This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re hiring a Lead of Information Security, reporting to the VP of Technical Operations. You’ll architect and evolve the security and compliance foundation of our Concentriq platform—used in regulated environments around the world. This is a high-impact leadership role focused on building a modern, rigorous security program where AI tools are part of how you and your team think, investigate, and operate every day.
Job Responsibility
Manage and evolve vulnerability management— tooling, reporting, and remediation governance
Serve as a consultative security leader for Engineering, Product, and Customer teams—governing system designs, architecture, and implementation through a security-first lens
Implement AI native tooling to improve detection and response capabilities without incurring an increased demand on resources
Partner with Engineering to implement developer-friendly security tools that improve security posture and reduce compliance burdens without slowing velocity
Oversee incident response preparation, processes, and execution—ensuring coordinated action, effective communication, and the kind of thorough post-incident analysis that prevents the same problem twice
Under the direction VP, TechOps, improve the Proscia Information Security Program, with a focus on governance, risk, and compliance (GRC) across the Concentriq suite of applications and Proscia’s business applications
Contribute to security policy development across regulated and non-regulated markets—implementing agentic workflows where it accelerates your research and stress-testing, iterating with stakeholders, and maintaining the rigor and compliance standards our customers expect
Influence and execute on the company’s regulatory roadmap—seeking new certifications and frameworks (e.g., ISO 27001, SOC 2, HITRUST) in response to customer and market demands
Enable other teams to answer security-related questions from customers, prospects, and partners providing expert information security guidance
Anticipate and adapt to industry and regulatory trends, including how AI is reshaping both the threat landscape and the defender’s toolkit—and surface emerging requirements before they become urgent
Help shape internal security standards and documentation that work for both humans and AI-augmented workflows
Requirements
5+ years of experience in information security, including direct experience improving, and contributing to GRC programs
Proven expertise in regulatory frameworks such as ISO 27001, SOC 2, GDPR, HIPAA, FedRAMP, TX-RAMP, StateRAMP or similar
Hands-on experience with vulnerability management tools, incident response, and security audits
Experience embedding security into software development lifecycles—DevSecOps principles applied in practice