Information Security Lead
$45kAlloy Therapeutics
Role Location: Remote
The Company
We are Alloy Therapeutics —a biotechnology ecosystem company empowering the global scientific community to make better medicines together. Through a community of partners, we democratize access to pre-competitive tools, technologies, services, and company creation capabilities that are foundational for discovering and developing therapeutic biologics. The company facilitates affordable, non-exclusive access to the entire drug discovery community from academic scientists, small and medium biotech, to the largest biopharma. At Alloy, we believe our industry should compete on getting the best drugs to patients as quickly as possible, not exclusive access to the best platforms. As a reflection of our relentless commitment to the scientific community, we reinvest 100% of our revenue in innovation and access to innovation. MAY THE BEST DRUG WIN.
Alloy has evolved from a startup into a global biotechnology infrastructure company operating 11 divisions across 5 research sites in 4 countries on 3 continents. Our model - Integrated Independence - combines centralized capabilities with entrepreneurial operating divisions. Successful members thrive in our shared culture of accountability, deliberate trust, and open communication. As a team we aspire to work together to exceed expectations and collectively contribute across the global organization to always maintain our nimble, startup culture.
At Alloy, we have an ethos of “Mentorship-By-Apprenticeship” in all of our positions. We strive to have workers in the office when needed to interact organically and face-to-face. Of course, as a lab-based operation, our cells and animals grow 7 days a week, 365 days per year. We respect and value our colleagues for their hard work that requires them to be in the lab every day. We ask our people who have more flexible accommodations, like this position, to appreciate their colleagues who have less flexibility. We are all one team!
The Team
The IT function at Alloy Therapeutics sits at the nerve center of our bold scientific mission to enable the researchers, scientists, and AI experts to set the standard for what's possible in collaborating to discover and develop new medicine. Proprietary new medicine comes from proprietary insights and proprietary data that are closely guarded and protected by our partners as their core economic differentiator to make their business work. As such, protecting and federating these data is one of the most critical aspects of our business.
Over the last 10 years, Alloy has reinvented the paradigm of the biotech “Contract Research Organization” (CRO) by creating a true biotech infrastructure company we call a “Product Development Organization” (PDO). As the world’s first PDO, Alloy is defining what it means to work closely and longitudinally with our partners to discover and develop new therapeutics for their drug pipeline. This is a true partnership model with shared risk and economics requiring trust and data protection throughout the long life of the partnership. We operate with the pace and ambition of a startup and the rigor of a company where technology failures have real consequences. Data and Information Security is a core enabler of the trust that lets us work with the world's leading pharmaceutical partners, handle sensitive research data responsibly, and protect the proprietary science that defines our competitive advantage. We are building our security program in earnest and need someone who can do both: design and implement technical controls from the ground up, and write the governance frameworks and policies that make those controls auditable and defensible.The Role
As Information Security Lead, you will own Alloy's security program in its entirety — building on a strong foundation and shaping our IT team’s motto of responsible innovation. This is a rare role that offers breadth of scope: you will be equally responsible for hands-on technical work (configuring IAM controls, participating in system architecture, managing endpoint security and patching, running vulnerability management) and for the governance work that sits alongside it (writing policies, maintaining compliance documentation, and satisfying the increasingly rigorous security requirements of our enterprise partners). You will be the primary security practitioner at Alloy — the person who gets called when something goes wrong and the person who built the system that catches it before it does.
This role will report to the Director, Information Technology and will work in close partnership with the broader IT team and the AI and research Divisions in a fast-moving, AI-forward environment.Key Responsibilities
- Incident Response & Business Continuity : You refine and own Alloy's Incident Response Plan and Business Continuity / Disaster Recovery plan as live operational playbooks that you maintain, test annually, and can execute under pressure. You establish clear partner-notification SLAs and ensure our detection and response tooling is wired to the right workflows.
- Vulnerability & Patch Management : You run a structured vulnerability management program with defined remediation SLAs (including tight timelines for critical-severity findings), integrate CVE and CSIRT advisory feeds into a regular review cadence, and work directly with IT to ensure patch coverage across endpoints and internet-exposed services. You also coordinate annual penetration testing with an external firm and track findings through to closure.
- Policy, Governance & Compliance : You maintain Alloy's information security policy landscape by maintaining and continuously improving a coherent, indexed Information Security Program that can survive an external audit. You own our SOC 2 type designations, manage the evidence collection and audit readiness work, and ensure we can satisfy the increasingly detailed security questionnaires and contractual requirements that come with working alongside major pharmaceutical partners.
- Identity, Access & Endpoint Hardening : You design and implement IAM controls that enforce least-privilege across cloud, SaaS, and on-prem systems including standardizing MFA (including FIDO2/hardware key deployment for high-assurance scenarios), building access registries, automating provisioning and de-provisioning, and closing gaps in privilege management. You also own endpoint security configuration across our fleet, ensuring encryption, patching cadence, and EDR coverage are consistently enforced.
- Data Protection & Security Posture : You own Alloy’s approach to protecting and ensuring proper federation of proprietary scientific data at massive scale across its full lifecycle. You are responsible for classifying and safeguarding multi-petabyte research, model-training, and partner-derived datasets. You define handling and access requirements and ensure controls are in place wherever that data lives. You treat data protection as a first-class engineering discipline: encryption in transit and at rest, key management, exfiltration detection, and tamper-evident controls operating across high-throughput, large-scale data pipelines. You ensure our backup and recovery capabilities meet continue to meet the evolving partner requirements (including immutable, geo-redundant copies of critical data), maintain a data retention and deletion process that can be demonstrated to external auditors, and own data residency and sovereignty controls for high-assurance and government-aligned projects.
- Detection, Monitoring & Threat Response : You maintain visibility across Alloy’s environment through logging, alerting, and monitoring tooling, and you own incident classification and response when things go wrong. You design detection and response plans against advanced, persistent, and nation-state-level threat actors by integrating threat intelligence, building anomaly detection across large-scale data movement, and maintaining rapid containment playbooks for sophisticated intrusion attempts. You assess whether our current tooling provides sufficient coverage or whether additional capabilities are warranted.
- AI & Emerging Technology Security : You work closely with Alloy's AI teams to ensure our AI-forward environment is secure, including assessing data flows through AI tooling, managing shadow-AI risk, and building controls that let the organization adopt new capabilities without exposing partner or research data. You help ensure our AI usage policies are nimble and operationalized, not just documented.
- Application & SaaS Security : You serve as the security voice in software and tooling decisions across the organization as you evaluate new SaaS applications, advise business teams on secure configuration and data-handling practices, manage vendor security reviews, and ensure that the software landscape Alloy depends on doesn't introduce unacceptable risk. You maintain an application inventory with associated risk ratings and own the process for assessing and onboarding new tools.
- Sovereign & High-Assurance Program Security : You design and operate the elevated controls required for sovereign and government-aligned engagements carrying national-security sensitivity with strict data residency and segregation, compartmentalized access, enhanced personnel and supply-chain assurance, and defenses calibrated to nation-state threat actors. You serve as the security liaison for government and sovereign partners and ensure Alloy can meet the heightened requirements that come with sovereign-level work.
Qualifications
- Significant breadth across both technical security work and governance. You are equally comfortable architecting a backup solution or configuring IAM policies as you are writing an incident response plan or preparing evidence for an audit
- Hands-on experience with cloud security across Google Workspace and AWS (or GCP/Azure equivalent), including IAM design, cloud storage security, and logging and monitoring configuration
- Experience securing proprietary scientific or research data at massive scale. Segmenting and federating multi-petabyte environments, high-throughput research and model-training pipelines, and the data-protection engineering that protecting irreplaceable datasets demands
- Experience defending against advanced and nation-state-level threat actors, and supporting sovereign, government, or other high-assurance programs with elevated security and data-residency requirements
- Experience implementing MFA programs including FIDO2/hardware key standards (e.g., YubiKey) and SSO/SCIM provisioning across a SaaS environment
- Demonstrated experience with backup architecture design, including immutable and geo-redundant backup solutions, and with running and documenting restore tests
- Familiarity with compliance frameworks including SOC 2 Type 2 and/or ISO 27001 — ideally you have worked through an audit or certification process and understand what evidence-ready looks like in practice
- Experience writing security policies and documentation that can withstand external scrutiny (AUPs, IRPs, BCP/DR plans, vulnerability management programs) as living operational documents
- Comfortable operating as the primary security practitioner in a lean environment where you are self-directed, able to prioritize across competing demands, and effective at coordinating with Legal, Finance, and external vendors without bureaucratic supporting team
- Biotech, life sciences, or regulated industry experience strongly preferred; experience with pharmaceutical partner security requirements a plus
Taking Care of Our People
We support the individuality of what people need to do outside of work to empower them to do their best at work. While you focus on making better medicine together , we focus on programs and benefits that support a diverse and growing team. Whether you’re single, in a growing family, or nearing retirement, Alloy offers a variety of comprehensive and competitive benefits starting from day one.
Compensation
- Competitive base and equity compensation commensurate with level of experience and independence
- 401(k) company match
Health & Family
- Generous personal and family medical, dental and vision benefits with 100% of premiums and deductibles covered
- Company-paid disability (STD, LTD) and life insurance
Paid parental leave
- Family planning support up to $45,000 (e.g., IVF/PGT, adoption, surrogacy, egg retrieval)
Unique Perks
- Unlimited PTO (paid time off) and flexible schedules
- Annual stipend for continuing education with commitment to your career through individualized professional development plan
- Wellness and Extensive Employee Assistance Program (EAP) including resources for mental wellness
Pay Transparency
At Alloy Therapeutics, we believe in fostering trust and open communication. For this role, the estimated range is $150,000 - $200,000, with the final offer based on factors like your experience, skills, and alignment with our needs.
Additionally, this role is eligible for equity compensation, reflecting our commitment to shared success as we work together to make better medicines.
We are proud to offer competitive compensation and benefits, aiming to support our team’s professional and personal well-being. If you have any questions about pay or benefits, we’re here to help.
Alloy Therapeutics is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, veteran status, disability, or other legally protected status. If you are unable to submit an application because of incompatible assistive technology or a disability, please contact us at View email address on alloytherapeutics.applytojob.com . We will make every effort to respond to your request for disability assistance as soon as possible.$105.4k - $207.8k
...with confidence, and proactively manage to secure success. Recruiting for this role ends on... ...threat intelligence and open-source information to maintain awareness of new patterns, activity... ...possess these skills: Proven ability to lead and coordinate a team of analysts across...SuggestedLocal areaVisa sponsorshipShift workRotating shift- RedTrace Technologies seeks an Information System Security Manager II (ISSM II) to lead security for DoD SAP/SCI programs at Hanscom AFB, MA. The role focuses on RMF/JSIG implementation, policy development, and risk management across complex information systems. The ideal...Suggested
- ...Description - Disaster Recovery and Resiliency Lead (260006F4) Job Description Disaster... ...Office of Technology Services and Security The Executive Office of Technology Services... ...Operating Environment that includes an information security and risk management framework for...SuggestedFull timeWork at officeRemote workMonday to FridayShift work
- ...Leidos Corporate Information Security Office (CISO) in Concord, MA is seeking an Information Systems Security Manager to oversee SIPRNET security... ...a team of analysts and staff. You will coordinate audits, lead cybersecurity initiatives, develop training programs, and...SuggestedWork at office
- ...with marketing and promotion. About Jaxon: Jaxon is a leading provider of machine learning and artificial intelligence solutions... ...the company's ideal customer profile. This involves gathering information about the prospect's needs, budget, timeline, and decision-...SuggestedFull timeRemote workFlexible hours
- ...Volantsoft Inc. in Boston, MA is seeking a senior information security professional to oversee security across infrastructure, applications, and user authentication. The role collaborates with state agencies and vendors to ensure secure onboarding and access controls...
- ...\n \n We are seeking a Director of Search & Evaluation to lead strategic sourcing and evaluation of external innovation opportunities... ...scientific, clinical, regulatory, and commercial assessments to inform governance decisions. \n Transaction Execution: Partner...Remote work3 days per week
- PURPOSE AND SCOPE:The Construction Management Lead - Clinics is responsible for leading all... ...of US Clinic Real Estate & Corporate Security.PRINCIPAL DUTIES AND RESPONSIBILITIES:... ...click the link below to request further information on this position. Pay Transparency...Full timeFor contractorsLocal areaRelocationNight shift
$114k - $211.9k
Reporting: Head of Mariana Oncology OperationsDescription: We are seeking an experienced Site Lead, Lab Operations to join Mariana’s Operations team within the G&A organization.Illustrative Breadth of Responsibilities:Accountability for overall Lab Operations strategy...Work at office- Job ID: SRJ_8004Posted: 2025-12-05Location: Waltham, MASalary: USD 65-70 / Hourly (C2C)Employment Type: 1099, C2C, W-2Industry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsRole: Snowflake & Matillion LeadLocation: Waltham, Massachusetts...Hourly payWork experience placement3 days per week
$109k - $154k
...recent merger, National Grid is seeking a Lead Category Buyer within our new Generation... ...' portfolio.The role is accountable for securing market-leading commercial outcomes while... ...Business, or a related discipline.More Information#LI-hybrid #LI-procurement #LI-buyer #LI-...Contract workLocal area$163k - $173k
...Imprivata, we deliver unified access and security management programs that eliminate... ....We are seeking an AppSec and DevSecOps Lead to join our team. This is a hybrid opportunity... ...’s degree in Computer Science, Information Technology, Cybersecurity, Engineering,...Work at officeLocal areaRemote work$19 - $23.75 per hour
...team members to ensure excellent member service. The Front End Lead teaches, develops and motivates all team members for the successful... ...for business growth. Communicate effectively. Provide the information teams require to be successful. Build high performing teams...Weekly payFull timeFlexible hours$185k
...Associate Vice President Bridge Structural Lead US-MA-Newton Job ID: 2026-3318 # of Openings: 1 Category: Civil/Structural Engineering LiRo-Hill Overview We have an immediate need for an Associate Vice President – Bridge Structural Lead to join...Work at officeLocal areaImmediate startRemote work$18 - $21 per hour
Opens and closes the store in the absence of store management, including all required systems start-ups, required cash handling, and ensuring the floor and stock room are ready for the business day. Responsible for opening back door of store for deliveries. Completes...Hourly payWork experience placementSeasonal workLocal areaShift work- ...technology services.At Staples, technology and security are critical to delivering exceptional... ...for our customers and associates. As a Lead Cyber Security Analyst, you will play a... ...Qualifications:Bachelor’s degree in Information Technology, Cybersecurity, Computer Science...Local area
- Job-ID32217193Reference26-00544Job Summary: Responsible for leading and maturing the Validation / Computer System Validation (CSV) program, ensuring compliance with GxP and FDA requirements. The role focuses on driving validation strategy, closing compliance gaps, supporting...
$129k - $153k
...authority interaction with support GRL or Regulatory TA Head. Partner with GRAST members to achieve regulatory deliverables (including leading assigned tasks) while fostering individual accountability, 'team spirit', actively contribute and executing on decisions...WorldwideRelocation package$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Waban. These roles are ideal for individuals looking to step into leadership positions within airport security operations. TSA provides training to...Shift workNight shiftWeekend work$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Lexington. These roles are ideal for individuals looking to step into leadership positions within airport security operations. TSA provides training...Shift workNight shiftWeekend work$85.6k - $149.4k
...a Senior Technology Product Manager - GTM Enablement and Launch Lead, you will play a critical role in ensuring the successful planning... ...together. This role is central to ensuring internal teams are informed, prepared, and aligned.The ideal candidate combines strong program...Full timeWork at office$272k - $340k
...autoimmune diseases. Zenas is advancing two late-stage, potential franchise molecules, obexelimab and orelabrutinib. Obexelimab, Zenas’ lead product candidate, is a bifunctional monoclonal antibody designed to bind both CD19 and FcγRIIb, which are broadly present across B...Flexible hours$17.5 - $26 per hour
...possibilities quite this beautiful. GENERAL SUMMARY & SCOPE The Lead Cashier (LC) is responsible for the efficiency of guest... ...associate exit inspections as needed. Take the initiative to stay informed regarding new and existing industry trends, products, and...Full timePart timeWork experience placementLocal areaFlexible hoursShift workAfternoon shift- ...external innovation priorities.* Partner closely with TA Search Leads to conduct regional searches, plan engagements and conferences,... ...CSL Vifor visit and CSL Plasma at .**Our Benefits**For more information on CSL benefits visit .**You Belong at CSL**At CSL, Inclusion and...Local areaWorldwide
$128.9k - $226.05k
...momentum, and how product changes affect adoption and value. As Lead Product Analyst, CDS Adoption & Engagement, you will focus on adoption... ...launches, pilots, MVPs, and experiments. Identify insights that inform roadmap priorities, UX improvements, content needs,...Full timeWork at office$25 per hour
...Job Description Job Description Site Lead – Fingerprinting Operations (Temporary Project) Sparks Group has partnered with a... ...religion, sex, national origin, age, pregnancy, citizenship, family status, genetic information, disability, or protect veteran status....Hourly payTemporary workImmediate startMonday to FridayShift work- ...Imprivata is seeking an AppSec and DevSecOps Lead to operationalize security across its product lines, engineering teams, and infrastructure. This role will embed security throughout the software lifecycle—from design and coding through testing, deployment, operations,...
- ...Imprivata is seeking an AppSec and DevSecOps Lead to operationalize secure software delivery across product lines, engineering teams, and infrastructure. You will embed security throughout the lifecycle—from design and coding through testing, deployment, operations, and...
- ...milestone delivery. You will coordinate cross-functional planning, maintain integrated timelines, prepare dashboards, identify risks, and lead team meetings to keep programs on track. Travel up to 10% may be required. This role requires a BA/BS in life sciences and 10+...
$154.45k - $212.37k
...personal growth, all while valuing your unique contributions. Lead the Intelligence Logic team responsible for the next-generation... ..., marital status, family responsibilities, pregnancy, genetic information, sexual orientation, gender expression, gender identity,...Temporary workWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Lead. Be the first to apply!








