Associate Director, Cybersecurity & IT
$140k - $180kSage Bionetworks
About Us
Sage Bionetworks is a nonprofit biomedical research and technology organization that advances human health through open science and collaborative discovery. We work at the intersection of biomedical science, data, technology, and patient engagement, partnering across academia, industry, philanthropy, and government to build research programs, data resources, and technology that accelerate scientific progress.
Sage brings particular expertise in collaborative research, multimodal biomedical data, responsible data governance, and open source technology. Our Synapse platform serves as a generalist research data repository and is trusted to responsibly steward research data at scale.
The Opportunity
Sage Bionetworks is seeking an Associate Director, Cybersecurity & IT to lead our cybersecurity program and enterprise IT function. This role sets Sage’s cybersecurity strategy and leads the teams responsible for implementing and operating security controls, protecting Sage’s systems and data, identifying and remediating vulnerabilities, responding to security incidents, and providing reliable and secure technology services to our employees.
Sitting at the intersection of Sage’s research mission, technology platforms, and federal security obligations, this leader will bring deep cybersecurity engineering expertise alongside practical IT leadership. We are looking for someone who can strengthen and scale our security capabilities, translate security requirements into effective technical practices and controls, and lead the team responsible for employee technology, access, infrastructure, and IT services.
This role works closely with Sage’s security compliance function. The compliance team is responsible for interpreting applicable security frameworks and requirements, coordinating assessments and audits, and organizing compliance evidence. The cybersecurity team is responsible for implementing and operating security controls, maintaining secure engineering and operational practices, addressing identified risks and vulnerabilities, and producing evidence demonstrating that controls are operating effectively.
This is a chance to make a meaningful impact at the intersection of security, technology, research, and open science, building the capabilities and foundation Sage needs for its next phase of growth.
You'll succeed at Sage if you:
- Have led cybersecurity teams responsible for designing, implementing, and operating security controls in environments subject to rigorous security requirements, including federal security standards.
- Understand frameworks such as FISMA/RMF and NIST well enough to translate security requirements into practical technical controls and engineering priorities.
- Thrive on continuously strengthening and scaling security capabilities as the organization grows, rather than simply maintaining an established program.
- Can explain complex security risks and technical trade-offs in terms a scientist, an engineer, and an executive can each act on, and can maintain high security standards under delivery pressure.
- Bring genuine IT operations experience alongside cybersecurity leadership and are comfortable staying close to infrastructure, identity, endpoint management, security tooling, and day-to-day technology operations.
- Are motivated by mission-driven organizations and know how to build high-impact security and technology capabilities efficiently.
You'll know you're succeeding when:
- Sage’s security controls are implemented effectively, operated consistently, and supported by reliable technical evidence demonstrating that they are functioning as intended.
- Vulnerabilities, security findings, and technical risks are identified, prioritized, and remediated according to defined, risk-based timelines.
- Sage has effective capabilities for detecting, investigating, containing, and recovering from cybersecurity incidents.
- Security practices are integrated into engineering and IT operations, with clear standards, repeatable processes, appropriate automation, and well-defined ownership.
- Product and engineering teams incorporate security requirements early in technology and product decisions, with the cybersecurity team serving as a trusted technical partner.
- Sage’s cybersecurity function is resilient and appropriately staffed, with the skills, tooling, processes, and coverage necessary to protect the organization.
- Sage’s security compliance team receives timely, accurate evidence and technical support needed to demonstrate the effectiveness of Sage’s security controls.
- Employees have a reliable, low-friction technology experience, with timely onboarding and offboarding, appropriate access, responsive IT support, and well-managed software and device lifecycles.
- Leadership and the Board have clear, ongoing visibility into significant cybersecurity risks, incidents, security capabilities, and technology investments.
Note: Please do not upload your resume as your cover letter (required)
Key Responsibilities
Cybersecurity Leadership & Operations
- Set and execute Sage’s cybersecurity strategy and roadmap, establishing priorities, investments, capabilities, and measures of effectiveness based on organizational risk, the threat landscape, and applicable security requirements.
- Lead the design, implementation, operation, and continuous improvement of technical and operational security controls across Sage’s enterprise and technology environments.
- Oversee security operations, including security monitoring, threat detection, vulnerability management, security testing, incident investigation and response, and remediation of identified weaknesses.
- Establish and maintain security engineering and operational practices that reduce risk through secure configuration, automation, monitoring, testing, and repeatable processes.
- Ensure vulnerabilities and security findings are appropriately triaged, assigned, tracked, and remediated according to risk-based timelines.
- Lead Sage’s cybersecurity incident-response capabilities, including preparation, detection, investigation, containment, remediation, recovery, and post-incident improvement.
- Partner with product and engineering teams to identify security risks and incorporate appropriate security controls and practices into Sage’s platforms, infrastructure, and software-development processes.
- Author and maintain the technical security standards, procedures, and documentation that implement Sage’s security policies, along with the operational evidence needed to demonstrate that controls are implemented and operating effectively.
- Partner closely with Sage’s security compliance function to translate applicable framework and control requirements into technical implementations and provide evidence needed for assessments and audits.
- Evaluate and manage security technologies and services, ensuring that Sage’s security tooling provides effective protection, visibility, and operational efficiency.
- Provide technical security expertise in the evaluation, onboarding, and ongoing management of critical technology and cloud vendors.
- Represent Sage in external technical security and IT conversations as appropriate.
IT Operations & Employee Technology
- Lead day-to-day IT operations and employee technology services, ensuring employees have reliable and secure access to the systems, devices, software, and support they need throughout the employee lifecycle.
- Oversee identity and access management, including provisioning and deprovisioning, authentication and authorization controls, privileged access, and periodic access reviews.
- Oversee endpoint and asset management, enterprise SaaS administration and licensing, and associated technology vendor relationships.
- Establish and enforce technical IT and security standards, including device configuration, endpoint protection, identity and access controls, software management, and acceptable technology use.
- Own the technical implementation, maintenance, and testing of business continuity and disaster recovery capabilities for critical IT systems, in partnership with organizational stakeholders responsible for broader continuity planning.
- Oversee help desk operations, establishing service standards and processes that provide employees with reliable, timely technology support.
Cross-Organizational Security Partnership
- Partner with the security compliance team to understand applicable security requirements, implement required controls, remediate technical findings, and produce accurate evidence demonstrating control operation.
- Partner with product and engineering teams to ensure security, identity, access-management, and data-protection requirements are incorporated into platform architecture and the Synapse roadmap.
- Work with organizational risk and governance functions to evaluate technical security risks and implement agreed-upon risk treatments.
- Advise executive leadership and the Board on cybersecurity threats, technical risk exposure, security capabilities, significant incidents, and investments in clear, actionable terms, supported by meaningful security metrics.
People Leadership
- Build, lead, and develop Sage’s cybersecurity and IT teams, maintaining appropriate staffing, technical capabilities, operational coverage, and clear accountability.
- Establish clear ownership for security operations, security engineering, vulnerability management, incident response, identity and access management, and IT operations.
- Develop team members through clear expectations, coaching, professional development, and opportunities for increased responsibility.
- Foster a culture in which security is treated as an engineering and operational discipline characterized by measurable controls, automation, continuous improvement, and shared accountability.
Qualifications
Education
- Bachelor’s degree in computer science, information security, or a related field, or equivalent professional experience.
Experience
- 8+ years of progressive experience in cybersecurity, security engineering, security operations, infrastructure security, or related disciplines , including significant security leadership responsibility.
- Demonstrated experience leading teams responsible for implementing and operating security controls in production technology environments .
- Strong working knowledge of security frameworks and standards such as NIST SP 800-53, NIST Cybersecurity Framework, FISMA/RMF, FedRAMP , or comparable frameworks, with demonstrated ability to translate requirements into effective technical controls.
- Experience with core cybersecurity disciplines such as vulnerability management, security monitoring and detection, incident response, identity and access management, endpoint security, cloud security, and security testing.
- Experience establishing repeatable processes for identifying, prioritizing, tracking, and remediating security vulnerabilities and findings.
- Experience responding to and investigating cybersecurity incidents, including coordinating technical response and driving improvements following incidents.
- Demonstrated ability to communicate cybersecurity risk and technical trade-offs to non-technical executives and a Board .
- Experience partnering effectively with security compliance, risk, audit, or governance teams, including providing technical documentation and evidence demonstrating control implementation and effectiveness.
- Experience leading IT operations at an organization of comparable size and complexity, including employee technology services, identity and access management, endpoint management, and enterprise SaaS administration.
- Experience operating effectively in a lean, mission-driven nonprofit, research, or similarly complex environment.
Nice to Have
- Experience implementing and operating security controls in an environment subject to FISMA, FedRAMP, or other federal security requirements.
- Experience shaping security compliance strategy, including supporting an organization through FISMA/RMF, ATO, or FedRAMP authorization and working with independent assessors or federal authorizing officials.
- Experience securing cloud-native platforms, research data environments, or biomedical data repositories.
- Experience establishing security engineering practices within software-development and cloud-infrastructure teams.
- CISSP, CISM, or other cybersecurity-focused certification; GRC-oriented certifications such as CGRC or CISA are a plus.
Job Functions and Physical Requirements
The following cognitive and physical activities outline the essential functions required for successful job performance. Reasonable accommodations may be provided to enable individuals with disabilities to fulfill these functions.
Physical Demands
- Extended periods of sitting at a desk and using a computer.
- Repeated wrist, hand, and finger movements.
- Requires clear vision for tasks like data analysis, transcribing, computer use, and reading.
- Occasionally lifting or moving objects weighing up to 10 pounds.
Cognitive Demands
- Able to work effectively under deadlines.
- Strong problem-solving and analytical skills.
- Attention to detail and accuracy.
- Flexibility to adapt to changing environments, priorities and multitask.
Additional Functions
- Travel two times per year for on-site events in Seattle, WA.
- Effective verbal and written communication skills.
- Works well in a team and maintains professionalism.
- Follows company policies, procedures, and relevant laws and regulations.
Note: This list is not exhaustive and may be subject to modification as job duties evolve.
Compensation & Total Rewards
Sage Bionetworks implements equitable workplace strategies to ensure fair pay. Actual compensation is determined by market data, specific experience, and internal parity.
- Job Level: Associate Director
- Annual Salary Range: $140,000 - $180,000
- Note: New hires typically receive an offer between the minimum and the midpoint of the range to allow for future growth within the role. Higher offers may be considered for exceptional experience or specific market conditions.
- Comprehensive Benefits: We offer a package competitive with both commercial biotech and nonprofit sectors:
- Health & Wellness: Comprehensive medical, dental, vision, life, AD&D, and long-term disability.
- Future Security: Robust retirement plan and flexible spending accounts (FSA).
- Work-Life Harmony: Paid time off and flexible work arrangements.
- Learn more at: Benefits – Sage Bionetworks
Equal Opportunity & Inclusion
Sage Bionetworks is an Equal Opportunity Employer. We prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
Accommodation Request: If you require a reasonable accommodation during the application or interview process, please contact HR during the scheduling process.
Modern Hiring & Responsible AI
We value your talent and your time. To ensure a fair and inclusive experience, we operate with the following principles:
- Responsible AI in Recruiting: To help us find the best talent, we may utilize AI tools within our recruiting platforms. We use these technologies responsibly to avoid the pitfalls of bias and discrimination. We believe technology should enhance human judgment, not replace it, and we regularly audit our processes to ensure every candidate is evaluated fairly based on their unique skills.
- Work from (Almost) Anywhere: We are a distributed workforce and support remote or hybrid arrangements within the United States.
- Virtual-First Interviews: All interviews are conducted virtually to ensure accessibility and flexibility for all candidates.
About Sage Bionetworks: Science for the Common Good
At Sage Bionetworks, we believe the greatest barriers to medical progress aren't just biological—they are structural. Since 2009, our Seattle-founded nonprofit has been on a mission to tear down the "silos" of traditional science. We don’t just conduct research; we redefine how it’s done through open science, radical collaboration, and ethical data sharing.
When you join Sage, you aren't just taking a job; you’re joining a bold collective of scientists, engineers, governance experts, and visionaries. We empower patients to be partners, not just data points, and we provide the platforms that allow the global scientific community to accelerate life-saving discoveries.
The Sage Way: Our Core Values
We don’t just talk about change; we live it through these five pillars:
- Science Driven: We use data and evidence to ensure our work creates a measurable, positive impact on human health.
- Accountable: We deliver on our promises through a foundation of trust and radical transparency.
- Growth Oriented: We stay curious, seek out the hardest challenges, and constantly aspire to improve ourselves and our field.
- Empathetic + Inclusive: We embrace our differences and build environments where every voice is empowered.
- Radically Collaborative: We believe the best solutions come from teamwork and building diverse, global communities.
$64.6k - $96.9k
...Technology and a Bachelor of Science in Cybersecurity. The SoIT serves more than 1,300... ...In 2017, the SoIT launched the Early IT as a collaborative ecosystem among educational... ...Information Technology seeks to hire an Associate Director for Academic Partners. We are looking for...SuggestedHourly payPermanent employmentFull timeWork experience placementH1bWork at officeImmediate startRemote workFlexible hours$130k - $155k
...of 70+ employees. JOB SUMMARY: C.A.S.E. is seeking a Director of IT who can both lead and execute. This is not a traditional help... ...Director of IT will lead priority work in CRM modernization, cybersecurity, IT governance, SharePoint and Microsoft 365 modernization,...SuggestedPermanent employmentWork at officeLocal areaImmediate startRemote workFlexible hours$115.01k
...has an outstanding opportunity for an Associate Director of Technology Communications to join their... ...associated with UW Medicine IT Services and Innovation Core.The Associate... ...including ITIL, COBIT, cloud infrastructure, cybersecurity, enterprise applications, digital transformation...SuggestedFull timeTemporary workTraineeshipRemote workShift work$140.5k - $204k
...POSITION SUMMARY : Reporting to the Sr. Director of IT Technology, we are seeking a polished, technical Director of IT Architecture... ...security frameworks that protect patient data and mitigate cybersecurity threats. Partner with Cloud team to establish common...SuggestedFull timeFixed term contractFlexible hours$152.7k - $294k
...initiatives in a global organization, aligning diverse teams (security, IT, and business) through influence and relationship-building... ...of information security domains and technologies – including cybersecurity architecture, risk management, identity and access management (...SuggestedSummer holidayLocal areaFlexible hoursShift work$127.79k - $212.99k
...now.We are currently seeking a Delivery Associate Director to join our team in Arlington, Virginia... ...: Supports development of long-term IT strategies, technical roadmaps, and policies... ...services, server administration, cybersecurity, and cloud platforms.Ensures compliance...Full timeTemporary workWork at officeLocal areaRemote workFlexible hours- ...coaching, and managerial oversight to the IT Support Technician staff. Serve as the... ...methodologies when applicable. Partner with the IT Director on hiring, onboarding, performance... .... Additional Information PURPOSE The Associate IT Director serves as the on‑site operational...Work experience placementWork at office
$150k - $215k
...Energy is seeking an experienced technical IT consulting leader who can move fluently... .... How you will contribute As a Director or Senior Director, you will lead work at... ...savings and sequence execution. IT/OT and cybersecurity assessment: evaluate enterprise...Part timeInterim roleWork at officeRemote workFlexible hoursShift work- ...Klaasmeyer Construction Company is looking our next Technical IT Manager to join the Technology team. In this position, you will... ...hands-on with network infrastructure, systems administration, cybersecurity, and automation. If you want a role where your technical skills...Work at officeRemote work
$168k - $231k
...results. Here, you will find more than just a job—you will find purpose and pride. Your role at Baxter As the Associate Director, IT Portfolio Manager, you will serve as the primary technology portfolio leader for Baxter's Supply Chain organization,...Temporary workLocal areaWork visaFlexible hours- ...operating effectiveness across: Logical Access (user provisioning, privileged access, periodic access reviews) Change Management IT Operations (e.g., job scheduling, backups, incident management) Execute ITGC testing on behalf of management, ensuring alignment...
$85.5k - $95k
Associate PR Director We believe great work happens when everyone feels welcome, supported, and empowered to contribute. We strongly encourage... ...growth startups, and category-defining innovators across IT, cybersecurity, data, AI, and other complex technology sectors. As an...Summer workWork at officeRemote workFlexible hours- Northwest Kidney Centers seeks an IT Technical Manager to support the Information Technology... ...and oversight of NKC's infrastructure, cybersecurity, cloud services, and Salesforce... ...including physical characteristics historically associated with race, such as hairstyle or hair...Full timeContract workTemporary workLocal areaWork from homeMonday to FridayFlexible hoursShift work
$185.1k - $277.6k
...data fabric/architecture, advanced cloud and edge platforms, cybersecurity, and full-stack engineering through mission-focused,... ...Cyberspace Systems & Security Subdivision (CS3) is seeking an Associate Director - Cyberspace Innovation to shape the future of cybersecurity...Full timeFor contractorsImmediate startRemote workRelocation packageFlexible hours$184k - $276k
Grant Thornton is seeking a Director, Core IT Integration Delivery Lead to join the team. Approved... ...content, device management, and associated Azure subscription and workload moves... ...architecture review processes, cybersecurity control requirements, and IT service...Contract workInternshipSeasonal workWork at officeLocal areaRemote workFlexible hours3 days per week$133.5k - $190.05k
...About the Role Radiant is seeking a Technical Program Manager, IT & Security, to own visibility and delivery across our IT and... ...commitments and unresolved blockers to the VP of IT and VP of Cybersecurity early enough to act on them, and represent IT leadership in meetings...Full timeFor contractorsSummer workWork at officeImmediate startRemote workFlexible hoursWeekend work- ...Job title: Associate Director of Internal Audit Location: New Haven, CT/ Hybrid Overview The Director of Internal Audit evaluates the adequacy and effectiveness of financial, cybersecurity and operating controls in order to safeguard assets. Manages work...Work from homeHome office
$165.7k - $328.1k
...drive revenue at scale. The Cyber Alliance Relationship Associate Director is responsible for working with EY alliance and sales teams... ...in alliance management, business development, technology, cybersecurity, or professional services. Ability to manage many...Contract workSummer holidayLocal areaFlexible hours- ...Job Title: Associate Customer Success Manager About Trellix Trellix is a global company redefining the future of cybersecurity. The company's comprehensive, open, and native cybersecurity... ..."the big picture" to a CISO or IT Director. ~ You have an enthusiastic and...Immediate startRemote workFlexible hours
- ...Associate Account Manager Keeper is hiring a driven Associate Account Manager to join... ...global headquarters in Chicago. Keeper's cybersecurity software is trusted by millions of people... ...Enterprise organizations, C-level Executives, IT and Cyber Security Executives, an...Contract workTemporary workRemote work
- ...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a IT Associate Director - Full Time to join our team in Noida, Uttar Pradesh (IN-UP), India (IN). General Duties and Responsibilities: In these...Full timeWork at officeRemote workFlexible hours
- ...Description Keeper is hiring a driven Associate Account Manager to join a high producing... ...headquarters in Chicago. Keeper's cybersecurity software is trusted by millions of people... ...organizations, C-level Executives, IT and Cyber Security Executives ~ Unrivaled...Contract workTemporary workRemote work
- ...integrating projections with forecast dataAd hoc report development for senior business and management forumsQuarterly report creation for the IT Governance CommitteeProduce documentation, test results as requested by the Model Validation Committee Policy procedure documentation...Remote workFlexible hours
$130k - $190k
...Energy is seeking its first in-house Senior Manager, Corporate IT to build and lead our internal IT organization. Reporting directly... ..., patch management, and compliance controls. ~ Support cybersecurity initiatives including endpoint protection, phishing awareness,...Work at officeRemote workHome officeFlexible hours- ...Associate Director, Email & GTM Campaigns - Remote Work At BairesDev®, we've been leading the way in technology projects for over 15 years. We... ...level Employment type Full‑time Job function Information Technology Industries: IT Services and IT Consulting #J-18808-Ljbffr...Full timeRemote workWork from homeWorldwide
$100k - $115k
...The Role We're looking for an Associate Director, Paid Social to provide hands-on strategic and tactical leadership across a portfolio of client... ...conversion, retention, and creative testing, and translating it into practical guidance for account teams Partnering with paid...Temporary workWork at officeLocal areaRemote workFlexible hours- ...Experienced professionals will find a full-time salaried Associate Director opportunity focused on business development and sales within the IT services and consulting industry, requiring extensive experience and a master's degree. Key responsibilities: Lead business...Full timeRemote work
- ...Join to apply for the Associate Director role at ISG (Information Services Group) 9 months ago Be among the first 25 applicants Join to apply... ...teams that support governance of large information technology (IT) outsource managed services agreements (MSA) for clients. Responsible...Contract workImmediate startRemote work
$71k - $77k
...time Unionized Position Code Not Applicable Job Description The Associate Director participates in the development and implementation of a... ...transformed Syracuse University into the national research institution it is today. The University’s contemporary commitment to veterans...Full timeWork experience placementSummer workSeasonal workWork at officeLocal areaRemote work- ...role and cell therapy is strongly preferred! The Local Study Associate Director (LSAD) leads Local Study Team(s) (LSTs) at country level to... ...negotiation skills. Good ability to learn and to adapt to work with IT systems. Skills (Desirable): Good analytical skills....Local areaRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Associate Director, Cybersecurity & IT. Be the first to apply!
- associate business manager Remote
- associate creative director copywriter Remote
- associate director clinical research Remote
- associate director clinical data management Remote
- associate clinical manager Remote
- associate director contracts Remote
- remote associate product manager Remote
- associate director biostatistics Remote
- associate strategy director Remote
- associate manager digital marketing Remote




