Senior Director, Cloud Security, Compliance Lead
Lila SciencesAbout the role
<p><strong>Your Impact at LILA</strong></p> <p>Cloud Security & Compliance Lead is responsible for the end-to-end security, governance, risk management, and regulatory compliance of Lila Sciences’ cloud environments and research workflows. You’ll own cloud security architecture, policy frameworks, data protection, and compliance programs across multi-cloud and on-premises contexts as appropriate. You’ll partner with Engineering, Data Science, IT, Legal, and Compliance to codify secure patterns, enable rapid yet safe experimentation, and maintain a robust governance program with auditable evidence for regulators and customers.</p> <p><strong>What You'll Be Building</strong></p> <h4>Cloud Security Architecture & Governance</h4> <ul> <li>Define and maintain cloud security strategy, reference architectures, and security baselines for public cloud (AWS, Azure, GCP) and hybrid deployments. </li> <li>Implement secure-by-default patterns for CI/CD is intentionally out of scope; focus on secure design patterns for cloud resources, data flows, and analytics. </li> <li>Establish IAM least privilege, network segmentation, private endpoints, key/secret management, and centralized logging across AWS, Kubernetes (where applicable), and cloud-native services. </li> </ul> <h4>Governance, Compliance & Risk Management</h4> <ul> <li>Develop, implement, and continuously improve policies, standards, and procedures aligned to applicable frameworks (e.g., NIST CSF, NIST 800-53, FedRamp, ISO 27001, SOC 2, GDPR/CCPA). </li> <li>Lead data protection program: data classification, data minimization, data retention, and data lifecycle management; oversee DLP strategies where relevant. </li> <li>Manage third-party risk assessments, vendor security questionnaires, and contract security annexes; maintain evidence for audits. </li> </ul> <h4>Security Controls & Monitoring</h4> <ul> <li>Define and oversee security controls across cloud resources, including identity, access management, encryption, key management, log collection, and telemetry. </li> <li>Collaborate with Security Operations to establish monitoring, alerting, incident response coordination, and evidence collection for audits. </li> </ul> <h4>Compliance & Audit Readiness</h4> <ul> <li>Prepare for internal and external audits; map controls to frameworks and translate them into engineering artifacts and evidence. </li> <li>Maintain alignment with SOC 2, ISO 27001, and other regulatory requirements, coordinate with Legal and Privacy on data protection controls. </li> </ul> <h4>Data, ML/AI Security & Priva
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s