# Information Security Lead at Alloy Therapeutics

- Company: Alloy Therapeutics
- What the company does: Alloy Therapeutics democratizes access to antibody discovery and biologics discovery technology to enable and advance drug discovery in antibodies and TCRs.
- Company website: https://www.alloytx.com
- Type: Startups
- Level: Senior
- Location: Remote (US)
- Work setup: Remote
- Pay: $150K to $200K base salary per year (USD)
- Posted: 2026-07-20
- Apply by: 2026-10-12
- Apply: https://alloytherapeutics.applytojob.com/apply/a2qEIipAG7/Information-Security-Lead
- Page: https://www.1752.vc/careers/jobs/alloy-therapeutics-information-security-lead/

## About the role

We support the individuality of what people need to do outside of work to empower them to do their best at work. While you focus on making better medicine together , we focus on programs and benefits that support a diverse and growing team. Whether you’re single, in a growing family, or nearing retirement, Alloy offers a variety of comprehensive and competitive benefits starting from day one.

## What they're looking for

- Hands-on experience with cloud security across Google Workspace and AWS (or GCP/Azure equivalent), including IAM design, cloud storage security, and logging and monitoring configuration
- Experience defending against advanced and nation-state-level threat actors, and supporting sovereign, government, or other high-assurance programs with elevated security and data-residency requirements
- Experience implementing MFA programs including FIDO2/hardware key standards (e.g., YubiKey) and SSO/SCIM provisioning across a SaaS environment
- Demonstrated experience with backup architecture design, including immutable and geo-redundant backup solutions, and with running and documenting restore tests
- Familiarity with compliance frameworks including SOC 2 Type 2 and/or ISO 27001 — ideally you have worked through an audit or certification process and understand what evidence-ready looks like in practice
- Experience writing security policies and documentation that can withstand external scrutiny (AUPs, IRPs, BCP/DR plans, vulnerability management programs) as living operational documents

