Information Security Compliance Engineer (Remote)
Why join Freenome?
Freenome is a high-growth biotech company developing tests to detect cancer using a standard blood draw. To do this, Freenome uses a multiomics platform that combines tumor and non-tumor signals with machine learning to find cancer in its earliest, most-treatable stages.
Cancer is relentless. This is why Freenome is building the clinical, economic, and operational evidence to drive cancer screening and save lives. Our first screening test is for colorectal cancer (CRC) and advanced adenomas, and it’s just the beginning.
Founded in 2014, Freenome has ~500 employees and more than $1.1B in funding from key investors, such as the American Cancer Society, Andreessen Horowitz, Anthem Blue Cross, Bain Capital, Colorectal Cancer Alliance, DCVC, Fidelity, Google Ventures, Kaiser Permanente, Novartis, Perceptive Advisors, RA Capital, Roche, Sands Capital, T. Rowe Price, and Verily.
At Freenome, we aim to impact patients by empowering everyone to prevent, detect, and treat their disease. This, together with our high-performing culture of respect and cross-collaboration, is what motivates us to make every day count.
Become a Freenomer
Do you have what it takes to be a Freenomer? A “Freenomer” is a determined, mission-driven, results-oriented employee fueled by the opportunity to change the landscape of cancer and make a positive impact on patients’ lives. Freenomers bring their diverse experience, expertise, and personal perspective to solve problems and push to achieve what’s possible, one breakthrough at a time.
About this opportunity:
The Information Security Compliance Engineer will oversee execution of our end-to-end audit requirements and support 3rd party auditor relationships, respond to Security Questionnaires for new customers and partners, maintain accuracy of our policies and procedures and adherence to our Security Awareness Program.
This position will report directly to the Director, Information Security.
What you’ll do:
- Responsible for working directly with internal Security, Product and Engineering, Legal, Operations and Business Stakeholders as well as with third-party auditors to communicate compliance mandates and maintain annual compliance against published standards (HIPAA, HITRUST, NIST 800-53, SOC2, ISO27001) and Privacy programs
- Assess internal and production environments on an ongoing basis to meet compliance
- Collect and analyze audit artifacts to support continuous compliance and drive audit activities by utilizing Governance Risk and Compliance Tool
- Communicate the progress and results of audits throughout the engagement
- Able to respond to and understand Security Questionnaires from a variety of customers or partners
- Drive the delivery and reporting of security awareness training compliance and enhance the program to continue to build a security aware organization
- Contribute to the continuous evolution of our compliance program, create control lifecycle processes, and ensure appropriate mappings to industry standards
- Work with stakeholders and teams to strategize on automation strategy for evidence collection and continuous control monitoring
- Ability to assess an operational or security challenge/opportunity and determine best future state potentially leveraging technology/automation
- Proactively look for areas of improvement and provide value added advice and insight on process and controls improvements, policy and standards change and drive continuous advancement of compliance automation capabilities
- Manage and assist engineering and product teams on all security and compliance related technical components
- Create and maintain compliance related documents, such as Policies, Procedures, Standards and Guidelines
- Develop measurements and metrics of the program to report up to management
- Perform all other Information Security related duties as assigned and contribute to the success of the Information Security Team
- 2+ years of relevant industry experience in such a role
- B.S. or M.S. in computer science, security and risk analysis or a related technical field
- Project managing regulatory audits, and information security audits in a regulated environment requiring compliance with standards and regulations such as HIPAA, HITRUST, SOC2, ISO27001, CCPA, and GDPR
- Ability to gather and perform due diligence on the evidence in support of audits
- Ability to work independently as a self-starter in a fast-paced environment
- Working knowledge of cyber and compliance risk management
- Able to conduct internal audits and audit report generation
- Google Cloud Platform experience
- Hands-on experience in vulnerability assessment, red- and blue-teaming, IDS/IPS, SIEM and endpoint protection
- You enjoy working with a team and alone as the situation dictates
- Well organized with good time management skills
Nice to haves:
- You have unwavering personal integrity and work ethic
- You are proactive
- A systematic problem-solving approach, coupled with effective communication skills and a sense of ownership and drive
- Working knowledge of creating and presenting awareness training content
- Genomics or bioinformatics background
Benefits and additional information:
The US target range of our base salary for new hires is $98,000 - $150,000. You will also be eligible to receive pre-IPO equity, cash bonuses, and a full range of medical, financial, and other benefits depending on the position offered. Please note that individual total compensation for this position will be determined at the Company’s sole discretion and may vary based on several factors, including but not limited to, location, skill level, years and depth of relevant experience, and education. We invite you to check out our career page @ https://careers.freenome.com/ for additional company information.
Freenome is proud to be an equal-opportunity employer, and we value diversity. Freenome does not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
Applicants have rights under Federal Employment Laws.
- Family & Medical Leave Act (FMLA)
- Equal Employment Opportunity (EEO)
- Employee Polygraph Protection Act (EPPA)
Something looks off?