Senior Security Specialist - Risk & Compliance in London

Senior Security Specialist - Risk & Compliance in London

London Full-Time 60000 - 80000 € / year (est.) Home office (partial)
Isomorphic Labs Limited

At a Glance

  • Tasks: Lead security risk management for third-party partnerships and enhance our information security management system.
  • Company: Join Isomorphic Labs, a pioneering company in AI-driven drug discovery.
  • Benefits: Enjoy hybrid working, competitive salary, and a commitment to diversity and inclusion.
  • Other info: Collaborative environment with opportunities for professional growth in the life sciences sector.
  • Why this job: Make a real impact on health by securing innovative drug discovery processes.
  • Qualifications: Strong risk management skills and knowledge of cybersecurity standards required.

The predicted salary is between 60000 - 80000 € per year.

About Iso

Isomorphic Labs (IsoLabs) was launched in 2021 to advance human health by building on and beyond the Nobel-winning AlphaFold system. Our interdisciplinary team of drug discovery experts and machine learning specialists has built powerful new predictive and generative AI models that accelerate scientific discovery at digital speed. We believe a symmetry exists between biology and information science, and we harness AI to model complex biological phenomena, design novel molecules, anticipate drug performance, and develop innovative medicines.

Your impact

As a Senior InfoSec Specialist, you will be a cornerstone of our Governance Risk and Compliance (GRC) function, primarily focused on securing our supply chain and third-party ecosystem. Reporting to the InfoSec Risk and Governance Lead, you will ensure that our partnerships—from SaaS providers to Clinical Research Organisations—meet our security standards. You will also play a key role in enhancing our ISMS and supporting secure business operations, including drug discovery and clinical activities.

What You Will Do

  • Coordinate the third-party security risk management lifecycle: execute the end-to-end third-party risk process, including initial intake, technical due diligence, risk-based tiering, ongoing monitoring, secure offboarding, and liaising with Legal and Finance teams.
  • Perform detailed vendor assurance activities commensurate with their risk profile, ensuring alignment with legal, regulatory, contractual and policy requirements.
  • Continuously develop and refine assessment methodologies to evaluate and audit vendors.
  • Promote operational efficiency by building and maintaining third-party security risk management dashboards and automating evidence collection to provide real-time visibility into the vendor risk landscape.
  • Provide expert guidance to medicinal and ML research colleagues on complex risk topics, translating technical issues into clear business impact statements.
  • Support the InfoSec Risk and Governance Lead in improving and maintaining the Isomorphic Labs ISMS and other regulated and contractual data assurance requirements, including internal audit execution and control testing.
  • Develop a unified GRC framework able to provide internal and external assurance for all relevant legal, regulatory, contractual and policy requirements.
  • Coordinate, author and maintain security policies and processes, ensuring they reflect reality as well as meeting our legal, regulatory, and contractual requirements.
  • Support the development of secure, lean pharma and clinical operations with an AI-first approach.

Skills And Qualifications

Essential

  • Capacity to prioritise critical inquiry over rote compliance—critical thinking through risks and issues and providing timely, accurate and enabling advice suitable to the business.
  • Ability to excel as an individual contributor with agility and adaptability to pivot quickly between strategic and operational levels.
  • Strong understanding of risk management with a proven ability to manage the full risk management lifecycle, from technical risk identification and analysis to presenting clear, business-focused mitigation options.
  • Robust knowledge of information technology and cybersecurity, including cloud and ML-based environments.
  • Experience leading internal and external assurance activities.
  • Knowledge of relevant security and compliance standards (e.g., ISO 27001, NIST).
  • Experience managing the security threats posed by a complex third-party ecosystem, including cloud providers.
  • Demonstrated experience in life sciences, technology, or AI industries.
  • Open-minded and innovative approach in meeting regulatory requirements, balancing compliance with the efficiency demands of ML-driven drug discovery.
  • A natural ability to build credibility and influence decision-making across scientific, engineering, corporate and leadership functions to drive the security agenda forward.

Nice to have

  • Deep experience of the Pharma industry and Drug Development process and ecosystem.
  • Experience in threat modelling.
  • Interest in or experience of GRC engineering.
  • Interest in or experience of Cyber Risk Quantification.
  • Familiarity with AI-specific threats and security controls, such as those addressing model inversion, data poisoning, or adversarial attacks.
  • Relevant certifications (e.g., CISA, CISSP).
  • Experience automating evidence collection and control monitoring.
  • Contribution to open-source security projects or participation in security communities.

Hybrid working

We follow a hybrid model and would require you to be able to come into the office three days a week (currently Tuesday, Wednesday, and one other day depending on the team). If you have additional needs that would prevent you from following this hybrid approach, we would be happy to discuss alternatives if you are selected for an initial screening call.

Equal Employment Opportunity

We are committed to equal employment opportunities regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy or related condition (including breastfeeding) or any other basis protected by applicable law. If you have a disability or additional need that requires accommodation, please let us know.

Senior Security Specialist - Risk & Compliance in London employer: Isomorphic Labs Limited

Isomorphic Labs is an exceptional employer that fosters a collaborative and innovative work culture, where employees are empowered to make significant contributions to advancing human health through cutting-edge AI technology. With a strong focus on employee growth, we offer opportunities for professional development in a dynamic environment that values critical thinking and creativity. Our hybrid working model promotes work-life balance, while our commitment to diversity and inclusion ensures that every team member feels valued and supported.

Isomorphic Labs Limited

Contact Detail:

Isomorphic Labs Limited Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Security Specialist - Risk & Compliance in London

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend relevant meetups or webinars, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their mission and values, especially how they relate to risk and compliance in the pharma sector. This will help you tailor your responses and show you're genuinely interested.

Tip Number 3

Practice your pitch! Be ready to explain your experience and how it aligns with the role of a Senior Security Specialist. Focus on your critical thinking skills and how you've tackled risk management challenges in the past.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who take that extra step to engage with us directly.

We think you need these skills to ace Senior Security Specialist - Risk & Compliance in London

Risk Management
Third-Party Risk Management
Vendor Assurance
Information Technology
Cybersecurity
ISO 27001
NIST

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Senior Security Specialist role. Highlight your experience in risk management and compliance, especially in relation to third-party ecosystems. We want to see how your skills align with our needs!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about the role and how your background in InfoSec can contribute to our mission at IsoLabs. Keep it engaging and relevant to the job description.

Showcase Your Achievements:When detailing your experience, focus on specific achievements that demonstrate your ability to manage risks and enhance security protocols. Numbers and outcomes speak volumes, so don’t shy away from quantifying your successes!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team at IsoLabs!

How to prepare for a job interview at Isomorphic Labs Limited

Know Your Risk Management Lifecycle

Make sure you understand the full risk management lifecycle, especially how it applies to third-party security. Be ready to discuss your experience with technical due diligence and ongoing monitoring, as these are key aspects of the role.

Showcase Your Technical Knowledge

Brush up on your knowledge of information technology and cybersecurity, particularly in cloud and ML-based environments. Be prepared to explain how you've managed security threats in complex ecosystems, as this will demonstrate your expertise.

Prepare for Scenario-Based Questions

Expect scenario-based questions that assess your critical thinking and problem-solving skills. Think of examples where you've had to balance compliance with operational efficiency, and be ready to articulate your thought process clearly.

Demonstrate Your Communication Skills

Since you'll need to translate complex risk topics into clear business impact statements, practice explaining technical issues in simple terms. This will show your ability to influence decision-making across various functions within the company.