Chief Information Security Officer
- Develop and implement a global information security strategy aligned with business goals and regulatory requirements
- Establish and maintain enterprise-wide security policies, standards, and procedures.
- Lead the information security governance, risk management, including responsibility for audit readiness and post-assessment remediation plans, especially for ISO 27001 and 42001 gaps
- Define and report on key security metrics (e.g., incident response times, vulnerability remediation SLAs, phishing simulation results) to executive leadership and the board
- Lead the development and enforcement of cloud security strategies across Microsoft 365, Azure, AWS, and other SaaS platforms with emphasis on configuration management, monitoring, and incident detection/remediation in cloud environments
- Foster a security-first culture by engaging business leaders and department heads in regular security briefings and risk discussions.
- Lead threat detection, prevention, and response capabilities, including Security Operations Center (SOC) oversight.
- Ensure the timely investigation, response, and remediation of security incidents and breaches.
- Establish and document a framework-aligned, business-integrated security ecosystem for Trinity and enable mechanisms to showcase it to customers on a need basis.
- Lead data protection efforts across Trinity SaaS, Product and Internal environments , including cloud-native services and large-scale repositories .
- Integrate security practices into the full software development lifecycle, including secure architecture, code review, automated testing for vulnerabilities, and DevSecOps principles.
- Collaborate with IT and Product teams to ensure security controls are embedded from project initiation through deployment.
- Oversee the security review process for third-party vendors, cloud providers, and partners.
- Ensure supply chain security and resilience.
- Oversee the design and implementation of technical safeguards including access control, encryption, patch management, and threat detection systems
- Manage the cybersecurity team, including security engineers, analysts, and external vendors (e.g., Managed SOC services)
- Direct incident response planning and execution, including breach investigations and reporting
- Ensure secure configuration and monitoring of cloud-native services, including identity, access, and data protection controls
- Oversee data governance and protection strategies for large-scale data repositories, including SharePoint Online, OneDrive, and Teams
- Orchestrate regular security audits in SaaS ecosystems, to proactively identify vulnerabilities.
- Collaborate with international teams to maintain consistent security posture and incident response readiness globally
- Champion regular security audits and continuous improvement cycles, with a focus on cloud ecosystem vulnerabilities such as drift in Microsoft 365, AWS, Azure, among others.
- Work directly with General Counsel and Compliance group to ensure compliance with HIPAA, GDPR, NIST CSF, SOC 2, ISO 27001 and ISO 42001and other global data protection regulations relevant to pharmaceutical consulting
- Conduct regular risk assessments based on NIST RMF and develop mitigation plans
- Lead external security audits and accreditation surveys
- Ensure security practices are adapted to regional regulatory requirements and cultural contexts across North America, Europe, and Asia.
- Champion a culture of security awareness across the organization specifically with development teams
- Develop and deliver training programs tailored to different roles and regions
- Demonstrated ability to communicate complex security concepts to the board, non-technical stakeholders, and external customers in plain, persuasive language.
- Evaluate and implement emerging security technologies (e.g., CASB, PAM, GRC tools)
- Align security architecture with frameworks such as NIST CSF, CIS 18, and OWASP
- Work Experience: 10+
- Experience in pharmaceutical, healthcare, or consulting industries preferred
- Certifications such as CISSP, CISM, CEH, GSEC, ECSA, Security+ or CISA strongly preferred
- Proven ability to lead cross-functional teams and manage global security operations
- Strategic thinking and business acumen
- Strong communication and stakeholder engagement skills with demonstrated record of translating technical content for business adoption
- Experience with vendor management and contract negotiation
- Familiarity with cloud security, application security, and data loss prevention
- Understanding of modern threats and exploits
- Ability to understand and communicate attack chains to management and key stakeholders
- Develop, execute and track the performance of security measures to protect information and network infrastructure and computer systems
- Identify, define and document system security requirements and recommend solutions to management
- Identify and document security requirements and recommend solutions to management
- Ownership of remediation activities for ISO and other regulatory gaps.
- Experience managing or working with Managed Security Service Providers (MSSPs) and Security Operations Centers (SOCs).
- Familiarity with Zero Trust architecture and identity-centric security models.
Recommended Jobs
REGISTERED NURSE
Job Description Job Description looking for a nurse to work for an ADULT FOSTER CARE facility. job description: not a bed side nurse, will not get in contact directly with patients mostly pape…
Scientific Research Intern (part-time)
At BioAgilytix, we are passionate about premier science and the impact it has on our world. Our team of highly experienced scientists and professionals deliver tailored services for supporting new med…
Test Engineer I
Summary/Objective The Test Engineer I is responsible for maintenance, calibration, fixture development and installation of test equipment, including work-cell layout, product flow optimizatio…
Carpenter Assistant
Job Description Job Description Looking for part time with potential for full time carpenter’s helper or lead carpenter for work in Massachusetts and southern New Hampshire. Types of work include…
Get cash for taking surveys
Becoming a survey responder with YouGov presents an opportunity to express opinions on a wide range of topics, playing a role in shaping public discourse and influencing decision-making processes.In …
Join Our Team in Beautiful Cape Cod's ER!
Registered Nurse - Emergency Room - Travel - (ER RN) Join our dedicated team of Emergency Room nurses at Falmouth, Cape Cod, where your expertise and compassion can make a significant impact on patie…
Manufacturing Process Engineer
At Rodney Hunt, we are problem-solvers, focused on a common purpose: solving flow control challenges of the water & wastewater industry. As a global technology and engineering leader, we provide solut…
Sales Manager- Toyota (Haverhill, MA)
Responsibilities * Coach sales team on proper closing techniques through training and active participation * Manage all showroom activities for a large sales team * Spend time with customers to deter…
Full Time Family Medicine Job Boston, MA
Excellent opportunity for a Family Practice or Internal Medicine Physician to work in an outpatient clinic with a large medical group in the Northern Boston, MA area. ~ Board Certified or Board Eli…
Sr Process Engineer - Injection Molding
Job Description Job Description Title: Sr Process Engineer Location: Danvers, MA US 01923 Top 3 technical skills that are required for the role: # Injection Molding Process development …