
Director of Cyber Security
Sermo
Job description
Company Description
Sermo transforms physician experience, expertise, and real-world observations into actionable insights for the global healthcare community. With a social platform that engages more than 1 million healthcare professionals across 150 countries, Sermo enables peer-to-peer collaboration and meaningful discussions focused on patient care and clinical practice. The company’s proprietary technology offers on-demand access to physicians, providing business intelligence that supports patients, pharmaceutical organizations, healthcare partners, and the broader medical community. Sermo combines data, technology, and community to drive better decision-making and improve health outcomes worldwide.
Role Description
The Director of Cyber Security is a full-time, remote leadership role responsible for defining and executing Sermo’s overall cyber security strategy. This role oversees the design, implementation, and continuous improvement of security controls across applications, networks, and cloud environments to protect sensitive healthcare and business data. Day-to-day responsibilities include leading security operations, managing threat detection and incident response, and ensuring compliance with relevant security and privacy regulations. The Director will collaborate with engineering, product, data, and compliance teams to embed secure-by-design principles, perform risk assessments, and guide secure architecture decisions. This position also involves developing security policies, leading audits, overseeing vendor and third-party risk, and driving security awareness programs across the organization.
Qualifications
-
Candidates should possess strong skills in Cybersecurity and Information Security, including risk management, governance, and incident response.
-
Candidates should possess skills in Application Security and Security Architecture Design, including secure SDLC, code review, and designing resilient, scalable security architectures.
-
Candidates should possess skills in Network Security, including configuration and monitoring of firewalls, VPNs, IDS/IPS, and secure network segmentation.
-
Experience leading security programs in cloud-based or SaaS environments, preferably in healthcare, life sciences, or regulated industries.
-
Familiarity with security and privacy frameworks and regulations (e.g., ISO 27001, NIST, SOC 2, HIPAA, GDPR) and implementing controls to meet compliance requirements.
-
Proven leadership experience managing cross-functional security initiatives, mentoring security professionals, and influencing technical and non-technical stakeholders.
-
Strong analytical, communication, and documentation skills, with the ability to explain complex security concepts clearly to diverse audiences.
-
Bachelor’s degree in Computer Science, Information Security, or a related field; advanced degree or relevant certifications (e.g., CISSP, CISM, CCSP) are beneficial.