Associate Director/Director, Information Security
Axsometherapeutics · New York, NY
About this role
**Axsome Therapeutics — Associate Director/Director, Information Security** ## About This Role Axsome Therapeutics is seeking an **Associate Director/Director, Information Security** to lead **threat management, incident response, and vulnerability management**. This is a **hands-on leadership** role directing the cybersecurity team and service providers while staying actively engaged in technical work. You will execute and advance the corporate **Information Security Program and Management System** owned by the Head of Information Security, and help maintain the company’s security posture during **non-standard hours** (including **evening/weekend monitoring** and rapid response to high-priority incidents). **Reporting to:** Sr. Director, Information Security **Location:** On-site at Axsome’s HQ in **New York City** — **at least 3 days/week**. **Fully remote candidates cannot be considered.** ## Job Responsibilities and Duties ### Security Operations & Threat Management - Lead security monitoring and detection across **MSP, SIEM, IDS/IPS**, and the broader security toolset; personally triage/analyze/escalate high-severity alerts - Set alert prioritization and detection-engineering standards; tune detections, correlation rules, and use cases to improve signal quality - Perform hands-on threat hunting; operationalize hunting strategies and resulting mitigations - Drive continuous improvement of security controls using threat intelligence, hunt findings, and incident trends ### Incident Response - Act as incident lead for significant business-impact security events (identification, containment, eradication, recovery), including direct investigation and forensic analysis - Maintain and mature incident response plans, runbooks, and playbooks; optimize alerts; design and lead tabletop exercises - Lead post-incident reviews, author executive-facing reports, and drive remediation of process/control gaps ### Vulnerability & Risk Management - Lead the vulnerability management program; execute/validate scans, analyze results, and confirm remediation - Use risk-based prioritization and remediation SLAs aligned to business impact; report progress and residual risk - Partner with IT Infrastructure & Operations and Application Development to drive timely patching and configuration hardening ### Vendor, MSP & Third-Party Risk - Manage cybersecurity vendor and MSP relationships; ensure effective service delivery and enforce SLAs - Define provider KPIs; lead service reviews and drive continuous improvement - Manage the **Third-Party Risk Management (TPRM)** program (assessments, risk ratings, contract security requirements, remediation tracking) ### Program Support, Awareness & Team Leadership - Oversee cybersecurity awareness and training; champion best practices and measure effectiveness - Support security audits and contribute to continuous improvement of security policies/standards/procedures - Manage the InfoSec project portfolio and contribute to technical workstreams as needed - Manage, mentor, and develop team members while modeling hands-on technical excellence ### Data Protection & Insider Risk - Support data protection initiatives (data classification, DLP monitoring, SaaS security assessments, insider risk investigations) - Investigate potential data leakage events and coordinate containment activities ### Identity & Access Security - Oversee security requirements for identity governance, **PAM**, **MFA**, conditional access, and a
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.