Senior Manager, Information Security and Compliance

Parabilis MedicinesCambridge, MA
$165,000 - $195,000

About The Position

Parabilis Medicines, Inc. is seeking a hands-on, experienced Security and Compliance Senior Manager to join our lean and high-impact technology team. As a recently public company operating under SOX, GxP, HIPAA, and SOC2 frameworks, Parabilis relies on a strong security and compliance posture to protect its science, its data, and its patients. This role owns that posture in partnership with the Sr. Director of IT. Reporting to the Sr. Director of IT, this role is focused primarily on technical security, with compliance and quality integration as a constant second thread. You will implement and operate security controls, manage the vendors and consultants who support them, and work across every technical team to ensure they operate securely and within our established policies, procedures, and QA guidance. You will direct the work of MSP contractors, consultants, and vendor partners to deliver outcomes. This role is not just policy setting and enforcement. We are looking for someone who can be hands-on-keyboard for the activities that warrant it. The ideal candidate is a security practitioner who is equally comfortable configuring an endpoint detection platform, leading an incident response, and sitting with QA to make sure a change control workflow satisfies both a real threat model and an auditor.

Requirements

  • 6+ years of hands-on experience in technical security, ideally within regulated industries
  • Demonstrated experience operating within a regulated compliance environment (FDA/GxP, HIPAA, SOX, or SOC2), ideally in life sciences, healthcare, or another audited industry.
  • Hands-on expertise across endpoint security (EDR/MDR), identity and access management (Okta, Entra ID), and cloud security (AWS multi-account environments).
  • Practical experience implementing and operating security controls and mapping them to compliance frameworks and audit requirements.
  • Proven ability to lead incident response and manage security and compliance vendors and consultants to deliver outcomes.
  • Working knowledge of QA and change control practices in a regulated environment, and the judgment to make controls satisfy both security and compliance goals.
  • Comfort operating in a lean team: setting priorities independently, staying hands-on, and directing external partners without relying on direct reports.
  • Proficiency in scripting (PowerShell, Python, or equivalent) for automation and integration.
  • Exceptional communication skills and the ability to influence cross-functional teams without direct authority.

Nice To Haves

  • Bachelor’s degree in Computer Science, Information Systems, or related field preferred
  • CISA (compliance and audit focus) and/or CISSP (security focus) preferred

Responsibilities

  • Implement, configure, and operate security controls across endpoint, identity, network, and cloud, including endpoint detection and response, managed detection and response, and software and extension controls.
  • Own the endpoint security roadmap and drive execution across the environment, including migration off legacy tooling to a modern EDR/MDR stack.
  • Design and enforce identity and access controls across Okta, Entra ID, and connected systems, including least-privilege access, access recertification, and privileged access management.
  • Partner with Cloud Architecture to embed security into AWS multi-account infrastructure, including guardrails, network segmentation, logging, and posture management.
  • Serve as the technical lead for security tooling evaluations, proofs of concept, and rollouts, staying hands-on where depth is required.
  • Maintain intimate familiarity with Parabilis policies, SOPs, and QA guidance, and ensure all technical teams operate securely and within that framework.
  • Translate SOX ITGC, GxP, HIPAA, and SOC2 requirements into practical, enforceable technical controls and repeatable operating practices.
  • Partner with QA to align security controls with validated-system requirements, change control, and data integrity expectations.
  • Own control documentation, evidence collection, and traceability to support internal reviews and external audits, and act as a primary technical point of contact during audit activity.
  • Contribute to and enforce IT policy, working with the Sr. Director of IT to set standards and best practices across the organization.
  • Manage security and compliance vendors, MSP contractors, and specialist consultants, directing their work to deliver defined outcomes on schedule.
  • Own vendor risk assessment for new and existing technology partners, including privacy, data handling, and terms-of-service review in coordination with Legal and IT leadership.
  • Hold vendors accountable to SLAs, security commitments, and contractual obligations, and escalate where performance or risk warrants.
  • Own the security incident response process end to end, from detection and triage through containment, remediation, and post-incident review.
  • Respond to security incident reports, coordinate the technical response across internal teams and vendors, and drive incidents to closure with clear documentation.
  • Maintain and exercise incident response and business continuity runbooks, and feed lessons learned back into controls and policy.
  • Support regulatory, legal, and breach-notification obligations in coordination with IT leadership, QA, and Legal when incidents carry compliance impact.
  • Report to the Sr. Director of IT and work collaboratively with cross-functional teams across the organization to maintain the company's security and compliance posture across all systems.
  • Act as a trusted advisor to Engineering, Research, Clinical, and Enterprise teams, embedding secure and compliant practices into how they build and operate.
  • Communicate risk clearly to both technical and non-technical audiences, and advocate for pragmatic controls that enable the business rather than block it.

Benefits

  • annual target bonus
  • equity
  • comprehensive suite of competitive benefits designed to support our employees’ overall well-being
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service