OneStudyTeam

OneStudyTeam

Security Compliance Manager

United States-Remote · Full-time

No sponsorship$140k-$170kDetected 27 days ago
AWSGCPAzureCI/CDIncident ResponseComplianceAuditingHIPAAClinical TrialsClinical ResearchResearchLeadershipCommunicationInternal Audit

About the role

  • At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes.
  • StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries.
  • We do not discriminate on the basis of race, sex, religion, color, national origin, gender identity, age, marital status, veteran status, or disability status.

Responsibilities

  • Drive quarterly ISO control requirements, manage ISO surveillance audits, lead SOC 2 examination readiness, and oversee ongoing maintenance activities once achieved.
  • Manage internal ISMS control reviews, coordinate remediation and corrective actions, and ensure controls remain effective and scalable as the organization changes.
  • Recommend and implement improvements to the information security risk management program; develop and maintain the risk register, risk ownership, and workflows for tracking remediation plans to closure.
  • The Security Compliance Manager leads the organization's security compliance and assurance efforts-ensuring we meet and maintain certification requirements (e.g., ISO 27001, SOC 2) and always remain audit-ready.
  • This role translates security control requirements into actionable work across teams, drives evidence collection and remediation, and strengthens risk management practices to enable growth in regulated environments.

Requirements

  • Minimum of 5+ years in a dedicated information security role in a regulated environment (e.g., HIPAA, GLBA, PCI).

Compensation

  • Demonstrated ability to lead ISO 27001 and/or SOC 2 certification efforts and ongoing maintenance activities.
  • Strong competency in gap analysis and risk assessment methodologies; able to translate results into prioritized remediation plans.
  • Working knowledge of security policy, procedure, and enforcement across key domains: access control, data classification, change management, asset management, BCDR, incident response, vulnerability management, secure SDLC, source control, endpoint protection.
  • Ability to translate security/compliance requirements into actionable work for Engineering/IT/Operations (tickets, owners, acceptance criteria, evidence).
  • Strong written and verbal communication-able to interface with all levels of the organization and produce high-quality audit-ready documentation.
  • Technical foundation sufficient to understand high-level concepts related to public cloud (AWS/GCP/Azure), Agile SDLC, CI/CD, VPNs, and modern web applications.

Company info

  • Join us in our mission to advance clinical research and improve patient care.

Visa & Work Authorization

  • OneStudyTeam is unable to sponsor work visas at this time.

This listing is sourced directly from OneStudyTeam's careers page and normalized into a canonical job model.