About the job
At OneStudyTeam (a Reify Health company), we are dedicated to accelerating clinical trials and enhancing the likelihood of new therapies receiving approval, ultimately aiming to improve patient outcomes. Our cloud-based platform, StudyTeam, digitizes research site workflows, allowing sites, sponsors, and critical stakeholders to collaborate more efficiently. Trusted by the largest global biopharmaceutical companies, StudyTeam is utilized in over 6,000 research sites across more than 100 countries. Join us in our mission to propel clinical research forward and elevate patient care.
One mission. One team. That’s OneStudyTeam.
The Director of Security spearheads the enterprise security strategy and implementation, encompassing governance, risk management, compliance, and security engineering. This leadership role oversees the GRC and Security Engineering teams, collaborates with technology and business leaders, and ensures the development and management of secure systems and processes throughout the organization.
The Director is responsible for program maturity, readiness for audits, and ongoing enhancement. Responsibilities include managing third-party risks, vendor assessments and qualifications, overseeing security architecture, providing guidance on AI-related security assessments, leading incident response efforts, and managing the budget for security initiatives.
This position is a hands-on, technical leadership role with a high level of autonomy that combines strategic program management with practical execution. The Director will create roadmaps and metrics, allocate resources, and align efforts with business goals and regulatory requirements.
Key Responsibilities:
- Lead and manage the GRC and Security Engineering teams, setting strategy, objectives, staffing, coaching, and performance evaluation.
- Oversee governance, risk, and compliance programs. Ensure ISO 27001 compliance and drive audit readiness for HIPAA and other frameworks. Manage policy lifecycle and control testing.
- Implement a vendor assessment and qualification program. Manage third-party risk, due diligence, contractual security requirements, and ongoing monitoring.
- Provide assessments and guidance related to AI security. Establish acceptable use guidelines for AI, evaluate model and data risks, and recommend controls for AI-enabled solutions.
- Oversee security architecture for cloud environments and enterprise platforms. Collaborate with engineering teams for secure design in AWS, Azure, identity management, network, and data protection.
- Direct security engineering operations.

