> Markdown version of [/jobs/ext/208583-associate-director-information-security](https://www.wearedevelopers.com/jobs/ext/208583-associate-director-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Director, Information Security - **Company:** Iambic Therapeutics, Inc - **Location:** San Diego, CA, United States - **Salary:** $156,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Encodings, Cyber Security, DevOps, Identity and Access Management, IT Management, Security Information and Event Management, Software Engineering, Software Vulnerability Management, IT General Controls (ITGC), Software Security, RSA Archer Platform, GXP - **Published:** May 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=af8f0d9f36fc6d96 ## About the Role Do you have experience in SOX?, * 12+ years of progressive information security experience with a strong track record of hands-on technical execution * Direct, practitioner-level experience in at least two of the three domains: GRC, IT security operations, and application/cloud security * Experience collaborating with or embedding security within software engineering or product organizations * Deep working knowledge of ISO 27001, including post-certification program management and audit readiness * Familiarity with SOC 2, NIST CSF, HIPAA, SOX IT General Controls, and related frameworks * Hands-on understanding of application security principles, secure SDLC practices, and cloud security (AWS, Azure, or GCP) * Able to write and maintain clear, practical policies and standards directly, without relying on external consultants or pre-built templates * Strong risk assessment skills with the ability to translate technical findings into business impact for non-technical audiences * Experience supporting or preparing for a SOX readiness assessment or IPO-related compliance effort * Direct experience with GRC platforms (Vanta, Drata, Tugboat Logic, or similar) and security tooling across endpoint, identity, SIEM, and AppSec domains * Pragmatic and mission-driven; energized by doing meaningful work in a fast-moving clinical-stage environment PREFERRED QUALIFICATIONS * Regulated industry experience strongly preferred; life sciences, biotech, or pharma background is a meaningful plus * CISM, CISSP, or CRISC certification preferred, AWS Security Specialty, CCSP, or equivalent a plus ## Description We have an established information security program and are looking for a hands-on Associate Director to grow it and take it to the next level. This is a practitioner role as much as a leadership role - you will be directly involved in the work across governance, IT, cloud security, software, and DevOps. The immediate strategic priority is expanding our security posture into the software development lifecycle, embedding cloud security practices across our internally developed SaaS environment, while maintaining and maturing our governance, risk, and compliance foundation. You will work to obtain and maintain our ISO certification, partnering closely with IT leadership, R&D, and the broader organization to continuously raise the security bar across the company. This role reports to the VP of IT and carries significant visibility to the CTO and senior leadership., * Drive and mature the company-wide information security program and strategy including managing policies, standards, risk assessments, and the enterprise risk register * Act as the primary internal authority on information security operations, advising leadership and department heads on risk and priorities * Develop security metrics and reporting for technical and executive stakeholders * Serve as a working technical mentor to security analysts, providing hands-on guidance, knowledge sharing, and day-to-day direction across IT and cloud security domains * Own ISO 27001 certification and maintenance, including audits, evidence collection, and improvement * Directly manage controls rationalization across frameworks (ISO 27001, SOC 2, NIST CSF, SOX ITGC) to support evolving compliance requirements * Lead and execute the vendor and third-party risk management program * Establish and maintain information security controls in alignment with life sciences regulatory requirements, including 21 CFR Part 11 and GxP * Partner with the Software, cloud security, and DevOps teams on expanding industry-standard security practices into the software development lifecycle * Actively participate in security operations across the corporate IT environment, including hands-on involvement in endpoint security, identity and access management, vulnerability management, and security monitoring * Define cloud security governance standards and policies for SaaS-hosted environments and oversee compliance * Own and continuously improve the company-wide security awareness and training program * Champion a realistic, risk-based security culture across a diverse workforce spanning research, clinical, and corporate functions ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)