Iterative Health is a healthcare technology and services company building a high-performing, multispecialty clinical research network that embeds research into clinical care.
<div class="content-intro"><p><span style="font-size: 10pt;">Iterative Health is a healthcare technology and services company powering the acceleration of clinical research to transform patient outcomes.</span></p> <p><span style="font-size: 10pt;">We built a leading performance-driven network of 100+ sites across the US, Europe, India, and Australia, conducting research directly in the communities where care is delivered across gastrointestinal, hepatology, obesity, and cardiology. By combining deep clinical trial expertise with cutting-edge AI, we connect sponsors' scientific ambitions with high-performing research teams that expedite and expand access to novel therapeutics for patients in need. Today, Iterative Health is headquartered in Cambridge, Massachusetts, and New York City with 250+ employees world-wide.</span></p> <p> </p></div><p></p> <p><span style="font-size: 10pt;">As Iterative Health's first dedicated cybersecurity hire, you won't be stepping into an existing security program—you'll be building it. This is a rare opportunity to establish and lead the company's cybersecurity strategy, creating the foundation that will protect our people, technology, data, and business as we continue to scale.</span></p> <p><span style="font-size: 10pt;">In this role, you'll own the end-to-end security landscape, including our AWS cloud infrastructure, identity and access management, SaaS ecosystem, endpoint security, sensitive clinical and patient data, and the security and compliance frameworks that support our business. You'll work cross-functionally with IT, Engineering, Compliance, Legal, and business leaders to strengthen our security posture, reduce organizational risk, and embed security into every aspect of the company.</span></p> <p><span style="font-size: 10pt;">We're looking for a hands-on security leader who combines deep technical expertise with strong business judgment and a builder's mindset. You'll be equally comfortable architecting security solutions, responding to evolving threats, developing policies and controls, and influencing stakeholders across the organization. This is an opportunity to create a scalable, modern security program that grows alongside a fast-paced healthcare technology company.</span></p> <p> </p> <p><span style="font-size: 10pt;"><strong>Where You’ll Drive Impact </strong></span></p> <p><span style="font-size: 10pt;">Security Program Development</span></p> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Serve as Iterative Health's first dedicated cybersecurity resource — build, mature, and operate the company's security program from the ground up.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Identify security gaps, prioritize remediation, and partner with the IT Director to define security priorities, roadmap items, and risk reduction plans.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Develop, maintain, and enforce security policies, standards, procedures, runbooks, and control documentation.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Provide company-wide subject matter expertise and support related to cybersecurity awareness and compliance.</span></li> </ul> <p><span style="font-size: 10pt;">Cloud & Infrastructure Security</span></p> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Work with engineering team to secure and monitor AWS environments, including IAM, logging, encryption, backups, access controls, and overall cloud security posture.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Configure firewalls, encryption, and access controls across cloud and corporate infrastructure.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Improve security controls across Okta, Entra ID, Microsoft 365, Google Workspace, Box, SharePoint, AWS, and other cloud platforms.</span></li> </ul> <p><span style="font-size: 10pt;">Identity & Access Governance</span></p> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Maintain and improve RBAC, access reviews, privileged access controls, admin role governance, service account oversight, and joiner/mover/leaver security processes.</span></li> </ul> <p><span style="font-size: 10pt;">Incident Response</span></p> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Own incident response for suspected cyberattacks, account compromise, malware, data exposure, unauthorized access, and other security events.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Lead incident investigation, containment, remediation, documentation, root-cause analysis, and post-incident improvement tracking.</span></li> </ul> <p><span style="font-size: 10pt;">Compliance & Risk Management</span></p> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Own security evidence collection, control documentation, remediation tracking, and audit support for SOC 2, HIPAA/HITECH, and applicable GDPR requirements.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Own all vendor assessment and security questionnaire responses.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Support vulnerability management, penetration testing, social engineering testing, customer security reviews, vendor security questionnaires, third-party risk assessments, security awareness, and user education.</span></li> </ul> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Performs related duties as requested </span></li> </ul> <p><span style="font-size: 10pt;"><strong>What You Bring to the Team</strong></span></p> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Bachelor's degree in IT, engineering, mathematics, or a related field; candidates with extensive cybersecurity certification in lieu of a degree will be considered.</span></li> <li style="font-