This role is not open to remote applicants and would require relocation to Seattle, WA.
Starting Salary Range: $135,000 - $169,000 annually
Exemption Status: Exempt
Location Expectations: Hybrid
Reporting To: VP, Finance & Operations
A-Alpha Bio is seeking a Manager, Information Security & Technology to own and lead our information security and technology program - encompassing information security, cloud infrastructure, laboratory technology, and technology governance. Success in this role depends on a combination of strategic planning and technical implementation, the ability to build strong internal and external partnerships, and a sense of ownership and accountability for technology outcomes. This position will require direct ownership, execution, and vendor management, rather than delegation through a dedicated internal team.
Key Responsibilities
Cybersecurity Program
- Own the company's cybersecurity program and NIST-aligned roadmap.
- Maintain security policies and procedures, control reviews, and corrective actions.
- Manage risk assessments, penetration testing, and vulnerability remediation.
- Develop security metrics, risk reporting, and executive dashboards.
- Coordinate awareness and phishing training; support customer security reviews and questionnaires.
Cloud & Infrastructure
- Lead AWS infrastructure and security improvements from risk assessments and operational reviews.
- Manage cloud identity, access, encryption, logging, and monitoring.
- Support disaster recovery and business continuity, partnering with Data Science on secure, maintainable cloud environments.
Network & Systems
- Own office and laboratory network security and architecture.
- Assess, design, and implement network segmentation between corporate and laboratory environments, including compensating controls for legacy laboratory systems.
- Manage firewalls, DNS, secure connectivity, and network access controls.
- Support lab device and instrument integration, partnering with the MSP on reliable infrastructure.
Microsoft 365 & Identity
- Administer Microsoft 365 and Entra ID, including Conditional Access, Intune, identity governance, and endpoint security.
- Manage application registrations, enterprise applications, user provisioning, and privileged access reviews.
Enterprise Applications
- Own administration and governance of key SaaS and enterprise applications with business owners, including access, licensing, integrations, and vendor escalations.
- Coordinate response to application outages and service issues.
AI & Technology Governance
- Establish AI governance and secure-use standards, including an inventory of approved AI tools and platforms.
- Review technology vendors and SaaS applications for security risks.
Technology Program & Vendor Management
- Own MSP and security vendor relationships, performance, and accountability.
- Lead technology, infrastructure, and security projects end-to-end, coordinating changes organization-wide.
- Develop a multi-year technology roadmap and recommend appropriate investments in security, efficiency, and scalability.
Qualifications & Experience
Required
- Bachelor's degree in a related field with 7+ years of experience in IT, cybersecurity, cloud administration, or technology operations; or an equivalent combination of education and experience.
- Hands-on experience administering and securing AWS cloud environments, Microsoft 365, and Entra ID.
- Experience implementing and operating a cybersecurity program aligned with the NIST Cybersecurity Framework (or comparable), including risk management, vulnerability remediation, governance, and vendor and MSP oversight.
- Experience leading cross-functional cybersecurity, cloud, and infrastructure initiatives end-to-end through influence and technical expertise.
- Ability to communicate technical concepts and risks to technical and non-technical audiences.
- Strong writing skills in regards to policies, executive summaries, and customer-facing security responses.
- Ability to develop pragmatic, fit-for-purpose solutions that balance security, laboratory, scientific, and business needs.
Preferred
- Professional certifications (CISSP, CISM, Security+, AWS, Microsoft, etc.).
- Experience supporting regulated environments (life sciences, biotech, healthcare, SaaS).
- Experience with Microsoft 365 security controls and AWS networking and security.
- Experience with AI governance or emerging technologies.
- Experience supporting laboratory or scientific computing environments.