Staff Information Security Engineer
Adaptive BiotechnologiesAbout the role
At Adaptive, we’re Powering the Age of Immune Medicine. Our goal is to harness the power of the adaptive immune system to transform the way diseases are diagnosed and treated.
As an Adapter, you’ll have the opportunity to make a difference in people’s lives. With Adaptive, you’ll create a career highlight through collaboration with bright, curious colleagues working at the apex of innovation and application.
It’s time for your next chapter. Discover your story with Adaptive.
Position Overview
The Staff Information Security Engineer is responsible for driving information security functions as related to specific domain(s) of cyber security. This role is accountable for the organization’s governance of information security risk domains by developing and implementing processes responsible for overseeing and managing information security risk. As part of Information Security team, this role will collaborate closely with leaders in Information Technology, Software Development and other departments to implement and manage Adaptive’s information security strategy and priorities and offer independent advice and recommendations regarding ways to further mature the information security and risk management posture and policies.
Key Responsibilities and Essential Functions
- Strategic Leadership & Governance
- Serve as subject matter expert on information security, guiding cross-functional partners and leading enterprise-wide risk committees and security reviews.
- Participate in the definition and evolution of Adaptive’s cybersecurity strategy, architecture, and GRC roadmap aligned with business priorities.
- Develop and maintain security reference architecture across cloud, hybrid, and on-prem environments
- Policy & Compliance Management
- Drive the development and implementation of security policies and ISMS practices, ensuring alignment with ISO 27001, SOC 2, TX-RAMP, HIPAA, and other regulatory frameworks.
- Lead internal and external audits and certification efforts.
- Security Architecture & Control Design
- Collaborate with IT, Privacy, and Engineering to design and implement layered security controls across identity, access, network, endpoint, application, and data environments. Continuously evaluate and integrate emerging technologies to strengthen Adaptive’s security architecture.
- Risk Management & Assurance
- Conduct enterprise risk assessments, maintain the risk register, and monitor key indicators to identify and remediate non-compliance.
- Support customer audits, contract negotiations, and third-party risk management.
- Lead the assessment, management and response efforts for incidents, vulnerabilities, and other security events.
- Control Implementation & Optimization
- Ensure effective deployment and optimization of security tools (e.g., SIEM, EDR, DLP, IAM), ensuring controls meet GRC requirements and business needs.
- Lead control testing, continuous monitoring, and third-party penetration testing engagements.
- Reporting & Stakeholder Communication
- Develop and maintain KPIs, metrics, dashboards and reporting to measure the effectiveness of information security program activities.
- Translate technical risks into business impact for non-technical stakeholders and support customer audits and inquiries.
- All other duties as assigned.
Position Requirements
- Bachelors + 12 years of related experience, or Masters + 8 years of related experience
- Understand Risk Management principles and the tools to ensure attention is brought to high-risk areas.
- Have solid knowledge of ISO 27001, NIST and other information security standards, with some experience implementing these standards.
- Good communicator who is used to working in a dynamic environment.
- Solid attention to detail and ability to communicate that detail in summary form.
- Ability to multi-task and meet deadlines.
- Proven ability to achieve results in a fast moving, dynamic environment.
- Proven understanding of information security risk assessment and technology risk management and compliance procedures and methodologies.
- Ability to establish and maintain relationships with individuals at all levels of the organization, in the business community and with vendors.
- Thorough knowledge of all aspects of information security and compliance including SOC 2, ISO 27001/2, and HIPAA. Life sciences, medical device, or healthcare industry experience ideal, particularly experience with
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s