Sr. Information Security Specialist - Remote
Philadelphia, PA, United States
Applications have closed
Medable
Streamline your clinical trial and generate high-quality data with a #1 rated, easy-to-use platform, offered in over 60 countries and 120 languages. Book a demo to learn more.Company Description
Medable's mission is to get effective therapies to patients faster. We provide an end-to-end, cloud-based platform with a flexible suite of tools that allows patients, healthcare providers, clinical research organizations and pharmaceutical sponsors to work together as a team in clinical trials. Our solutions enable more efficient clinical research, more effective healthcare delivery, and more accurate precision and predictive medicine. Our target audiences are patients, providers, principal investigators, and innovators who work in healthcare and life sciences.
Our vision is to accelerate the path to human discovery and medical cures. We are passionate about driving innovation and empowering consumers. We are proactive, collaborative, self-motivated learners, committed, bold and tenacious. We are dedicated to making this world a healthier place.
Job Description
- Participate in ISO 27001 Certification and annual surveillance audits.
- Participate in SOC-2 reporting processes in collaboration with key stakeholders and third-party auditors.
- Modify Medable IT/IS related policies and procedures as needed to comply with audit findings and applicable IS industry and regulatory standards.
- Participate in customer requested audits of the IS program.
- Oversee IS related audit findings and work with key stakeholders to establish and execute remediation plans within SLAs.
- Participate in critical vendor IS Risk and Compliance audits in accordance with Vendor Management SOP.
- Complete customer RFI assessments as assigned. Maintain the RFI library with current information.
- Evaluate vendor RFI responses in relation to company information security requirements and assess risk accordingly.
- Maintain Governance Risk and Compliance (GRC) tool risk assessments for vendor and asset risk management.
- Participate in cross-functional risk assessments for vendor management and custom solutions.
- Participate in IS related Incident Management investigation and reporting activities in collaboration with key stakeholders and incident response team members.
- Participate in Business Continuity and Disaster Recovery Plan development and annual testing in collaboration with key stakeholders.
- Other duties as assigned.
Qualifications
- 2+ years experience specifically in an IS/IT Risk and Compliance role.
- Preferred experience in the Clinical Research/Technology industry.
- Experience with ISO 27001 and SOC-2 standards and controls.
- Experience with Risk Assessment activities and documentation.
- Experience in IS related incident investigation, reporting, and compliance.
- Experience participating in IT/IS audits.
- Experience managing customer and vendor RFI responses.
- Experience authoring and maintaining IT/IS related policies and procedures.
- Knowledge/Experience with Business Continuity and Disaster Recovery planning.
- Strong organizational, and interpersonal communication skills
- Multi-tasking and prioritization skills
- Critical thinking and problem-solving skills
- Ability to build strong cross-functional relationships
- Proficient process enhancement skills
- Policy writing skills
Education, Certification, Licenses:
- Bachelor's degree in IT/IS related field, or equivalent combination of certifications and/or work experience.
- One or more IS or Risk and Compliance related certifications including but not limited to (CRISC, CGEIT, GRCP, etc.)
#LI-MQ1
#LI-REMOTE
Additional Information
Medable, Inc provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
U.S. employees and contractors, and International workers with travel to the U.S. must have a willingness and ability to provide proof of completed COVID-19 vaccination prior to start date. All strongly held beliefs, religious, medical, and other legally recognized exemptions regarding vaccination status will be considered.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Cloud Compliance CRISC Governance Incident response ISO 27001 Risk assessment Risk management SLAs SOC Surveillance Vendor management
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Senior Security Analyst jobs
- Open Security Operations Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Information Security Analyst jobs
- Open Product Security Engineer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Cybersecurity Analyst jobs
- Open Cyber Security Specialist jobs
- Open Principal Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Specialist jobs
- Open Security Specialist jobs
- Open Chief Information Security Officer jobs
- Open Security Researcher jobs
- Open Senior Penetration Tester jobs
- Open Senior Security Architect jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Cyber Security Specialist jobs
- Open Information System Security Officer (ISSO) jobs
- Open Clearance-related jobs
- Open ISO 27001-related jobs
- Open Application security-related jobs
- Open Windows-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open CISM-related jobs
- Open GCP-related jobs
- Open Vulnerability management-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open IAM-related jobs
- Open CISA-related jobs
- Open Threat intelligence-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open Java-related jobs
- Open Kubernetes-related jobs
- Open EDR-related jobs
- Open Malware-related jobs
- Open APIs-related jobs
- Open IDS-related jobs
- Open Security Clearance-related jobs
- Open DevSecOps-related jobs
- Open CI/CD-related jobs