drjobs InfoSec Risk and Governance Lead, London

InfoSec Risk and Governance Lead, London

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

London - UK

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

InfoSec Risk and Governance Lead London

We are here to advance human health by reimagining drug discovery with the power and pace of artificial intelligence.

The future is coming. A future enabled and enriched by the incredible power of machine learning. A future in which diseases are curtailed or cured by better and faster drug discovery.

Our values exist in service of that future. We think theyll help us bring it closer too.

Come and be part of an interdisciplinary team driving groundbreaking innovation and play a meaningful role in contributing towards us achieving our ambitious goals while being a part of an inspiring and collaborative culture.

The world we want tomorrow is the one were building today. It starts with the culture at this company. It starts with you.

About Iso

Isomorphic Labs (IsoLabs) was founded in 2021 and is led by Sir Demis Hassabis. Our aim is to usher in a new era of biomedical breakthroughs and find cures for some of humanitys devastating diseases.

Our foundations are built on the success of Google DeepMinds AlphaFold but we didnt stop there! We are continuing to develop and implement state-of-the-art technologies as we move towards our goal of dramatically accelerating and improving the process of designing and bringing new medicines to patients.

We have built a world-leading drug design engine comprising foundational AI models that are capable of working across multiple therapeutic areas and drug modalities. The company is continually innovating on model architecture and developing cutting-edge capabilities to advance rational drug design.

Your impact

As the Information Security Risk and Governance Lead you will architect and evolve our security governance framework underpinning our scientific breakthroughs. Directly reporting to the CISO your work will be critical in aligning our data management and security strategy with a complex regulatory landscape; enabling cutting-edge research programmes and reinforcing trust with partners. Your role will be instrumental in fostering a culture of security accountability and risk-informed decision-making and ultimately in enabling Isomorphic Labs mission to solve all disease.

What you will do

  • Architect and operationalise a unified compliance framework spanning Drug Discovery and Development AI and Cyber regulatory landscapes.
  • Own the strategic programme to achieve and maintain ISO 27001 certification for our Information Security Management System (ISMS).
  • Author and maintain our security policies and processes ensuring they are practical and effectively applied within our GxP-regulated and AI-first environment.
  • Lead information security-related risk management and deliver actionable reports to key stakeholders translating technical risks into business impact.
  • Combine robust technical knowledge and business operations expertise to craft tailored risk mitigation strategies.
  • Partner with Tech ML Legal and Medical Research Teams to implement a comprehensive data governance framework encompassing labelling audit trails and data lifecycle.
  • Oversee internal and external audit programs and drive continuous readiness for regulatory inspections and partner due diligence.
  • Lead engaging awareness and training programmes that foster a strong security culture throughout the organisation.
  • Own Third Party Risk Management including building an innovative approach to assess and manage risks from our critical AI cloud and research partners.
  • Establish and report on Key Performance Indicators (KPIs) to demonstrate the effectiveness of security operations on business outcomes.

Skills and qualifications

Essential:

  • Ability to excel as an individual contributor initially with the agility to pivot from strategic risk planning to direct collaborative implementation assistance.
  • Knowledge of security and compliance standards across InfoSec (e.g. ISO 27001 NIST HITRUST) life sciences (e.g. GxP 21 CFR) emerging AI regulation (e.g. EU AI Act) and privacy domains (GDPR HIPAA).
  • Demonstrated experience leading multifaceted certification programs and responding to external audits.
  • Robust knowledge of information technology and cybersecurity including cloud and ML-based environments.
  • Proven ability to manage the full risk management lifecycle from technical risk identification and analysis to presenting clear business-focused mitigation options.
  • Experience managing the security threats posed by a complex third-party ecosystem including cloud providers AI vendors and clinical research organisation partners (CROs).
  • Practical experience with data governance and privacy controls including data classification audit trail de-identification and data lifecycle management.
  • Demonstrated experience in either the life sciences or the AI industry with a strong grasp of domain-specific risks and regulatory challenges.
  • Open-minded and innovative approach in meeting regulatory requirements balancing compliance with the efficiency demands of ML-driven drug discovery.
  • A natural ability to build credibility and influence decision-making across scientific engineering corporate and leadership functions to drive the security agenda forward.

Nice to have:

  • Experience building and operating a Trusted Research Environment and/or Trusted ML Environments.
  • Familiarity with AI-specific threats and security controls such as those addressing model inversion data poisoning or adversarial attacks.
  • Relevant certifications (e.g. CISM CISA CISSP ISO 27001 Lead Implementer/Auditor).
  • Experience using modern GRC platforms (e.g. Vanta Drata) or scripting (e.g. Python) to automate evidence collection and control monitoring.
  • Contribution to open-source security projects or participation in security communities.


Culture and values

We are guided by our shared values. Its not about finding people who think and act in the same way. These values help to guide our work and will continue to strengthen it.

Thoughtful
Thoughtful at Iso is about curiosity creativity and care. It is about good people doing good rigorous and future-making science every single day.

Brave
Brave at Iso is about fearlessness but its also about initiative and integrity. The scale of the challenge demands nothing less.

Determined
Determined at Iso is the way we pursue our goal. Its a confidence in our hypothesis as well as the urgency and agility needed to deliver on it. Because disease wont wait so neither should we.

Together
Together at Iso is about connection collaboration across fields and catalytic relationships. Its knowing that transformation is a group project and remembering that what were doing will have a real impact on real people everywhere.


Creating an extraordinary company

We believe that to be successful we need a team with a range of skills and talents. Were building an environment where collaboration is fundamental learning is shared and every employee feels supported and able to thrive. We value unique experiences knowledge backgrounds and perspectives and harness these qualities to create extraordinary impact.

We are committed to equal employment opportunities regardless of sex race religion or belief ethnic or national origin disability age citizenship marital domestic or civil partnership status sexual orientation gender identity pregnancy or related condition (including breastfeeding) or any other basis protected by applicable law. If you have a disability or additional need that requires accommodation please do not hesitate to let us know.


Hybrid working

Its hugely important for us to share knowledge and build strong relationships with each other and we find it easier to do this if we spend time together in person. This is why we follow a hybrid model and would require you to be able to come into the office 3 days a week (currently Tuesday Wednesday and one other day depending on which team youre in). If you have additional needs that would prevent you from following this hybrid approach wed be happy to talk through these if youre selected for an initial screening call.

Please note that when you submit an application your data will be processed in line with our .


>> Click to view other open roles at Isomorphic Labs

Employment Type

Full Time

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.