SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Click Therapeutics is a digital therapeutics company developing FDA-regulated prescription software treatments for conditions across psychiatry, neurology, oncology, immunology, and cardiometabolic diseases. As Information Security Lead, you will build and mentor a high-performing security team while establishing the company's information security strategy across all operations and partnerships.
Key responsibilities include maintaining and improving the Information Security Management System (ISMS) to sustain certifications such as ISO 27001, SOC 2, IEC 81001-5-1, and UK Cyber Essentials Plus. You will lead technical security aspects of data privacy compliance with GDPR, CCPA, and HIPAA regulations. The role requires maturing the company's Security Operations Center (SOC) capabilities, including threat intelligence, monitoring, detection, and incident response using SIEM and EDR technologies.
You will collaborate closely with Engineering to embed Secure Development Lifecycle (SDLC) practices, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification. You'll oversee security testing activities including penetration testing and vulnerability scanning, develop KPI reporting for threats and incidents, and conduct security awareness training across the organization.
Additional responsibilities include managing third-party and vendor risk, collaborating with Quality and Regulatory teams on cybersecurity processes, and supporting FDA regulatory submissions by generating Cybersecurity Quality Management System (QMS) documentation aligned with FDA Cybersecurity Guidance (2025), EU MDR, NIST 800-53, IMDRF, and AAMI TIR57.
The position is based at Click's Tribeca headquarters in NYC with a hybrid model requiring at least 4 days in office weekly. The company values professionals who seamlessly integrate AI into their workflows as a force multiplier for innovation and productivity.