At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes. Our cloud-based platform, StudyTeam, brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively. StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries. Join us in our mission to advance clinical research and improve patient care.
One mission. One team. That’s OneStudyTeam .
The Security Compliance Manager leads the organization’s security compliance and assurance efforts—ensuring we meet and maintain certification requirements (e.g., ISO 27001, SOC 2) and always remain audit-ready. This role translates security control requirements into actionable work across teams, drives evidence collection and remediation, and strengthens risk management practices to enable growth in regulated environments.
What You’ll Be Working On
- Lead security certification & audit readiness (ISO 27001 / SOC 2): Drive quarterly ISO control requirements, manage ISO surveillance audits, lead SOC 2 examination readiness, and oversee ongoing maintenance activities once achieved.
- Operate the ISMS controls program: Manage internal ISMS control reviews, coordinate remediation and corrective actions, and ensure controls remain effective and scalable as the organization changes.
- Evidence management & auditor response: Prepare for internal and external audits by organizing requests, gathering evidence, maintaining audit artifacts, and authoring clear, consistent responses to auditors.
- Risk management program execution: Recommend and implement improvements to the information security risk management program; develop and maintain the risk register, risk ownership, and workflows for tracking remediation plans to closure.
- Metrics, reporting, and stakeholder enablement: Partner with Security leadership to define and report KRIs/KPIs for the information security program; support consistent responses to customer security audits and questionnaires aligned to program commitments.
- Manage periodic reviews and updates of security policies and procedures to ensure alignment with certifications, business needs, and regulatory expectations.
- Partner with an outsourced/internal audit function to validate control performance and drive continuous improvement.
- Support cross-functional education and adoption of security requirements by translating compliance language into clear tasks, owners, and acceptance criteria.
What You Bring to OneStudyTeam
- Required: Minimum of Experience leading a successful ISO 27001 or SOC 2 certification effort.
- Required: Minimum of 5+ years in a dedicated