Head of Information Security

Accumulus Technologies, Inc.
United States
19 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$200,000.0 - $260,000.0
Working hours
Regular working hours
Job source

Tech stack

Software as a Service Cloud Computing Cloud Computing Security Cyber Security DevOps Disaster Recovery Identity and Access Management IT Management Secure Coding Software Vulnerability Management Software Security

Job description

Accumulus Technologies is seeking a Head of Information Security to lead the company’s information security function across corporate operations and the Accumulus Platform. Reporting directly to the Chief Operating Officer, with direct access to executive leadership and the Board on material security matters, this leader will set security strategy, oversee governance, risk, and compliance, and represent Accumulus’ security posture to customers, regulators, and other external stakeholders.

You will lead the CyberDefense, Product Security, and GRC teams. Working with Engineering, Product, DevOps, IT, Legal, and Commercial, you will translate business priorities and security risks into a practical roadmap, establish clear control ownership, and hold teams accountable for delivery.

This is a strategic and hands-on leadership opportunity for a security leader who combines technical judgment, operational discipline, and clear communication to protect the business, sustain assurance commitments, and build customer trust.

Responsibilities

  • Own the corporate and product information security strategy, program, and annual objectives; define a prioritized roadmap and align security resources and investment needs with the COO.

  • Own the evolution of Accumulus’ technical security capabilities across cloud infrastructure, product security, identity, vulnerability management, detection and response, and security architecture, prioritizing investment according to material business and cyber risk.

  • Lead and develop the CyberDefense and Product Security teams; set priorities, performance expectations, and accountability for internal staff and external providers.

  • Oversee the GRC program and delivery of audit coordination, evidence collection, policies, assessments, remediation tracking, and Vanta administration; retain accountability for program outcomes.

  • Maintain audit readiness and oversee required audits, certifications, and attestations, prioritizing current commitments and the effective operation of supporting controls.

  • Review material cyber risks, challenge risk ratings and treatment plans, approve security exceptions within delegated authority, and escalate business risk acceptance to executive leadership.

  • Partner with Engineering, Product, DevOps, and IT leadership to embed security in architecture, development, and operations; hold control owners accountable for effective safeguards and timely remediation.

  • Provide senior security direction during material incidents, authorize escalations, oversee lessons learned, and ensure incident response, disaster recovery, and business continuity capabilities are tested with accountable teams.

  • Resolve cross-functional security decisions affecting delivery, customer commitments, or business risk; escalate unresolved tradeoffs and investment needs to the COO and executive leadership.

  • Report security posture, material risks, incidents, remediation performance, emerging threats, and investment priorities to executive leadership and the Board, as appropriate.

  • Serve as Accumulus’ senior security representative with customers, prospects, regulators, auditors, partners, and insurers; clearly explain the company’s architecture, controls, certifications, risk posture, and regulatory environment.

  • Lead Accumulus’ customer security assurance program, including strategic customer and prospect discussions, due diligence, RFPs, and security assessments; establish a scalable response process and ensure timely, accurate responses.

Requirements

  • Substantial progressive experience in information security, including leadership of a corporate or product security function and ownership of security strategy and program delivery.

  • Demonstrated ability to manage and develop internal security teams and hold external contractors or service providers accountable for results.

  • Required familiarity with Vanta and with ISO 27001, SOC 2, and HITRUST; practical experience overseeing GRC programs, audits, evidence readiness, and remediation.

  • Strong understanding of cloud and SaaS security, secure development, identity and access management, encryption, vulnerability management, monitoring, and incident response.

  • Experience assessing cyber risk, evaluating control effectiveness, governing security exceptions, and translating technical findings into business decisions.

  • Proven ability to lead customer security reviews and questionnaires and communicate security posture credibly to executives, auditors, regulators, and technical stakeholders.

  • Experience coordinating response, recovery, resilience testing, and follow-through on corrective actions.

  • Ability to prioritize competing demands, influence cross-functional teams, and make pragmatic, risk-based security decisions that support product delivery and commercial objectives while protecting the company’s security and assurance commitments.

  • Experience in SaaS, life sciences, or other regulated environments preferred; CISSP, CISM, or a comparable security certification is a plus.

Benefits & conditions

  • Base salary: $200,000 - $260,000/year

  • Discretionary bonus of 22%.

  • 3% contribution to a 401(k), even if you do not make contributions.

  • Medical, dental, vision, short-term disability, long-term disability, and life insurance from day one.

  • Unlimited vacation.

  • Up to 16 weeks of parental leave.

About the company

Accumulus Technologies helps life sciences companies reduce regulatory friction, shorten timelines, and lower execution risk across product development and lifecycle management-delivering measurable and transformational ROI. We support the full spectrum of regulatory engagements-strategy, submissions, and lifecycle management-spanning CMC, clinical and nonclinical content, labeling, commitments, post-approval changes, and reliance/work-sharing models. Our focus is commercial impact: faster approvals, smoother post-approval change execution, fewer surprises, and tighter alignment between commitments and what teams can deliver. Our clients measure the value we bring in the tens of millions.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Analyzing differences between mobile and traditional backend DevOps

Mete Baydar Mete Baydar · World Congress 2025

2:10 min

Managing open source ports using the zopen package manager

Igor Todorovski · World Congress 2023

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

3:27 min

Defining DevOps through its historical origins and foundational texts

Sonal Patil · LIVE

Videos

See all

Related articles

See all