At a Glance
- Tasks: Lead security governance and compliance initiatives, ensuring robust data protection and risk management.
- Company: Join Isomorphic Labs, a pioneer in AI-driven drug discovery focused on advancing human health.
- Benefits: Enjoy a hybrid work model, collaborative culture, and opportunities for professional growth.
- Why this job: Make a real impact in healthcare while fostering a strong security culture in a dynamic environment.
- Qualifications: Strong IT background, experience with security policies, and excellent communication skills required.
- Other info: Work in a supportive team that values diversity and encourages innovative thinking.
The predicted salary is between 43200 - 72000 £ per year.
We are here to advance human health, by reimagining drug discovery with the power and pace of artificial intelligence. As a Senior Security Engineer - GRC, you will play a crucial role in establishing and maintaining a robust security governance framework at Isomorphic Labs. Your work will be instrumental in ensuring the organisation's compliance with industry standards and regulations, enabling research programs and building trust with key partners.
Your impact
You will contribute to fostering a culture of security awareness and operational excellence, directly impacting the company's ability to achieve its ambitious goals.
What you will do
- Spearhead the development of IsoLabs' Information Security Management System (ISMS) and guide the organisation through ISO 27001 certifications.
- Implement and continuously improve security policies and technical controls, ensuring alignment with industry best practices and operational excellence.
- Monitor and maintain compliance with regulations, third-party requirements, and internal security policies, identifying and proactively addressing potential gaps.
- Partner with TechOps, Data Engineering, Legal and Product teams to implement robust data governance solutions, encompassing data labelling, access control, audit trails, de-identification, and data lifecycle management.
- Lead Infosec projects in collaboration with Machine Learning and Drug Discovery teams.
- Develop and execute internal audit programs, and effectively respond to external audits and due diligence requests.
- Leverage your technical knowledge to define risk management plans, secure vendor solutions and meet third party requirements.
- Actively contribute to IsoLabs’ security awareness program, fostering a strong security culture throughout the organisation.
- Manage Vendor Security Assessment operations and drive continuous improvement of these processes.
- Support the implementation and enhancement of Incident Management and Vulnerability Management policies.
- Partner with Legal and Privacy teams to ensure security practices align with legal and regulatory requirements, particularly concerning data privacy and protection.
- Establish and report on Key Performance Indicators (KPIs) to demonstrate the effectiveness of security operations on business outcomes.
Skills and qualifications
- Strong IT and cybersecurity technical background, including experiences with major cloud platforms.
- Demonstrated experience developing and implementing security policies, standards, and procedures.
- Solid understanding of risk management frameworks, and industry-specific compliance requirements (e.g., ISO/IEC 27001, GDPR, HITRUST).
- Excellent communication and interpersonal skills, with the ability to explain complex security concepts to diverse audiences.
- Practical experience with data governance and privacy controls, including data classification, audit trail, de-identification and data lifecycle management.
- Strong analytical and problem-solving skills, with the ability to differentiate true risks from over-compliance, develop creative solutions to balance business needs with risk mitigation.
- Extensive experience with external audits and leading certification processes.
- Proven ability to act as a project manager and collaborate effectively with cross-functional teams.
- Demonstrated ability to effectively manage and prioritise multiple projects simultaneously, meeting deadlines and delivering results.
Nice to have:
- Experience building and operating a Trusted Research Environment and/or Trusted ML Environments.
- Experience in the BioTech and Pharma industry.
- Experience streamlining Vendor Security Assessments (VSAs).
- Familiarity with the unique challenges of a fast-paced, high-growth environment.
- Solid understanding of security in a computational- and AI-first environment.
- Experience protecting sensitive scientific and personal data.
- Experience with security automation tools and technologies.
- Contribution to open-source security projects or participation in security communities.
Culture and values
We are guided by our shared values. It’s not about finding people who think and act in the same way. These values help to guide our work and will continue to strengthen it.
- Thoughtful: Thoughtful at Iso is about curiosity, creativity and care. It is about good people doing good, rigorous and future-making science every single day.
- Brave: Brave at Iso is about fearlessness, but it’s also about initiative and integrity. The scale of the challenge demands nothing less.
- Determined: Determined at Iso is the way we pursue our goal. It’s a confidence in our hypothesis, as well as the urgency and agility needed to deliver on it. Because disease won’t wait, so neither should we.
- Together: Together at Iso is about connection, collaboration across fields and catalytic relationships. It’s knowing that transformation is a group project, and remembering that what we’re doing will have a real impact on real people everywhere.
Creating an extraordinary company
We believe that to be successful we need a team with a range of skills and talents. We're building an environment where collaboration is fundamental, learning is shared and every employee feels supported and able to thrive. We value unique experiences, knowledge, backgrounds, and perspectives, and harness these qualities to create extraordinary impact.
We are committed to equal employment opportunities regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy or related condition (including breastfeeding) or any other basis protected by applicable law.
It’s hugely important for us to share knowledge and build strong relationships with each other, and we find it easier to do this if we spend time together in person. This is why we follow a hybrid model, and would require you to be able to come into the office 3 days a week (currently Tuesday, Wednesday, and one other day depending on which team you’re in).
Security Engineer - Governance, Risk and Compliance (GRC), London, Lausanne Lausanne employer: Isomorphic Labs Limited
Contact Detail:
Isomorphic Labs Limited Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Engineer - Governance, Risk and Compliance (GRC), London, Lausanne Lausanne
✨Tip Number 1
Familiarise yourself with ISO 27001 and other relevant compliance frameworks. Understanding these standards will not only help you in interviews but also demonstrate your commitment to the role and its responsibilities.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who have experience in governance, risk, and compliance. Engaging with industry peers can provide insights into the role and may even lead to referrals.
✨Tip Number 3
Stay updated on the latest trends and challenges in data governance and security, particularly in the biotech and pharma sectors. This knowledge will allow you to speak confidently about current issues during interviews.
✨Tip Number 4
Prepare to discuss your experience with cross-functional collaboration. Highlight specific projects where you've worked with teams like TechOps or Legal, as this is crucial for the role at IsoLabs.
We think you need these skills to ace Security Engineer - Governance, Risk and Compliance (GRC), London, Lausanne Lausanne
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity, risk management, and compliance. Use keywords from the job description to demonstrate that you meet the specific requirements for the Security Engineer role.
Craft a Compelling Cover Letter: In your cover letter, explain why you're passionate about security governance and how your background aligns with the company's mission. Mention specific projects or experiences that showcase your skills in developing security policies and managing compliance.
Showcase Technical Skills: Clearly outline your technical expertise, especially with major cloud platforms and security frameworks like ISO/IEC 27001 and GDPR. Provide examples of how you've implemented security measures or led audits in previous roles.
Demonstrate Soft Skills: Highlight your communication and interpersonal skills, as these are crucial for collaborating with cross-functional teams. Provide examples of how you've effectively communicated complex security concepts to diverse audiences.
How to prepare for a job interview at Isomorphic Labs Limited
✨Understand the GRC Landscape
Familiarise yourself with Governance, Risk, and Compliance frameworks, especially ISO 27001 and GDPR. Be prepared to discuss how these frameworks apply to the role and how you can contribute to maintaining compliance within the organisation.
✨Showcase Your Technical Skills
Highlight your experience with cloud platforms and security automation tools. Be ready to provide examples of how you've implemented security policies and technical controls in previous roles, demonstrating your ability to align with industry best practices.
✨Communicate Effectively
Prepare to explain complex security concepts in simple terms. The interviewers will be looking for your ability to communicate with diverse teams, so practice articulating your thoughts clearly and confidently.
✨Demonstrate Problem-Solving Abilities
Be ready to discuss specific challenges you've faced in risk management or compliance and how you approached them. Show your analytical skills by explaining how you differentiate between true risks and over-compliance, and share creative solutions you've developed.