For Employers
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The Associate Director will lead the cybersecurity program and enterprise IT function, setting strategy and overseeing security controls, incident response, and IT operations. They will partner with engineering and compliance teams to ensure secure practices and reliable technology services across the organization.

About Us

Sage Bionetworks is a nonprofit biomedical research and technology organization that advances human health through open science and collaborative discovery. We work at the intersection of biomedical science, data, technology, and patient engagement, partnering across academia, industry, philanthropy, and government to build research programs, data resources, and technology that accelerate scientific progress.

Sage brings particular expertise in collaborative research, multimodal biomedical data, responsible data governance, and open source technology. Our Synapse platform serves as a generalist research data repository and is trusted to responsibly steward research data at scale.

The Opportunity

Sage Bionetworks is seeking an Associate Director, Cybersecurity & IT to lead our cybersecurity program and enterprise IT function. This role sets Sage’s cybersecurity strategy and leads the teams responsible for implementing and operating security controls, protecting Sage’s systems and data, identifying and remediating vulnerabilities, responding to security incidents, and providing reliable and secure technology services to our employees.

Sitting at the intersection of Sage’s research mission, technology platforms, and federal security obligations, this leader will bring deep cybersecurity engineering expertise alongside practical IT leadership. We are looking for someone who can strengthen and scale our security capabilities, translate security requirements into effective technical practices and controls, and lead the team responsible for employee technology, access, infrastructure, and IT services.

This role works closely with Sage’s security compliance function. The compliance team is responsible for interpreting applicable security frameworks and requirements, coordinating assessments and audits, and organizing compliance evidence. The cybersecurity team is responsible for implementing and operating security controls, maintaining secure engineering and operational practices, addressing identified risks and vulnerabilities, and producing evidence demonstrating that controls are operating effectively.

This is a chance to make a meaningful impact at the intersection of security, technology, research, and open science, building the capabilities and foundation Sage needs for its next phase of growth.

You'll succeed at Sage if you:

  • Have led cybersecurity teams responsible for designing, implementing, and operating security controls in environments subject to rigorous security requirements, including federal security standards.
  • Understand frameworks such as FISMA/RMF and NIST well enough to translate security requirements into practical technical controls and engineering priorities.
  • Thrive on continuously strengthening and scaling security capabilities as the organization grows, rather than simply maintaining an established program.
  • Can explain complex security risks and technical trade-offs in terms a scientist, an engineer, and an executive can each act on, and can maintain high security standards under delivery pressure.
  • Bring genuine IT operations experience alongside cybersecurity leadership and are comfortable staying close to infrastructure, identity, endpoint management, security tooling, and day-to-day technology operations.
  • Are motivated by mission-driven organizations and know how to build high-impact security and technology capabilities efficiently.

You'll know you're succeeding when:

  • Sage’s security controls are implemented effectively, operated consistently, and supported by reliable technical evidence demonstrating that they are functioning as intended.
  • Vulnerabilities, security findings, and technical risks are identified, prioritized, and remediated according to defined, risk-based timelines.
  • Sage has effective capabilities for detecting, investigating, containing, and recovering from cybersecurity incidents.
  • Security practices are integrated into engineering and IT operations, with clear standards, repeatable processes, appropriate automation, and well-defined ownership.
  • Product and engineering teams incorporate security requirements early in technology and product decisions, with the cybersecurity team serving as a trusted technical partner.
  • Sage’s cybersecurity function is resilient and appropriately staffed, with the skills, tooling, processes, and coverage necessary to protect the organization.
  • Sage’s security compliance team receives timely, accurate evidence and technical support needed to demonstrate the effectiveness of Sage’s security controls.
  • Employees have a reliable, low-friction technology experience, with timely onboarding and offboarding, appropriate access, responsive IT support, and well-managed software and device lifecycles.
  • Leadership and the Board have clear, ongoing visibility into significant cybersecurity risks, incidents, security capabilities, and technology investments.

Note: Please do not upload your resume as your cover letter (required)

Key Responsibilities

Cybersecurity Leadership & Operations

  • Set and execute Sage’s cybersecurity strategy and roadmap, establishing priorities, investments, capabilities, and measures of effectiveness based on organizational risk, the threat landscape, and applicable security requirements.
  • Lead the design, implementation, operation, and continuous improvement of technical and operational security controls across Sage’s enterprise and technology environments.
  • Oversee security operations, including security monitoring, threat detection, vulnerability management, security testing, incident investigation and response, and remediation of identified weaknesses.
  • Establish and maintain security engineering and operational practices that reduce risk through secure configuration, automation, monitoring, testing, and repeatable processes.
  • Ensure vulnerabilities and security findings are appropriately triaged, assigned, tracked, and remediated according to risk-based timelines.
  • Lead Sage’s cybersecurity incident-response capabilities, including preparation, detection, investigation, containment, remediation, recovery, and post-incident improvement.
  • Partner with product and engineering teams to identify security risks and incorporate appropriate security controls and practices into Sage’s platforms, infrastructure, and software-development processes.
  • Author and maintain the technical security standards, procedures, and documentation that implement Sage’s security policies, along with the operational evidence needed to demonstrate that controls are implemented and operating effectively.
  • Partner closely with Sage’s security compliance function to translate applicable framework and control requirements into technical implementations and provide evidence needed for assessments and audits.
  • Evaluate and manage security technologies and services, ensuring that Sage’s security tooling provides effective protection, visibility, and operational efficiency.
  • Provide technical security expertise in the evaluation, onboarding, and ongoing management of critical technology and cloud vendors.
  • Represent Sage in external technical security and IT conversations as appropriate.

IT Operations & Employee Technology

  • Lead day-to-day IT operations and employee technology services, ensuring employees have reliable and secure access to the systems, devices, software, and support they need throughout the employee lifecycle.
  • Oversee identity and access management, including provisioning and deprovisioning, authentication and authorization controls, privileged access, and periodic access reviews.
  • Oversee endpoint and asset management, enterprise SaaS administration and licensing, and associated technology vendor relationships.
  • Establish and enforce technical IT and security standards, including device configuration, endpoint protection, identity and access controls, software management, and acceptable technology use.
  • Own the technical implementation, maintenance, and testing of business continuity and disaster recovery capabilities for critical IT systems, in partnership with organizational stakeholders responsible for broader continuity planning.
  • Oversee help desk operations, establishing service standards and processes that provide employees with reliable, timely technology support.

Cross-Organizational Security Partnership

  • Partner with the security compliance team to understand applicable security requirements, implement required controls, remediate technical findings, and produce accurate evidence demonstrating control operation.
  • Partner with product and engineering teams to ensure security, identity, access-management, and data-protection requirements are incorporated into platform architecture and the Synapse roadmap.
  • Work with organizational risk and governance functions to evaluate technical security risks and implement agreed-upon risk treatments.
  • Advise executive leadership and the Board on cybersecurity threats, technical risk exposure, security capabilities, significant incidents, and investments in clear, actionable terms, supported by meaningful security metrics.

People Leadership

  • Build, lead, and develop Sage’s cybersecurity and IT teams, maintaining appropriate staffing, technical capabilities, operational coverage, and clear accountability.
  • Establish clear ownership for security operations, security engineering, vulnerability management, incident response, identity and access management, and IT operations.
  • Develop team members through clear expectations, coaching, professional development, and opportunities for increased responsibility.
  • Foster a culture in which security is treated as an engineering and operational discipline characterized by measurable controls, automation, continuous improvement, and shared accountability.

Qualifications

Education

  • Bachelor’s degree in computer science, information security, or a related field, or equivalent professional experience.

Experience

  • 8+ years of progressive experience in cybersecurity, security engineering, security operations, infrastructure security, or related disciplines, including significant security leadership responsibility.
  • Demonstrated experience leading teams responsible for implementing and operating security controls in production technology environments.
  • Strong working knowledge of security frameworks and standards such as NIST SP 800-53, NIST Cybersecurity Framework, FISMA/RMF, FedRAMP, or comparable frameworks, with demonstrated ability to translate requirements into effective technical controls.
  • Experience with core cybersecurity disciplines such as vulnerability management, security monitoring and detection, incident response, identity and access management, endpoint security, cloud security, and security testing.
  • Experience establishing repeatable processes for identifying, prioritizing, tracking, and remediating security vulnerabilities and findings.
  • Experience responding to and investigating cybersecurity incidents, including coordinating technical response and driving improvements following incidents.
  • Demonstrated ability to communicate cybersecurity risk and technical trade-offs to non-technical executives and a Board.
  • Experience partnering effectively with security compliance, risk, audit, or governance teams, including providing technical documentation and evidence demonstrating control implementation and effectiveness.
  • Experience leading IT operations at an organization of comparable size and complexity, including employee technology services, identity and access management, endpoint management, and enterprise SaaS administration.
  • Experience operating effectively in a lean, mission-driven nonprofit, research, or similarly complex environment.

Nice to Have

  • Experience implementing and operating security controls in an environment subject to FISMA, FedRAMP, or other federal security requirements.
  • Experience shaping security compliance strategy, including supporting an organization through FISMA/RMF, ATO, or FedRAMP authorization and working with independent assessors or federal authorizing officials.
  • Experience securing cloud-native platforms, research data environments, or biomedical data repositories.
  • Experience establishing security engineering practices within software-development and cloud-infrastructure teams.
  • CISSP, CISM, or other cybersecurity-focused certification; GRC-oriented certifications such as CGRC or CISA are a plus.

Job Functions and Physical Requirements

The following cognitive and physical activities outline the essential functions required for successful job performance. Reasonable accommodations may be provided to enable individuals with disabilities to fulfill these functions.

Physical Demands

  • Extended periods of sitting at a desk and using a computer.
  • Repeated wrist, hand, and finger movements.
  • Requires clear vision for tasks like data analysis, transcribing, computer use, and reading.
  • Occasionally lifting or moving objects weighing up to 10 pounds.

Cognitive Demands

  • Able to work effectively under deadlines.
  • Strong problem-solving and analytical skills.
  • Attention to detail and accuracy.
  • Flexibility to adapt to changing environments, priorities and multitask.

Additional Functions

  • Travel two times per year for on-site events in Seattle, WA.
  • Effective verbal and written communication skills.
  • Works well in a team and maintains professionalism.
  • Follows company policies, procedures, and relevant laws and regulations.

Note: This list is not exhaustive and may be subject to modification as job duties evolve.

Compensation & Total Rewards

Sage Bionetworks implements equitable workplace strategies to ensure fair pay. Actual compensation is determined by market data, specific experience, and internal parity.

  • Job Level: Associate Director
  • Annual Salary Range: $140,000 - $180,000
    • Note: New hires typically receive an offer between the minimum and the midpoint of the range to allow for future growth within the role. Higher offers may be considered for exceptional experience or specific market conditions.
  • Comprehensive Benefits: We offer a package competitive with both commercial biotech and nonprofit sectors:
    • Health & Wellness: Comprehensive medical, dental, vision, life, AD&D, and long-term disability.
    • Future Security: Robust retirement plan and flexible spending accounts (FSA).
    • Work-Life Harmony: Paid time off and flexible work arrangements.
    • Learn more at: Benefits – Sage Bionetworks

Equal Opportunity & Inclusion

Sage Bionetworks is an Equal Opportunity Employer. We prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Accommodation Request: If you require a reasonable accommodation during the application or interview process, please contact HR during the scheduling process.

Modern Hiring & Responsible AI

We value your talent and your time. To ensure a fair and inclusive experience, we operate with the following principles:

  • Responsible AI in Recruiting: To help us find the best talent, we may utilize AI tools within our recruiting platforms. We use these technologies responsibly to avoid the pitfalls of bias and discrimination. We believe technology should enhance human judgment, not replace it, and we regularly audit our processes to ensure every candidate is evaluated fairly based on their unique skills.
  • Work from (Almost) Anywhere: We are a distributed workforce and support remote or hybrid arrangements within the United States.
  • Virtual-First Interviews: All interviews are conducted virtually to ensure accessibility and flexibility for all candidates.

About Sage Bionetworks: Science for the Common Good

At Sage Bionetworks, we believe the greatest barriers to medical progress aren't just biological—they are structural. Since 2009, our Seattle-founded nonprofit has been on a mission to tear down the "silos" of traditional science. We don’t just conduct research; we redefine how it’s done through open science, radical collaboration, and ethical data sharing.
When you join Sage, you aren't just taking a job; you’re joining a bold collective of scientists, engineers, governance experts, and visionaries. We empower patients to be partners, not just data points, and we provide the platforms that allow the global scientific community to accelerate life-saving discoveries.

The Sage Way: Our Core Values

We don’t just talk about change; we live it through these five pillars:

  • Science Driven: We use data and evidence to ensure our work creates a measurable, positive impact on human health.
  • Accountable: We deliver on our promises through a foundation of trust and radical transparency.
  • Growth Oriented: We stay curious, seek out the hardest challenges, and constantly aspire to improve ourselves and our field.
  • Empathetic + Inclusive: We embrace our differences and build environments where every voice is empowered.
  • Radically Collaborative: We believe the best solutions come from teamwork and building diverse, global communities.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Others jobs →

AI Response Evaluator

Freelance France, Japan, Mexico +3 more $10K – $20K Others

Proposal Lead - Government Business Solutions [543]

Full Time United States $111K - $153K per year Others

Director, Software Engineering Manager

Full Time United States $107K - $159K per year Others

Retail Catalog Optimization Specialist

Full Time United States $76000 - $82000 per year Others

Implementation Specialist - KitCheck - TRAVEL REQUIRED

Full Time United States $60000 - $75000 per year Others

Social Operations Lead - NO THIRD PARTIES

Freelance United States Others
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 218,987+ Jobs in Others

Answer easy questions

Answer easy questions

218,987+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified