Senior Security Specialist - Risk & Compliance New London
Senior Security Specialist - Risk & Compliance New London

Senior Security Specialist - Risk & Compliance New London

London Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Isomorphic Labs Limited

At a Glance

  • Tasks: Lead security risk management for third-party partnerships and enhance our information security management system.
  • Company: Innovative life sciences company focused on drug discovery and clinical operations.
  • Benefits: Hybrid work model, competitive salary, and opportunities for professional growth.
  • Other info: Collaborative environment with a focus on knowledge sharing and relationship building.
  • Why this job: Make a real impact in securing vital partnerships and advancing healthcare innovation.
  • Qualifications: Strong risk management skills and knowledge of cybersecurity standards required.

The predicted salary is between 60000 - 80000 £ per year.

Your impact

As a Senior InfoSec Specialist, you will be a cornerstone of our Governance Risk and Compliance (GRC) function, with a primary focus on securing our supply chain and third-party ecosystem. Reporting to the InfoSec Risk and Governance Lead, you will ensure that our innovative partnerships - from SaaS providers to Clinical Research Organisations (CROs) - meet our security standards. You will also play a key role in enhancing our ISMS and supporting secure business operations, including our drug discovery and clinical activities. Your work directly protects our organisation and ensures the right balance between business objectives and security is sustained.

What you will do

  • Coordinate the third party security risk management lifecycle: execute the end-to-end third-party risk process, including initial intake, technical due diligence, risk-based tiering, ongoing monitoring, secure offboarding, and liaising with Legal and Finance teams.
  • Perform detailed vendor assurance activities commensurate with their risk profile, ensuring alignment with legal, regulatory, contractual and policy requirements.
  • Continuously develop and refine assessment methodologies to evaluate and audit vendors.
  • Promote operational efficiency by building and maintaining third party security risk management dashboards and automating evidence collection to provide real-time visibility into the vendor risk landscape.
  • Provide expert guidance to medicinal and ML research colleagues on complex risk topics, translating technical issues into clear business impact statements.
  • Support the InfoSec Risk and Governance Lead in improving and maintaining the Isomorphic Labs ISMS and other regulated and contractual data assurance requirements, including internal audit execution and control testing.
  • Develop a unified GRC framework able to provide internal and external assurance for all relevant legal, regulatory, contractual and policy requirements.
  • Coordinate, author and maintain security policies and processes, ensuring they reflect reality as well as meeting our legal, regulatory, and contractual requirements.
  • Support the development of secure, lean pharma and clinical operations with an AI-first approach.

Skills and qualifications

  • Capacity to prioritise critical inquiry over rote compliance - you must be able to critically think through risks and issues and provide timely, accurate and enabling advice suitable to the business.
  • Ability to excel as an individual contributor with the agility and adaptability to quickly pivot between strategic to operational levels, and between widely differing contexts.
  • Strong understanding of risk management with a proven ability to manage the full risk management lifecycle, from technical risk identification and analysis to presenting clear, business-focused mitigation options.
  • Robust knowledge of information technology and cybersecurity, including cloud and ML-based environments.
  • Experience leading internal and external assurance activities.
  • Knowledge of relevant security and compliance standards (e.g. ISO 27001, NIST).
  • Experience managing the security threats posed by a complex third-party ecosystem, including cloud providers.
  • Demonstrated experience in life sciences, technology, or AI industries.
  • Open-minded and innovative approach in meeting regulatory requirements, balancing compliance with the efficiency demands of ML-driven drug discovery.
  • A natural ability to build credibility and influence decision-making across scientific, engineering, corporate and leadership functions to drive the security agenda forward.

Nice to have:

  • A deep experience of the Pharma Industry and Drug Development process and ecosystem is a plus.
  • Experience in threat modelling.
  • Interest in / experience of GRC engineering.
  • Interest in / experience of Cyber Risk Quantification.
  • Familiarity with AI-specific threats and security controls, such as those addressing model inversion, data poisoning, or adversarial attacks.
  • Experience automating evidence collection and control monitoring.
  • Contribution to open-source security projects or participation in security communities.

It’s hugely important for us to share knowledge and build strong relationships with each other, and we find it easier to do this if we spend time together in person. This is why we follow a hybrid model, and would require you to be able to come into the office 3 days a week (currently Tuesday, Wednesday, and one other day depending on which team you’re in). If you have additional needs that would prevent you from following this hybrid approach, we’d be happy to talk through these if you’re selected for an initial screening call.

We are committed to equal employment opportunities regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy or related condition (including breastfeeding) or any other basis protected by applicable law. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.

Senior Security Specialist - Risk & Compliance New London employer: Isomorphic Labs Limited

As a Senior Security Specialist at our London office, you will join a dynamic and innovative team dedicated to securing our supply chain and third-party ecosystem. We foster a collaborative work culture that prioritises knowledge sharing and personal growth, offering opportunities for professional development in the rapidly evolving fields of life sciences and AI. With a commitment to diversity and inclusion, we ensure a supportive environment where your contributions are valued and your career can thrive.
Isomorphic Labs Limited

Contact Detail:

Isomorphic Labs Limited Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Security Specialist - Risk & Compliance New London

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their security needs and be ready to discuss how your skills align with their goals. Tailor your responses to show you’re the perfect fit for their team.

✨Tip Number 3

Practice makes perfect! Conduct mock interviews with friends or use online platforms to get comfortable with common questions. The more you practice, the more confident you'll feel when it’s time to shine.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are genuinely interested in joining our team.

We think you need these skills to ace Senior Security Specialist - Risk & Compliance New London

Governance Risk and Compliance (GRC)
Third-Party Risk Management
Vendor Assurance Activities
Risk Management Lifecycle
Information Technology Knowledge
Cybersecurity Expertise
ISO 27001
NIST Standards
Cloud Security
Machine Learning Environments
Internal and External Assurance Activities
Regulatory Compliance
Communication Skills
Adaptability
Influencing Decision-Making

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter for the Senior Security Specialist role. Highlight your experience in risk management and compliance, and how it aligns with our needs at StudySmarter.

Showcase Your Skills: Don’t just list your skills; demonstrate them! Use specific examples from your past work that showcase your ability to manage third-party risks and enhance security frameworks.

Be Clear and Concise: Keep your application straightforward and to the point. We appreciate clarity, so make sure your writing is easy to read and free of jargon unless necessary.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role without any hiccups!

How to prepare for a job interview at Isomorphic Labs Limited

✨Know Your GRC Inside Out

Make sure you understand the Governance Risk and Compliance (GRC) landscape thoroughly. Brush up on relevant standards like ISO 27001 and NIST, and be ready to discuss how they apply to third-party risk management. This will show that you're not just familiar with the concepts but can also apply them in real-world scenarios.

✨Showcase Your Problem-Solving Skills

Prepare to discuss specific examples where you've identified risks and provided effective mitigation strategies. Use the STAR method (Situation, Task, Action, Result) to structure your answers. This will demonstrate your ability to think critically and provide timely, business-focused advice.

✨Familiarise Yourself with the Company’s Ecosystem

Research the company’s partnerships and the types of vendors they work with. Understanding their supply chain and third-party ecosystem will help you tailor your responses and show that you're genuinely interested in how you can contribute to their security objectives.

✨Prepare for Technical Questions

Expect questions about technical risk identification and analysis, especially in cloud and ML environments. Brush up on your knowledge of threat modelling and AI-specific security controls. Being able to translate complex technical issues into clear business impacts will set you apart from other candidates.

Senior Security Specialist - Risk & Compliance New London
Isomorphic Labs Limited
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>