Job Summary:
As the IT Security and Compliance Director, you will play a crucial role in ensuring the company’s security, regulatory, and compliance standards are met. In collaboration with various stakeholders, you will drive awareness of best security practices and enhance adherence to GDPR, CSL, and other data protection regulations. Your responsibilities will span across security operations, investigations, and compliance resolution, while overseeing business continuity, disaster recovery, crisis management, and employee training on security and compliance.
Responsibilities:
- Security Management
- Evaluate current security practices and strike the right balance between safeguarding data and supporting employee productivity.
- Oversee the outsourced Security Operations Center (SOC) to maintain proactive and continuous monitoring of endpoints, networks, and applications.
- Ensure the security of cloud platforms (e.g., AWS, Azure, GCP), applications and manage hybrid environments to maintain compliance across infrastructures.
- Conduct annual security assessments, review findings, and implement necessary actions.
- Develop, update, and train staff on Standard Operating Procedures (SOPs) related to security.
- Define and manage critical business processes, ensuring thorough recovery testing and resilience planning.
- Focus on risk-based reduction efforts to prioritize areas of greatest need.
- Select, administer and monitor security training for employees.
- Implement and oversee incident response plans to ensure timely and effective handling of security breaches.
- Represent the IT department to senior management, providing updates on key initiatives.
- Stay ahead of emerging threats, technologies, and security best practices. Compliance Oversight:
- Maintain an up-to-date inventory of company compliance requirements ensuring continuous alignment with international and industry-specific standards.
- Lead the creation, updating, and dissemination of IT compliance policies integrating legal and regulatory changes.
- Foster a culture of compliance and security awareness across the organization through regular communications and training.
- Coordinate preparations for audits and ensure resolution of any compliance-related issues.
- Develop and maintain a comprehensive compliance calendar to track and manage key compliance activities and deadlines.
- Work closely with legal and other teams to understand compliance and data requirements, assessing the impact on processes and systems.
- Oversee technology data retention policies and ensure standards are consistently applied.
- Keep up to date on changing data privacy laws, assess the impact and communicate and implement solutions.
- Evaluate new systems and vendors to determine their potential impact on security and compliance frameworks, ensuring proper vetting and alignment with company standards.
- Develop and track key security and compliance performance indicators (KPIs) to measure progress and effectiveness.
Required Skills
- 15+ years of IT security experience, with at least 5 years in a leadership role.
- Expertise in compliance, GDPR, data privacy and security training.
- Expertise in incident management, disaster recovery and crises management.
- Excellent communication, leadership, and problem-solving skills with the ability to simply and in non technical terms communicate with senior leadership and other stakeholders.
- Ability to manage multiple projects in a dynamic environment.
- Experience in a small emerging biopharma environment implementing security practices and policies as relevant to the stage of development we are in.
- Experience with selecting, implementing and management a Security Operations Center (SOC).
Slipstream IT is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation or identity, national origin, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws. Slipstream IT makes hiring decisions based solely on qualifications, merit, and business needs at the time.
This job description may not be inclusive of all assigned duties, responsibilities, or aspects of the job described, and may be amended at anytime at the sole discretion of the Employer.