At a Glance
- Tasks: Lead security governance and risk management to support groundbreaking drug discovery.
- Company: Join Isomorphic Labs, a pioneering AI-driven company transforming drug discovery for better health.
- Benefits: Enjoy a hybrid work model, collaborative culture, and opportunities for personal growth.
- Why this job: Make a real impact on global health while working in an innovative and supportive environment.
- Qualifications: Strong knowledge of InfoSec standards and experience in risk management are essential.
- Other info: Be part of a diverse team committed to equal opportunities and continuous learning.
The predicted salary is between 48000 - 84000 £ per year.
InfoSec Risk and Governance Lead, London
London
InfoSec Risk and Governance Lead, Lausanne or London
We are here to advance human health, by reimagining drug discovery with the power of artificial intelligence.
The future is coming. A future enabled and enriched by the incredible power of machine learning. A future in which diseases are curtailed or cured by better and faster drug discovery.
Our values exist in service of that future. We think they’ll help us bring it closer, too.
Come and be part of an interdisciplinary team driving groundbreaking innovation and play a meaningful role in contributing towards us achieving our ambitious goals, while being a part of an inspiring and collaborative culture.
The world we want tomorrow is the one we’re building today. It starts with the culture at this company. It starts with you.
About Iso
Isomorphic Labs (IsoLabs) was founded in 2021 and is led by Sir Demis Hassabis. Our aim is to usher in a new era of biomedical breakthroughs and find cures for some of humanity’s devastating diseases.
Our foundations are built on the success of Google DeepMind’s AlphaFold, but we didn’t stop there! We are continuing to develop and implement state-of-the-art technologies as we move towards our goal of dramatically accelerating and improving the process of designing and bringing new medicines to patients.
We have built a world-leading drug design engine comprising foundational AI models that are capable of working across multiple therapeutic areas and drug modalities. The company is continually innovating on model architecture and developing cutting-edge capabilities to advance rational drug design.
Your impact
As the Information Security Risk and Governance Lead, you will architect and evolve our security governance framework underpinning our scientific breakthroughs. Directly reporting to the CISO, your work will be critical in aligning our data management and security strategy with a complex regulatory landscape; enabling cutting-edge research programmes and reinforcing trust with partners. Your role will be instrumental in fostering a culture of security accountability and risk-informed decision-making, and ultimately in enabling Isomorphic Labs’ mission to solve all disease.
What you will do
- Architect and operationalise a unified compliance framework spanning Drug Discovery and Development, AI, and Cyber regulatory landscapes.
- Own the strategic programme to achieve and maintain ISO 27001 certification for our Information Security Management System (ISMS).
- Author and maintain our security policies and processes, ensuring they are practical and effectively applied within our GxP-regulated and AI-first environment.
- Lead information security-related risk management and deliver actionable reports to key stakeholders, translating technical risks into business impact.
- Combine robust technical knowledge and business operations expertise to craft tailored risk mitigation strategies.
- Partner with Tech, ML, Legal, and Medical Research Teams to implement a comprehensive data governance framework, encompassing labelling, audit trails, and data lifecycle.
- Oversee internal and external audit programs and drive continuous readiness for regulatory inspections and partner due diligence.
- Lead engaging awareness and training programmes that foster a strong security culture throughout the organisation.
- Own Third Party Risk Management, including building an innovative approach to assess and manage risks from our critical AI, cloud, and research partners.
- Establish and report on Key Performance Indicators (KPIs) to demonstrate the effectiveness of security operations on business outcomes.
Skills and qualifications
- Ability to excel as an individual contributor initially, with the agility to pivot from strategic risk planning to direct, collaborative implementation assistance.
- Knowledge of security and compliance standards across InfoSec (e.g. ISO 27001, NIST, HITRUST), life sciences (e.g. GxP, 21 CFR), emerging AI regulation (e.g. EU AI Act), and privacy domains (GDPR, HIPAA).
- Demonstrated experience leading multifaceted certification programs and responding to external audits.
- Robust knowledge of information technology and cybersecurity, including cloud and ML-based environments.
- Proven ability to manage the full risk management lifecycle, from technical risk identification and analysis to presenting clear, business-focused mitigation options.
- Experience managing the security threats posed by a complex third-party ecosystem, including cloud providers, AI vendors, and clinical research organisation partners (CROs).
- Practical experience with data governance and privacy controls, including data classification, audit trail, de-identification and data lifecycle management.
- Demonstrated experience in either the life sciences or the AI industry, with a strong grasp of domain-specific risks and regulatory challenges.
- Open-minded and innovative approach in meeting regulatory requirements, balancing compliance with the efficiency demands of ML-driven drug discovery.
- A natural ability to build credibility and influence decision-making across scientific, engineering, corporate and leadership functions to drive the security agenda forward.
Nice to have:
- Experience building and operating a Trusted Research Environment and/or Trusted ML Environments.
- Familiarity with AI-specific threats and security controls, such as those addressing model inversion, data poisoning, or adversarial attacks.
- Experience using modern GRC platforms (e.g. Vanta, Drata) or scripting (e.g. Python) to automate evidence collection and control monitoring.
- Contribution to open-source security projects or participation in security communities.
Culture and values
We are guided by our shared values. It\’s not about finding people who think and act in the same way. These values help to guide our work and will continue to strengthen it.
Thoughtful
Thoughtful at Iso is about curiosity, creativity and care. It is about good people doing good, rigorous and future-making science every single day.
Brave
Brave at Iso is about fearlessness, but it’s also about initiative and integrity. The scale of the challenge demands nothing less.
Determined
Determined at Iso is the way we pursue our goal. It’s a confidence in our hypothesis, as well as the urgency and agility needed to deliver on it. Because disease won’t wait, so neither should we.
Together
Together at Iso is about connection, collaboration across fields and catalytic relationships. It’s knowing that transformation is a group project, and remembering that what we’re doing will have a real impact on real people everywhere.
Creating an extraordinary company
We believe that to be successful we need a team with a range of skills and talents. We\’re building an environment where collaboration is fundamental, learning is shared and every employee feels supported and able to thrive. We value unique experiences, knowledge, backgrounds, and perspectives, and harness these qualities to create extraordinary impact.
We are committed to equal employment opportunities regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy or related condition (including breastfeeding) or any other basis protected by applicable law. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.
It’s hugely important for us to share knowledge and build strong relationships with each other, and we find it easier to do this if we spend time together in person. This is why we follow a hybrid model, and would require you to be able to come into the office 3 days a week (currently Tuesday, Wednesday, and one other day depending on which team you’re in). If you have additional needs that would prevent you from following this hybrid approach, we’d be happy to talk through these if you’re selected for an initial screening call.
Please note that when you submit an application, your data will be processed in line with our privacy policy .
Interested in building your career at Isomorphic Labs? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field
First Name *
Last Name *
Preferred First Name
Email *
Phone
Resume/CV *
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
As an AI-first company, we embrace tools like Gemini. However, our interview process is designed to understand your unique expertise and problem-solving skills, as well as what motivates you.Therefore, we ask that you refrain from using any AI tools, transcription services, or other assistants during your interview and assessment process, unless you\’ve made prior arrangements with our Talent team for specific needs or accommodations. (If you require any adjustments, please discuss this with the Talent team during your initial screening call.) *
By checking this box and proceeding with your application, you confirm that you have read and agreed to these terms and will not use any AI tools or assistants during the interview and assessment process.
In which of our office locations would you prefer to be based? (Note that certain jobs may only be available in one location – please check the details before applying) * Select…
What are your salary expectations (base / total package)? Please note that this is what you would be looking for in your next role, NOT your current package.
What is your current notice period?
Where did you hear about Iso?
Press article / publication
DeepMind website
Indeed
Other job board
Search engine
Conference/event (please let us know which one below)
Alphabet Grow (current employee of GDM)
Alphabet Grow (current employee of any other Bet)
Referred by an employee at Isomorphic Labs (please let us know who below)
Other
Where did you hear about Iso? (Additional info)
Is there anything else you\’d like us to know?
LinkedIn Profile
Website
Iso Demographic Questions
We value diversity of experience, knowledge, backgrounds and perspectives and harness these qualities to create extraordinary impact. We are working to build teams that reflect and represent the populations we are striving to serve. As part of this effort we would like to better understand our candidate audience, so that we can continue to improve.
We need your help to do this, but filling in this form is entirely voluntary . You may choose not to provide the requested demographic information. Whether you choose to provide the information or not, this will be kept separate from your application and will have no bearing on any hiring decision.
Any demographic information you provide will be anonymised and held separately from your application . No Isomorphic Labs hiring decision makers will have access to this information and the information will only be used for aggregated reporting and monitoring purposes, not for the purposes of your application or making any hiring decisions. You can find more information about how we process diversity and demographic information in our Applicant and Candidate Privacy Notice .
If you have any questions about the form contact us: .
Is the gender you identify with the same as your gender registered at birth? Select…
What is your ethnicity? (Ethnic origin is not about nationality, place of birth or citizenship. It is about the group to which you perceive you belong.) Select…
#J-18808-Ljbffr
InfoSec Risk and Governance Lead, London New London employer: Isomorphic Labs Limited
Contact Detail:
Isomorphic Labs Limited Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land InfoSec Risk and Governance Lead, London New London
✨Tip Number 1
Familiarise yourself with the latest trends in information security and compliance, especially those relevant to the life sciences and AI sectors. This knowledge will not only help you during interviews but also demonstrate your commitment to staying updated in a rapidly evolving field.
✨Tip Number 2
Network with professionals in the InfoSec community, particularly those who have experience in risk management and governance within the life sciences or AI industries. Attend relevant conferences or webinars to make connections that could lead to valuable insights or referrals.
✨Tip Number 3
Prepare to discuss specific examples of how you've successfully managed risk in previous roles. Be ready to explain your approach to aligning security strategies with business objectives, as this is crucial for the role at Isomorphic Labs.
✨Tip Number 4
Showcase your understanding of ISO 27001 and other relevant compliance frameworks by discussing how you've implemented or maintained these standards in past positions. This will highlight your practical experience and readiness to take on the responsibilities of the role.
We think you need these skills to ace InfoSec Risk and Governance Lead, London New London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in information security, risk management, and governance. Use keywords from the job description to demonstrate that you meet the specific requirements of the InfoSec Risk and Governance Lead position.
Craft a Compelling Cover Letter: Write a cover letter that not only outlines your qualifications but also reflects your understanding of Isomorphic Labs' mission and values. Explain how your skills can contribute to their goal of advancing human health through AI-driven drug discovery.
Showcase Relevant Skills: In your application, emphasise your knowledge of security and compliance standards such as ISO 27001 and GDPR. Provide examples of how you've successfully managed risk in previous roles, particularly in complex environments like life sciences or AI.
Highlight Collaborative Experience: Since the role involves partnering with various teams, mention any past experiences where you collaborated across departments. This could include working with tech, legal, or medical research teams to implement security frameworks or data governance strategies.
How to prepare for a job interview at Isomorphic Labs Limited
✨Understand the Regulatory Landscape
Familiarise yourself with key regulations such as ISO 27001, GDPR, and the EU AI Act. Be prepared to discuss how these regulations impact information security and risk management in the context of drug discovery and AI.
✨Showcase Your Technical Knowledge
Demonstrate your understanding of cybersecurity principles, especially in cloud and machine learning environments. Be ready to explain how you would approach risk identification and mitigation in these areas.
✨Emphasise Collaboration Skills
Highlight your experience working with cross-functional teams, particularly in tech, legal, and medical research. Discuss how you can foster a culture of security accountability and drive collaborative initiatives.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think about past experiences where you successfully managed risks or implemented compliance frameworks, and be ready to share those stories.