> Markdown version of [/jobs/ext/177913-information-security-lead](https://www.wearedevelopers.com/jobs/ext/177913-information-security-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Lead - **Company:** Proscia Inc. - **Location:** Philadelphia, PA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Business Software, Software as a Service, Cloud Computing, Code Review, Cyber Security, Information Security Management, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Large Language Models, Prompt Engineering, Devsecops - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=94307c5c1484ad54 ## About the Role You think in systems-you reason about how security, engineering, and compliance interact across the full stack, not just your own domain. AI tools are part of how you work: drafting policies, analyzing threats, reviewing configurations, pressure-testing your own thinking. You know when to trust AI output and when to change the approach. You iterate quickly, own your decisions, and you're ready to put your stamp on a security program at a company that's moving fast in regulated healthcare. * 5+ years of experience in information security, including direct experience improving, and contributing to GRC programs. * Proven expertise in regulatory frameworks such as ISO 27001, SOC 2, GDPR, HIPAA, FedRAMP, TX-RAMP, StateRAMP or similar. * Experience with FDA regulations is an asset. * Hands-on experience with vulnerability management tools, incident response, and security audits. * Experience embedding security into software development lifecycles-DevSecOps principles applied in practice. * Experience selecting, implementing, and managing security tooling (e.g., XDR, SIEM, endpoint, code scanning, etc.). * Exceptional communication and influencing skills across technical and non-technical teams. * A high degree of autonomy and ownership-comfortable leading cross-functional efforts and prioritizing in a dynamic environment. * You already use AI tools in your security work-for policy drafting, threat analysis, log review, control validation, or however it fits your practice. * Experience with cloud-native environments (AWS preferred) * Experience building with or on top of LLMs, AI agents, or agentic pipelines. * Familiarity with prompt engineering, tool use patterns, and evaluation of AI systems. Nice-to-Haves * Experience with SaaS platforms, and startup culture. * A portfolio, published work, or contributions that show how you think about security problems. * Background that spans multiple domains or disciplines. * Active in security communities, forums, or meetups. * Contributions to the broader AI security conversation. ## Description We're hiring a Lead of Information Security, reporting to the VP of Technical Operations. You'll architect and evolve the security and compliance foundation of our Concentriq platform-used in regulated environments around the world. This is a high-impact leadership role focused on building a modern, rigorous security program where AI tools are part of how you and your team think, investigate, and operate every day. What You'll Do Working at a startup like Proscia means wearing many hats, but when you come to work you can expect to focus on the following: * Manage and evolve vulnerability management- tooling, reporting, and remediation governance. You understand the current evolution of the field and leverage AI appropriately for first-class vulnerability management: deliberately and with clear guardrails. * Serve as a consultative security leader for Engineering, Product, and Customer teams-governing system designs, architecture, and implementation through a security-first lens. * Implement AI native tooling to improve detection and response capabilities without incurring an increased demand on resources. * Partner with Engineering to implement developer-friendly security tools that improve security posture and reduce compliance burdens without slowing velocity. * Oversee incident response preparation, processes, and execution-ensuring coordinated action, effective communication, and the kind of thorough post-incident analysis that prevents the same problem twice. * Under the direction VP, TechOps, improve the Proscia Information Security Program, with a focus on governance, risk, and compliance (GRC) across the Concentriq suite of applications and Proscia's business applications. * Contribute to security policy development across regulated and non-regulated markets-implementing agentic workflows where it accelerates your research and stress-testing, iterating with stakeholders, and maintaining the rigor and compliance standards our customers expect. * Influence and execute on the company's regulatory roadmap-seeking new certifications and frameworks (e.g., ISO 27001, SOC 2, HITRUST) in response to customer and market demands. * Enable other teams to answer security-related questions from customers, prospects, and partners providing expert information security guidance. * Anticipate and adapt to industry and regulatory trends, including how AI is reshaping both the threat landscape and the defender's toolkit-and surface emerging requirements before they become urgent. * Help shape internal security standards and documentation that work for both humans and AI-augmented workflows. ## Related Videos - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)