Skip to content
Click TherapeuticsClick TherapeuticsNew York, NY

Information Security Lead

Leads information security operations, compliance, risk management, and secure development for regulated digital therapeutics. The role requires healthcare or medical-device security experience, expertise with major security frameworks and cloud/application security, and the ability to lead cross-functional teams.

130k – 200k/yr
Hybrid5+ YOESecurity Engineering

About the role

Responsibilities

  • Maintain and continually improve the Information Security Management System (ISMS) to support certifications including ISO 27001, SOC 2, IEC 81001-5-1, and UK Cyber Essentials Plus.
  • Lead technical security aspects of data privacy and compliance with GDPR, CCPA, and HIPAA.
  • Lead and mature Security Operations Center (SOC) capabilities, including threat intelligence, monitoring, detection, and analysis.
  • Collect, analyze, escalate, and respond to cybersecurity vulnerabilities, threats, and attacks using SIEM and EDR technologies.
  • Collaborate with Engineering on Secure Development Lifecycle (SDLC) practices, including threat modeling, static and dynamic analysis, fuzz testing, and formal verification.
  • Develop and maintain reporting for threat and incident KPIs, including incident response timeliness and observability metrics.
  • Oversee penetration testing and vulnerability scanning.
  • Conduct security training and awareness programs.
  • Oversee third-party and vendor risk management activities.
  • Collaborate with Quality and Regulatory teams on cybersecurity processes.
  • Support regulatory submissions by generating Cybersecurity Quality Management System (QMS) documentation and ensuring compliance with FDA Cybersecurity Guidance (2025), EU MDR, NIST 800-53, IMDRF, and AAMI TIR57.

Requirements

  • Experience in a highly regulated industry such as medical devices, pharmaceuticals, biotechnology, or healthcare.
  • Understanding of security frameworks and standards, including NIST Cybersecurity Framework, ISO 27001/27002, and SOC 2.
  • Knowledge of risk assessment methodologies, threat modeling, network security, AWS cloud security, application security, and data protection technologies.
  • Experience leading or participating in formal security audits.
  • Experience interfacing with engineering teams and working in tiger teams or embedded SME Scrum teams.
  • Strong leadership and communication skills, including the ability to explain complex security concepts to technical and non-technical audiences.
  • Ability to integrate AI technologies into professional workflows and use them to drive innovation and productivity.

Compensation and Benefits

  • Base salary: $130,000–$200,000.
  • Annual performance-based cash bonus.
  • Equity package and stock options.
  • 5% 401(k) matching.
  • Medical, dental, vision, and life insurance.
  • Unlimited paid time off.
  • Professional development stipend.
  • Fitness reimbursement, commuter subsidies, fertility support, and parent benefits.
  • Flexible work arrangement, with at least four days per week in the office.
  • Additional benefits include Uber One, Nectar Rewards, One Medical, Bike Membership, LinkedIn Learning, Gemini Enterprise Stack, Industrious Workspaces, sponsored company events, office meals and snacks, and a choice of Mac or Windows.

Skills

information security management systemISO 27001SOC 2nist cybersecurity frameworkSIEMedrThreat ModelingAWSApplication SecurityPenetration Testingvulnerability scanningHIPAAGDPRCCPAsecure development lifecycle
Chainguard

Senior Security Engineer

ChainguardUnited States

Senior Security Engineer on the Cyber Resiliency team designing detection controls, engineering SOAR/AI playbooks, leading incident response, and conducting threat hunts to strengthen Chainguard's security posture.

130k – 150k/yrRemote5+ YOESecurity Engineering
Chime

Senior Security Engineer

ChimeNew York, NY +1

As a Senior Security Engineer, you will work across product, application, infrastructure, and enterprise security. This role involves hands-on work with code and cloud infrastructure, focusing on reducing security risks, performing security reviews, and building automation and tooling.

130k – 250k/yrHybrid5+ YOESecurity Engineering
MongoDB

Senior Software Engineer, Server Security

MongoDBNew York, NY

Senior Software Engineer builds and tests security features like cryptography, identity/access, and network security in MongoDB's C++ codebase. Requires 5+ years in distributed systems and proficiency in compiled languages like C++ or Rust.

126k – 248k/yrHybrid5+ YOESecurity Engineering
Plaid

Senior Security Analyst, Customer Assurance

PlaidNew York, NY +3

Own Plaid's Security Contracts program: review security provisions in MSAs/DPAs/addenda, provide positions to Legal/GTM for negotiations, build scalable processes/playbooks, track patterns for improvements, and support questionnaires/audit calls. Requires 6+ years in security GRC/assurance with fintech experience, deep clause knowledge, and AI fluency.

134k – 214k/yrHybrid6+ YOESecurity Engineering
Clickhouse

Senior Security Automation Engineer

ClickhouseUnited States

Senior Security Automation Engineer building centralized security telemetry, universal identity provisioning, and agentic risk engines to enable continuous compliance, self-healing controls, and real-time risk visibility at ClickHouse. Requires strong IAM/IGA and automation experience with Python, JS/TS, or Go.

125k – 205k/yrRemote5+ YOESecurity Engineering