> Markdown version of [/jobs/ext/1869027-senior-manager-information-security-and-compliance](https://www.wearedevelopers.com/jobs/ext/1869027-senior-manager-information-security-and-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Manager, Information Security and Compliance - **Company:** Parabilis Medicines - **Location:** Cambridge, UK - **Experience:** Expert - **Salary:** £165,000.0 - £195,000.0 - **Contract:** Franchise - **Skills:** Amazon Web Services, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems, Data Integrity, Identity and Access Management, Information Security Management, IT Management, Python (Programming Language), Network Segmentation, Windows PowerShell, Software Requirements Analysis, Data Logging, Data Processing, Scripting, IT General Controls (ITGC), Okta, Information Technology, GXP - **Published:** August 1, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5822579936 ## About the Role * 6+ years of hands-on experience in technical security, ideally within regulated industries * Bachelor's degree in Computer Science, Information Systems, or related field preferred * Demonstrated experience operating within a regulated compliance environment (FDA/GxP, HIPAA, SOX, or SOC2), ideally in life sciences, healthcare, or another audited industry. * Hands-on expertise across endpoint security (EDR/MDR), identity and access management (Okta, Entra ID), and cloud security (AWS multi-account environments). * Practical experience implementing and operating security controls and mapping them to compliance frameworks and audit requirements. * Proven ability to lead incident response and manage security and compliance vendors and consultants to deliver outcomes. * Working knowledge of QA and change control practices in a regulated environment, and the judgment to make controls satisfy both security and compliance goals. * Comfort operating in a lean team: setting priorities independently, staying hands-on, and directing external partners without relying on direct reports. * Proficiency in scripting (PowerShell, Python, or equivalent) for automation and integration. * Exceptional communication skills and the ability to influence cross-functional teams without direct authority. * CISA (compliance and audit focus) and/or CISSP (security focus) preferred ## Description Security Operations & Controls Implementation * Implement, configure, and operate security controls across endpoint, identity, network, and cloud, including endpoint detection and response, managed detection and response, and software and extension controls. * Own the endpoint security roadmap and drive execution across the environment, including migration off legacy tooling to a modern EDR/MDR stack. * Design and enforce identity and access controls across Okta, Entra ID, and connected systems, including least-privilege access, access recertification, and privileged access management. * Partner with Cloud Architecture to embed security into AWS multi-account infrastructure, including guardrails, network segmentation, logging, and posture management. * Serve as the technical lead for security tooling evaluations, proofs of concept, and rollouts, staying hands-on where depth is required. Compliance, Quality & Policy Integration * Maintain intimate familiarity with Parabilis policies, SOPs, and QA guidance, and ensure all technical teams operate securely and within that framework. * Translate SOX ITGC, GxP, HIPAA, and SOC2 requirements into practical, enforceable technical controls and repeatable operating practices. * Partner with QA to align security controls with validated-system requirements, change control, and data integrity expectations. * Own control documentation, evidence collection, and traceability to support internal reviews and external audits, and act as a primary technical point of contact during audit activity. * Contribute to and enforce IT policy, working with the Sr. Director of IT to set standards and best practices across the organization. Vendor & Consultant Management * Manage security and compliance vendors, MSP contractors, and specialist consultants, directing their work to deliver defined outcomes on schedule. * Own vendor risk assessment for new and existing technology partners, including privacy, data handling, and terms-of-service review in coordination with Legal and IT leadership. * Hold vendors accountable to SLAs, security commitments, and contractual obligations, and escalate where performance or risk warrants. Incident Response * Own the security incident response process end to end, from detection and triage through containment, remediation, and post-incident review. * Respond to security incident reports, coordinate the technical response across internal teams and vendors, and drive incidents to closure with clear documentation. * Maintain and exercise incident response and business continuity runbooks, and feed lessons learned back into controls and policy. * Support regulatory, legal, and breach-notification obligations in coordination with IT leadership, QA, and Legal when incidents carry compliance impact. Collaboration & Influence * Report to the Sr. Director of IT and work collaboratively with cross-functional teams across the organization to maintain the company's security and compliance posture across all systems. * Act as a trusted advisor to Engineering, Research, Clinical, and Enterprise teams, embedding secure and compliant practices into how they build and operate. * Communicate risk clearly to both technical and non-technical audiences, and advocate for pragmatic controls that enable the business rather than block it. ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)