-aligned reporting through a combination of strong technical expertise and deep understanding of stakeholder needs. Success in this role requires strong technical skills with Alteryx and Power BI along with advanced problem-solving and quantitative/analytical thinking skills. This role is responsible for optimizing and automating existing report processes in addition to developing new reporting based on stakeholder requirements. This role supports operational performance, leadership decision making, and continuous improvement by delivering accurate, scalable, and business aligned reporting through a combination of strong technical expertise and deep understanding of stakeholder needs. Key Responsibilities - Design, build, and maintain complex reports, scorecards, and dashboards using Power BI and Alteryx, presenting data in clear, accessible formats for business partners and executive audiences. - Compile, track, and analyze operational and transactional data including trend analysis, variance identification, and actual vs. plan comparisons. Translate findings into actionable observations and recommendations. - Develop and maintain Alteryx workflows to automate complex data analysis, review existing reporting procedures, and implement process improvements that drive efficiency. - Manage and contribute to projects spanning short- and long-term business planning, recommend metrics to track, and develop methods for how data is captured, stored, and reported. - Own an assigned report portfolio, provide backup support to peers, and partner with management to deliver executive summaries and reporting that inform key business decisions. Required Qualifications - 5+ years of related work experience creating and automating complex Alteryx reports, dashboards, and workflows along with Microsoft Excel utilizing x-lookup, v-lookup, linked tables, power query, pivot tables and Visual Basic. - 2+ years of experience creating Power BI Dashboards to automate business reports and processes. - Excellent communication skills (verbal and written) when interfacing with Senior Leaders and Executives. - Ability to work collaboratively to improve processes using strong problem solving and analytical thinking skills. - High school Diploma or GED equivalent. Preferred Qualifications: - Core or Advanced certification in Alteryx. - Understanding of operations, billing metrics and processes including forecasting cand goal setting. - College degree or higher education. At MetLife, we're leading the global transformation of an industry we've long defined. United in purpose, diverse in perspective, we're dedicated to make a difference in the lives of our customers. The expected salary range for this position is 71,100-119,500. This role may also be eligible for annual short-term incentive compensation. All incentives and benefits are subject to the applicable plan terms. Benefits We Offer Our U.S. benefits address holistic well-being with programs for physical and mental health, financial wellness, and support for families. We offer a comprehensive health plan that includes medical/prescription drug and vision, dental insurance, and no-cost short- and long-term disability. We also provide company-paid life insurance and legal services, a retirement pension funded entirely by MetLife and 401(k) with employer matching, group discounts on voluntary insurance products including auto and home, pet, critical illness, hospital indemnity, and accident insurance, as well as Employee Assistance Program (EAP) and digital mental health programs, parental leave, paid time off, paid holidays, volunteer time off, tuition assistance and much more! About MetLife Recognized on Fortune magazine's list of the "World's Most Admired Companies", Fortune World's 25 Best Workplaces™, as well as the Fortune 100 Best Companies to Work For®, MetLife, through its subsidiaries and affiliates, is one of the world's leading financial services companies; providing insurance, annuities, employee benefits and asset management to individual and institutional customers. With operations in more than 40 markets, we hold leading positions in the United States, Latin America, Asia, Europe, and the Middle East. Our purpose is simple - to help our colleagues, customers, communities, and the world at large create a more confident future. United by purpose and guided by our core values - Win Together, Do the Right Thing, Deliver Impact Over Activity, and Think Ahead - we're inspired to transform the next century in financial services. At MetLife, it's #AllTogetherPossible . Join us! MetLife is an Equal Opportunity Employer. All employment decisions are made without regards to race, color, national origin, religion, creed, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, marital or domestic/civil partnership status, genetic information, citizenship status (although applicants and employees must be legally authorized to work in the United States), uniformed service member or veteran status, or any other characteristic protected by applicable federal, state, or local law ("protected characteristics"). If you need an accommodation due to a disability, please email us at accommodations@metlife.com. This information will be held in confidence and used only to determine an appropriate accommodation for the application process. MetLife maintains a drug-free workplace. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liabilities. 71,100-119,500
Signaling Security Specialist
Deutsche Telekom IT SolutionsAs Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.
Role Description For an international team, we are looking for a signaling security & fraud specialist with high expertise in telecommunication protocols and networks, especially SS7/SMS, Diameter, SIP and 5G HTTP2, GTP and Roaming technologies and services. The tasks involve: - Conception of security and fraud anomaly monitoring - Detection, analysis and mitigation of attacks - Conception and implementing countermeasures - Coordination with stakeholders Tasks include: - Configuration of new detection filters - Analysing of alerts - Discuss findings with stakeholders and implement countermeasures - Coordinate the evaluation and mitigation process with the responsible stakeholders - Development of security policy focusing on signaling threats - Evaluation of new telco signaling and signaling based fraud scenarios Qualifications - Very good written and spoken English (C1), good German (min. B2) skills are desirable - Expertise in telecommunication signaling protocols (SS7, Diameter, GTP, 5G HTTP2, SIP) - Knowledge in operational mobile and roaming services - Experience in anomaly detection and fraud management solutions - Security expertise in telecommunication networks - Strong analytical and problem-solving skills - High attention to detail to identify potential vulnerabilities and risks - Ability to work in an environment with high confidentiality and sensitivity - Willingness to pass selected privacy, security and risk management training and be committed to compliance with content Requirements - Experience in telecommunication network security - Experience with signaling firewalls, telco protocol security monitoring systems - Experience in network/carrier fraud management - In-depth knowledge of fraud types, methods and techniques Benefits - Supportive colleagues locally and internationally - Knowledge expansion through trainings, professional certifications - Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation.

