Senior Security and Compliance Engineer
SirtexAbout the role
Company Description
Sirtex Medical is a global leader in healthcare, with offices in the U.S., Australia, Germany, and Singapore, dedicated to improving patient outcomes.
Our mission is to be at the forefront of minimally invasive cancer and embolization therapies. By partnering with physicians, we aim to provide innovative products that enhance patient outcomes and simplify treatments. Achieving this ambitious goal requires passionate and talented individuals who are committed to making a difference. Our flagship product, SIR-Spheres® Y-90 resin microspheres, is a targeted radiation therapy for liver cancer. To date, we have delivered over >150K doses across 50+ countries, significantly impacting patients' lives worldwide. Our success is fueled by our dedication to serving the medical community, maintaining professionalism, fostering a collaborative work culture, nurturing an entrepreneurial spirit, and continuously pursuing innovation and improvement.
At Sirtex, we are committed to creating a great workplace. We offer a range of benefits, programs, and services to support our employees, ensuring they have opportunities to contribute to our success and advance their careers. Join our inclusive community, where you can collaborate with talented colleagues, bring your ideas to life, and advance your career, all while delivering innovative healthcare solutions to patients.
Job Description
A Senior Security Compliance Engineer is responsible for ensuring that an organization's information systems and processes meet specific security and regulatory requirements. This role will be responsible to maintain compliance with various laws, regulations, and industry standards, and help identify and mitigate security risks to safeguard company data. The role involves collaboration with various teams to establish, monitor, and enforce security controls.
Key Responsibilities:
- Compliance Management:
- Monitor and enforce compliance with security standards, policies, and regulations such as GDPR, HIPAA, PCI-DSS, SOC 2, ISO 27001, and others.
- Conduct regular internal audits to ensure adherence to security best practices and regulatory frameworks.
- Assist in preparing for external audits, ensuring necessary documentation and evidence are in place.
- Risk Assessment:
- Assess and evaluate potential security risks in systems, applications, and processes.
- Conduct vulnerability assessments, risk assessments, and gap analyses to identify areas of non-compliance or weaknesses.
- Recommend corrective actions or enhancements to improve security and compliance posture within the Sirtex landscape.
- Security Framework Implementation:
- Develop, implement, and maintain security policies and procedures aligned with industry standards and regulatory requirements.
- Ensure proper implementation of controls (e.g., encryption, authentication) to meet compliance requirements.
- Collaboration:
- Work with the Director of IT and operations along with legal, and other relevant teams to ensure compliance with internal and external security standards.
- Provide guidance on security best practices for internal projects, system deployments, and new product launches.
- Documentation & Reporting:
- Maintain accurate documentation of compliance activities, audits, risk assessments, and findings.
- Prepare reports and presentations for senior management, highlighting compliance status, risk assessments, and recommendations.
- Incident Response:
- Participate in incident response activities related to security breaches, ensuring timely reporting and corrective actions in line with regulatory requirements.
- Assist in maintaining and testing disaster recovery and business continuity plans.
- Training & Awareness:
- Conduct regular training sessions for employees regarding security policies, compliance requirements, and best practices.
- Promote awareness of security issues within the organization and ensure compliance with security practices.
Qualifications
Required Skills and Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field
- 10 + years of experience in information technology along with information security and compliance
- In-depth knowledge of information security frameworks (e.g., ISO 27001, NIST) and compliance standards (e.g., GDPR, HIPAA, PCI DSS)
- Strong experience in risk assessment, security auditing, and penetration testing
- Proficiency in using and managing cybersecurity tools and technologies
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s