Director of Security -Remote
Schenectady, Schenectady County, New York, 12301, USA
Listed on 2026-06-12
-
IT/Tech
Cybersecurity
At One Study Team (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes. Our cloud-based platform, Study Team, brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively. Study Team is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries.
Join us in our mission to advance clinical research and improve patient care.
One mission. One team. That’s One Study Team .
The Director of Security leads enterprise security strategy and execution across governance, risk, compliance, and security engineering. This role manages the GRC and Security Engineering teams, partners with technology and business leaders, and ensures the design and operation of secure systems and processes across the organization.
The Director is accountable for program maturity, audit readiness, and continual improvement. The scope includes third party risk, vendor assessment and qualification, security architecture oversight, AI related security assessments and guidance, incident response leadership, and budget ownership for security programs.
This is a hands‑on, technical leadership role with high autonomy that blends strategic program leadership with practical execution. The Director will develop roadmaps and metrics, allocate resources, and ensure alignment with business priorities and regulatory obligations.
What You’ll Be Working On:- Lead and manage the GRC and Security Engineering teams, including strategy, objectives, staffing, coaching, and performance management.
- Own governance, risk, and compliance programs. Maintain ISO 27001 and related controls. Drive audit readiness for HIPAA and other frameworks. Coordinate policy lifecycle management and control testing.
- Run vendor assessment and qualification program. Oversee third party risk management, due diligence, contractual security requirements, and continuous monitoring.
- Provide AI related security assessments and guidance. Establish acceptable use guardrails for AI, assess model and data risks, and advise on controls for AI enabled solutions.
- Oversee security architecture for cloud environments and enterprise platforms. Partner with engineering on secure design for AWS, Azure, identity, network, and data protection.
- Direct security engineering operations. Manage EDR and threat detection with Crowd Strike, SIEM operations, CSPM posture management, vulnerability management, and SOAR automation.
- Lead incident response readiness and execution. Run tabletop exercises, coordinate investigations, and deliver root cause and lessons learned.
- Own and manage security budgets, multiyear planning, vendor contracts, and cost optimization while meeting control objectives.
- Report program status and risk posture to executives and the board. Define and track KPIs and KRIs. Communicate clearly with technical and non technical stakeholders.
- Establish and enforce secure software development practices and SDLC controls with engineering leadership.
- Maintain a current security roadmap and maturity plan aligned to business priorities.
- Oversee metrics, dashboards, and reporting for program performance and risk reduction.
- Coordinate with Legal, Privacy, and Compliance on regulatory obligations and customer security assessments.
- Champion security awareness training and culture, sponsor targeted training for engineering and high risk roles.
- Evaluate, select, and manage strategic security vendors and platforms, drive successful implementations and integrations.
- Represent security in customer meetings and due diligence, provide credible technical and compliance answers.
- 15+ years of progressive experience in information security or related fields.
- 10+ years of management experience leading security teams, including people leadership and program ownership.
- Bachelor's degree in Computer Science, Engineering, Information Security, or related field.
- Relevant certifications strongly preferred. Examples include CISSP…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).