Information Security Lead
$150,000–$200,000 year
RemoteUnited States
Job Summary
Own Alloy's security program by refining Incident Response and Business Continuity playbooks, running vulnerability management with strict remediation SLAs, and coordinating annual penetration testing. Design and implement IAM controls including FIDO2 hardware keys, manage endpoint security configurations, and ensure encryption across multi-petabyte research and partner-derived datasets. Maintain SOC 2 Type 2 compliance evidence, write auditable security policies, and establish detection plans against nation-state threat actors. Serve as the primary security practitioner for sovereign engagements, managing vendor reviews and data residency controls while partnering with AI and research divisions.
Required Qualifications
- Significant breadth across both technical security work and governance
- Hands-on experience with cloud security across Google Workspace and AWS (or GCP/Azure equivalent), including IAM design, cloud storage security, and logging and monitoring configuration
- Experience securing proprietary scientific or research data at massive scale
- Experience defending against advanced and nation-state-level threat actors, and supporting sovereign, government, or other high-assurance programs with elevated security and data-residency requirements
- Experience implementing MFA programs including FIDO2/hardware key standards (e.g., YubiKey) and SSO/SCIM provisioning across a SaaS environment
- Demonstrated experience with backup architecture design, including immutable and geo-redundant backup solutions, and with running and documenting restore tests
- Familiarity with compliance frameworks including SOC 2 Type 2 and/or ISO 27001
- Experience writing security policies and documentation that can withstand external scrutiny (AUPs, IRPs, BCP/DR plans, vulnerability management programs) as living operational documents
- Comfortable operating as the primary security practitioner in a lean environment where you are self-directed, able to prioritize across competing demands, and effective at coordinating with Legal, Finance, and external vendors without bureaucratic supporting team
Desired Qualifications
- Biotech, life sciences, or regulated industry experience
- Experience with pharmaceutical partner security requirements
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.