Senior Director, Chief Information Security Officer
Cambridge, Massachusetts, United States · On-site
$245k–$325k/yr
Senior+$843M raised
Scholar Rock is a late-stage global biopharmaceutical company focused on developing and commercializing apitegromab for children and adults with spinal muscular atrophy (SMA) and other rare, severe, and debilitating neur…
The Role: As a Cybersecurity Engineer, you will help design, implement, and mature Moderna’s approach to API security across modern applications, platform services, and AI-enabled use cases. This role is primarily focuse…
Skills: API Security, Cybersecurity, Authentication, Authorization, Threat Modeling
Overview: Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful a…
Cambridge, Massachusetts, United States · Remote OK
$245k–$441k/yr
Senior$5.2B raised
Would you like to work in a dynamic sales-growth role? Do you love collaborating across teams to deliver customer success? Join our API Security Sales Team! We work with world leading companies in every major industry to…
Skills: Digital Cybersecurity, API Security, API Gateway, Cloud Service Providers, Inside Sales
Design, Process, and Software Quality Risk Specialist
Cambridge, Massachusetts, United States · On-site
$140k–$150k/yr
Mid level
About Axoft Axoft is building a new class of implantable neural interface—ultra-flexible, minimally reactive, and designed to remain functional for decades inside the human brain. Our software connects that hardware to t…
Skills: FMEA, Risk Management, Quality Management Systems, ISO 14971, Medical Device Software
Overview: Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful a…
Skills: System architecture, GN&C, Systems engineering, Team leadership, Performance management
When you join the growing BILH team, you're not just taking a job, you’re making a difference in people’s lives. Reporting to the Director of Quality & Patient Safety, the Quality and Patient Safety nurse specialist play…
Company Description By working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expertise…
Skills: Facilities management, Building operations, Budget management, Project management, Space planning
Cambridge, Massachusetts, United States · Remote OK
$121k–$219k/yr
Senior$5.2B raised
Do you want to shape how AI models are validated, optimized, and deployed at global scale? Are you passionate about building the systems that ensure AI models perform reliably and responsibly in production Join the Akama…
Senior Manager, Information Security and Compliance
Cambridge, Massachusetts, United States · On-site
$165k–$195k/yr
Senior$910M raised
About Parabilis Medicines At Parabilis Medicines, we are redefining what's possible in drug discovery. We are a clinical-stage biopharmaceutical company dedicated to creating unique and extraordinary medicines for patien…
Skills: Information Security, Compliance, SOX, GxP, HIPAA
Senior Manager, Non-Kinetic Capabilities Integration and Transition Lead
Cambridge, Massachusetts, United States · Hybrid
$132k–$252k/yr
Senior+$200K raised
Date Posted: 2026-08-05 Country: United States of America Location: US-MA-CAMBRIDGE-BBN06 ~ 10 & 50 Moulton St ~ MOULTON B6 Position Role Type: Hybrid U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active…
Skills: Strategic planning, Program management, Integration and testing, Electromagnetic warfare, Cybersecurity
When you join the growing BILH team, you're not just taking a job, you’re making a difference in people’s lives. Transports patients, charts, specimens, equipment and supplies appropriate to the Transport Department resp…
Overview Allied Universal®, North America’s leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace…
Skills: Security patrol, Risk prevention, Customer service, Incident response, Communication
Overview: Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful a…
Skills: System security, Cybersecurity architecture, Systems engineering, Hardware security, Software security
Company Description By working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expertise…
Skills: Fire safety systems, Supervision, Facilities maintenance, Standard operating protocols, Performance management
Title:Custodian Job Description: Job Overview The Custodian is responsible for the cleanliness and sanitation of all areas assigned. Roles & Responsibilities To perform this job successfully and safely, an individual mus…
Job TitleNon-Licensed Building Engineer Job Description SummaryResponsible to ensure the efficient operation and maintenance of mechanical, electrical and plumbing equipment and systems for the assigned property(s). Resp…
Skills: HVAC Maintenance, Plumbing, Electrical Systems, Preventive Maintenance, Energy Management
Site: The General Hospital Corporation Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As …
Site: The General Hospital Corporation Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As …
Skills: Low Voltage Systems, Access Control, CCTV, Intercom Systems, Alarm Systems
Company Description By working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expertise…
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
$245k–$325k/yr
Full-time
bachelor degree
Posted 32d ago
~40 hrs/week
Responsibilities
The Chief Information Security Officer will define and execute the enterprise cybersecurity strategy, roadmap, and governance frameworks to protect the company's data and technology assets. This role involves leading security operations, architecture, and compliance efforts while serving as a primary advisor to senior leadership and the Board of Directors.
Requirements
Candidates must possess a bachelor's degree and at least 12 years of progressive cybersecurity experience with a proven track record in leadership roles. A CISSP certification is required, along with deep expertise in cybersecurity architecture, risk management, and regulatory compliance within regulated environments.
Full job description
Scholar Rock is a late-stage global biopharmaceutical company focused on developing and commercializing apitegromab for children and adults with spinal muscular atrophy (SMA) and other rare, severe, and debilitating neuromuscular diseases. As a global leader in myostatin biology, a field focused on proteins that regulate muscle mass, the Company is named for the visual resemblance of a scholar rock to protein structures. Our commitment to unlock fundamentally different treatment approaches is powered by broad application of a proprietary platform, which has developed novel monoclonal antibodies to modulate protein growth factors with extraordinary selectivity. Scholar Rock works every day to create new possibilities for patients through its highly innovative anti-myostatin program, including opportunities in additional rare neuromuscular diseases. Learn more at ScholarRock.com and follow @ScholarRock on X and on LinkedIn.
Summary of Position:
Scholar Rock is seeking a Senior Director, Cybersecurity to serve as the company’s Chief Information Security Officer, responsible for building and scaling enterprise cybersecurity capabilities that protect the organization’s people, data, technology assets, intellectual property, and business operations.
Reporting to the CIO, this role defines and executes the cybersecurity strategy and roadmap in partnership with enterprise stakeholders across technology, Legal, Privacy, HR, Finance, Quality, and business functions.
The successful candidate combines strategic leadership with hands-on execution, with deep expertise across cybersecurity architecture, engineering, operations, governance, risk management, and compliance. This leader will build scalable, risk-based cybersecurity capabilities for a growing biotechnology company, balancing current operational needs with the maturity required to support commercial growth, regulatory readiness, and future organizational scale.
This role is ideal for a cybersecurity leader who has successfully led multiple cybersecurity functions and is ready to assume broader enterprise cybersecurity leadership responsibilities in a lean, high-growth biotechnology environment.
Position Responsibilities
\nCybersecurity Strategy & Program Leadership
Define and execute the enterprise cybersecurity strategy, roadmap, priorities, and operating model
Establish cybersecurity governance, policies, standards, and control frameworks aligned with business objectives and organizational growth
Prioritize cybersecurity maturity initiatives based on business risk, regulatory expectations, commercial growth, and organizational scale
Drive continuous improvement of cybersecurity capabilities and maturity across the organization
Serve as the primary cybersecurity advisor to the CIO, Board of Directors, and business leadership
Translate cybersecurity risks and opportunities into clear, actionable business recommendations
Security Architecture & Engineering
Own the cybersecurity target-state architecture and security technology roadmap
Lead cybersecurity architecture and engineering across cloud, infrastructure, identity, endpoint, network, application, SaaS, and data environments
Embed secure-by-design and risk-based security principles across enterprise initiatives and technology platforms
Partner with technology teams to integrate security requirements into solution design, implementation, and operational support models
Evaluate, select, and optimize cybersecurity technologies and services that support business and regulatory requirements
Security Operations & Cyber Resilience
Own security operations capabilities, including vulnerability management, incident response, security monitoring, identity security, and cyber resilience
Establish and mature detection, response, recovery, and continuous improvement capabilities
Lead cybersecurity incident response activities, executive communications, and post-incident reviews
Partner with technology teams and service providers to strengthen operational security capabilities and reduce enterprise risk
Support business continuity, disaster recovery, and cyber resilience planning in partnership with IT and business stakeholders
Governance, Risk & Compliance
Lead the enterprise cybersecurity governance, risk, and compliance program
Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Support SOX IT General Controls, user access governance, change management controls, and third-party risk management activities
Maintain alignment with the NIST Cybersecurity Framework and applicable regulatory requirements
Develop meaningful cybersecurity metrics, KPIs, KRIs, and executive reporting
Prepare cybersecurity risk, maturity, roadmap, and investment updates for senior leadership and audit committee discussions, as appropriate
Data Protection & Privacy
Lead cybersecurity capabilities to protect sensitive company data, intellectual property, clinical data, regulated information, and business-critical records
Partner with Legal, Privacy, Quality, Data & Analytics, and business stakeholders to support data governance, data classification, access controls, and security-related privacy requirements
Strengthen data protection capabilities across cloud, SaaS, endpoint, collaboration, and enterprise application environments
Support implementation of privacy-by-design and least privilege principles in alignment with regulatory and business requirements
Partner with Legal and Privacy on security considerations related to data protection, privacy obligations, vendor risk, and evolving regulatory expectations
Audit, Quality & Regulatory Readiness
Serve as the cybersecurity lead for internal audits, external audits, inspections, and cybersecurity assessments
Partner with Privacy, Legal, Quality, and IT stakeholders to ensure cybersecurity controls support compliance obligations
Ensure cybersecurity controls support GxP-regulated systems, Computer System Validation, and data integrity
Drive timely remediation of audit findings, observations, and control deficiencies
Vendor & Managed Service Leadership
Define and lead the cybersecurity operating model, leveraging internal teams, managed service providers, consultants, and strategic partners
Own strategic relationships with cybersecurity vendors, MSSPs, consultants, and external partners, including governance, performance management, and accountability
Establish service expectations, SLAs, KPIs, KRIs, operational metrics, and accountability mechanisms for third-party providers
Conduct operational and executive-level performance reviews to ensure cybersecurity services meet business, compliance, regulatory, and operational objectives
Partner with Procurement, Legal, Finance, and IT leadership on vendor selection, contract negotiations, renewals, investment decisions, and build vs. buy vs. outsource decisions
Executive Communication & Business Partnership
Develop and deliver cybersecurity strategy updates, risk assessments, roadmap reviews, audit results, and investment recommendations to senior leadership
Communicate cybersecurity risks and opportunities in clear business, operational, regulatory, and financial terms
Build trusted relationships across business and technology functions
Influence enterprise decision-making through practical, risk-based recommendations and effective stakeholder management
Serve as a pragmatic advisor who enables business growth while maintaining appropriate risk discipline
People Leadership
Lead, coach, mentor, and develop cybersecurity personnel and security-focused resources
Provide leadership across employees, contractors, consultants, and managed service providers
Foster a culture of accountability, continuous improvement, collaboration, and operational excellence
Help shape the future cybersecurity organization as the company continues to scale
Build a security culture that is practical, business-aligned, and appropriate for a growing commercial biotechnology company
Candidate Requirements
Bachelor’s degree in Information Security, Computer Science, Engineering, Information Technology, or a related discipline
12+ years of progressive cybersecurity experience with increasing leadership responsibilities
Experience building, implementing, or maturing enterprise cybersecurity programs and capabilities
Experience leading cybersecurity initiatives within regulated environments
Strong knowledge of the NIST Cybersecurity Framework, cybersecurity governance, risk management, and security control implementation
Experience supporting audits, compliance programs, risk assessments, and remediation activities
Experience with data protection, access governance, third-party risk, and security controls for cloud, SaaS, endpoint, and enterprise application environments
Experience managing cybersecurity vendors, managed service providers, and outsourced security services
Proven ability to communicate effectively with executive leadership and influence organizational decision-making
Strong presentation, communication, and stakeholder management skills
CISSP certification required
Preferred Qualifications
Experience in biotechnology, pharmaceutical, life sciences, healthcare, or medical device industries
Experience supporting GxP-regulated systems, Computer System Validation, Quality Management Systems, and inspection readiness activities
Experience supporting SOX compliance and IT General Controls
Familiarity with cloud security, identity and access management, vulnerability management, data protection, cybersecurity operations, and cyber resilience programs
Experience partnering with Legal and Privacy teams on data protection, privacy-by-design, data classification, access control, and vendor risk considerations
Experience supporting commercial-stage companies through growth, scale, geographic expansion, or increasing regulatory complexity
CISM, CRISC, CCSP, GIAC, CISA, or ISO 27001 certifications preferred
\n
$245,000 - $325,000 a year
\n
Scholar Rock is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Scholar Rock is a biopharmaceutical company that discovers, develops and delivers life-changing therapies
Industry
Biotechnology
Company size
51-200 employees
Founded
2012
Headquarters
Cambridge, Massachusetts
LinkedIn followers
28,331
Total funding
$843M
Scholar Rock is a biopharmaceutical company that discovers, develops, and delivers life-changing therapies for people with serious diseases that have high unmet need. As a global leader in the biology of the transforming growth factor beta (TGFβ) superfamily of cell proteins and named for the visual resemblance of a scholar rock to protein structures, the clinical-stage company is focused on advancing innovative treatments where protein growth factors are fundamental. Over the past decade, the company has created a pipeline with the potential to advance the standard of care for neuromuscular disease, cardiometabolic disorders, cancer, and other conditions where growth factor-targeted drugs can play a transformational role.
Scholar Rock is the only company to show clinical proof of concept for a muscle-targeted treatment in spinal muscular atrophy (SMA). This commitment to unlocking fundamentally different therapeutic approaches is powered by broad application of a proprietary platform, which has developed novel monoclonal antibodies to modulate protein growth factors with extraordinary selectivity. By harnessing cutting-edge science in disease spaces that are historically under-addressed through traditional therapies, Scholar Rock works every day to create new possibilities for patients. Learn more about the company’s approach at ScholarRock.com and follow @ScholarRock on X.
For additional information on our guidelines, please visit https://scholarrock.com/community-guidelines/
For more information on how Scholar Rock collects, uses, and shares personal information, please visit: https://scholarrock.com/privacy-policy/
Offices: 301 Binney St, Cambridge, Massachusetts 02142, US
How many Security & Safety jobs are open in Cambridge, MA right now?
There are currently 272 open security & safety positions in Cambridge, MA listed on Clera. New openings are added daily as companies post roles.
Which companies are hiring for Security & Safety roles in Cambridge, MA?
Companies currently hiring include Akamai Technologies, Draper, MORSE Corp, Harvard Division of Medical Sciences, Veolia | France, among others. Browse the listings above to see every active employer.
Are there remote or hybrid Security & Safety jobs in Cambridge, MA?
Yes — 80 of the 272 open security & safety positions offer remote or hybrid work (35 remote, 45 hybrid).
How do I apply for Security & Safety jobs in Cambridge, MA?
Each listing links directly to the employer's application page. Apply early — fresh listings get the most recruiter attention in the first two weeks.