Jobs and Careers
SC
Senior Director, Chief Information Security Officer
Scholar RockUnited Statesfull_timeVerifiedPosted 11 Aug 2026
About the role
Scholar Rock is a late-stage global biopharmaceutical company focused on developing and commercializing apitegromab for children and adults with spinal muscular atrophy (SMA) and other rare, severe, and debilitating neuromuscular diseases. As a global leader in myostatin biology, a field focused on proteins that regulate muscle mass, the Company is named for the visual resemblance of a scholar rock to protein structures. Our commitment to unlock fundamentally different treatment approaches is powered by broad application of a proprietary platform, which has developed novel monoclonal antibodies to modulate protein growth factors with extraordinary selectivity. Scholar Rock works every day to create new possibilities for patients through its highly innovative anti-myostatin program, including opportunities in additional rare neuromuscular diseases. Learn more at ScholarRock.com and follow @ScholarRock on X and on LinkedIn.
Summary of Position:
Scholar Rock is seeking a Senior Director, Cybersecurity to serve as the company’s Chief Information Security Officer, responsible for building and scaling enterprise cybersecurity capabilities that protect the organization’s people, data, technology assets, intellectual property, and business operations.
Reporting to the CIO, this role defines and executes the cybersecurity strategy and roadmap in partnership with enterprise stakeholders across technology, Legal, Privacy, HR, Finance, Quality, and business functions.
The successful candidate combines strategic leadership with hands-on execution, with deep expertise across cybersecurity architecture, engineering, operations, governance, risk management, and compliance. This leader will build scalable, risk-based cybersecurity capabilities for a growing biotechnology company, balancing current operational needs with the maturity required to support commercial growth, regulatory readiness, and future organizational scale.
This role is ideal for a cybersecurity leader who has successfully led multiple cybersecurity functions and is ready to assume broader enterprise cybersecurity leadership responsibilities in a lean, high-growth biotechnology environment.
Position Responsibilities
Cybersecurity Strategy & Program Leadership
- Define and execute the enterprise cybersecurity strategy, roadmap, priorities, and operating model
- Establish cybersecurity governance, policies, standards, and control frameworks aligned with business objectives and organizational growth
- Prioritize cybersecurity maturity initiatives based on business risk, regulatory expectations, commercial growth, and organizational scale
- Drive continuous improvement of cybersecurity capabilities and maturity across the organization
- Serve as the primary cybersecurity advisor to the CIO, Board of Directors, and business leadership
- Translate cybersecurity risks and opportunities into clear, actionable business recommendations
Security Architecture & Engineering
- Own the cybersecurity target-state architecture and security technology roadmap
- Lead cybersecurity architecture and engineering across cloud, infrastructure, identity, endpoint, network, application, SaaS, and data environments
- Embed secure-by-design and risk-based security principles across enterprise initiatives and technology platforms
- Partner with technology teams to integrate security requirements into solution design, implementation, and operational support models
- Evaluate, select, and optimize cybersecurity technologies and services that support business and regulatory requirements
Security Operations & Cyber Resilience
- Own security operations capabilities, including vulnerability management, incident response, security monitoring, identity security, and cyber resilience
- Establish and mature detection, response, recovery, and continuous improvement capabilities
- Lead cybersecurity incident response activities, executive communications, and post-incident reviews
- Partner with technology teams and service providers to strengthen operational security capabilities and reduce enterprise risk
- Support business continuity, disaster recovery, and cyber resilience planning in partnership with IT and business stakeholders
Governance, Risk & Complian
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s