<div class="content-intro"><p><span style="font-size: 10pt;">Iterative Health is a healthcare technology and services company powering the acceleration of clinical research to transform patient outcomes.</span></p><p><span style="font-size: 10pt;">We built a leading performance-driven network of 100+ sites across the US, Europe, India, and Australia, conducting research directly in the communities where care is delivered across gastrointestinal, hepatology, obesity, and cardiology. By combining deep clinical trial expertise with cutting-edge AI, we connect sponsors' scientific ambitions with high-performing research teams that expedite and expand access to novel therapeutics for patients in need. Today, Iterative Health is headquartered in Cambridge, Massachusetts, and New York City with 250+ employees world-wide.</span></p><p> </p></div><p></p><p><span style="font-size: 10pt;">As Iterative Health's first dedicated cybersecurity hire, you won't be stepping into an existing security program—you'll be building it. This is a rare opportunity to establish and lead the company's cybersecurity strategy, creating the foundation that will protect our people, technology, data, and business as we continue to scale.</span></p><p><span style="font-size: 10pt;">In this role, you'll own the end-to-end security landscape, including our AWS cloud infrastructure, identity and access management, SaaS ecosystem, endpoint security, sensitive clinical and patient data, and the security and compliance frameworks that support our business. You'll work cross-functionally with IT, Engineering, Compliance, Legal, and business leaders to strengthen our security posture, reduce organizational risk, and embed security into every aspect of the company.</span></p><p><span style="font-size: 10pt;">We're looking for a hands-on security leader who combines deep technical expertise with strong business judgment and a builder's mindset. You'll be equally comfortable architecting security solutions, responding to evolving threats, developing policies and controls, and influencing stakeholders across the organization. This is an opportunity to create a scalable, modern security program that grows alongside a fast-paced healthcare technology company.</span></p><p> </p><p><span style="font-size: 10pt;"><strong>Where You’ll Drive Impact </strong></span></p><p><span style="font-size: 10pt;">Security Program Development</span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Serve as Iterative Health's first dedicated cybersecurity resource — build, mature, and operate the company's security program from the ground up.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Identify security gaps, prioritize remediation, and partner with the IT Director to define security priorities, roadmap items, and risk reduction plans.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Develop, maintain, and enforce security policies, standards, procedures, runbooks, and control documentation.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Provide company-wide subject matter expertise and support related to cybersecurity awareness and compliance.</span></li></ul><p><span style="font-size: 10pt;">Cloud & Infrastructure Security</span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Work with engineering team to secure and monitor AWS environments, including IAM, logging, encryption, backups, access controls, and overall cloud security posture.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Configure firewalls, encryption, and access controls across cloud and corporate infrastructure.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Improve security controls across Okta, Entra ID, Microsoft 365, Google Workspace, Box, SharePoint, AWS, and other cloud platforms.</span></li></ul><p><span style="font-size: 10pt;">Identity & Access Governance</span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Maintain and improve RBAC, access reviews, privileged access controls, admin role governance, service account oversight, and joiner/mover/leaver security processes.</span></li></ul><p><span style="font-size: 10pt;">Incident Response</span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Own incident response for suspected cyberattacks, account compromise, malware, data exposure, unauthorized access, and other security events.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Lead incident investigation, containment, remediation, documentation, root-cause analysis, and post-incident improvement tracking.</span></li></ul><p><span style="font-size: 10pt;">Compliance & Risk Management</span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Own security evidence collection, control documentation, remediation tracking, and audit support for SOC 2, HIPAA/HITECH, and applicable GDPR requirements.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Own all vendor assessment and security questionnaire responses.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Support vulnerability management, penetration testing, social engineering testing, customer security reviews, vendor security questionnaires, third-party risk assessments, security awareness, and user education.</span></li></ul><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Performs related duties as requested </span></li></ul><p><span style="font-size: 10pt;"><strong>What You Bring to the Team</strong></span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Bachelor's degree in IT, engineering, mathematics, or a related field; candidates with extensive cybersecurity certification in lieu of a degree will be considered.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">5+ years of experience in cybersecurity, security engineering, cloud security, IT security, or a related technical security role.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Strong working knowledge of HIPAA, HITECH, SOC 2, and HITRUST frameworks.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Hands-on experience with AWS, Microsoft 365, and Google Workspace security tooling.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Experience with Bitdefender, Microsoft Defender, Intune, Entra ID, Microsoft Purview, Google Workspace security, Okta, or SIEM/logging tools.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Strong documentation skills, including policy and procedure writing.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Ability to communicate effectively with non-technical business partners.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Experience with PowerShell, Python, APIs, or security workflow automation.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Experience with vulnerability management, penetration test remediation, phishing simulation programs, or third-party risk reviews.</span></li></ul><p><span style="font-size: 10pt;"><strong>Preferred Qualifications</strong></span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Knowledge of EU General Data Protection Regulation (GDPR).</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">One or more relevant certifications, including but not limited to: CompTIA Security+, CySA+, or Pen Test+; GCIH; ISC2 CCSP; AWS Certified Security Specialty (SCS-C03); Microsoft SC-200, SC-300, SC-401, SC-100, or SC-900; Google Cybersecurity Professional or Cloud Cybersecurity Certificate.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Experience building or maturing a security program in a high-growth or startup environment.</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Background in healthcare technology, clinical research, or other highly regulated industries.</span></li></ul><p> </p><p><span style="font-size: 10pt;"><strong>How We Work </strong></span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Collaborative and low-ego team environment</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">High ownership and accountability culture</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Fast-paced and highly iterative growth environment</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Open communication and continuous learning mindset</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Mission-driven organization focused on improving patient outcomes</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Comfortable navigating evolving business priorities and opportunities</span></li></ul><p><br><br><br></p><p><span style="font-size: 10pt;"><strong>Benefits That Support You </strong></span></p><p><span style="font-size: 10pt;">We believe great teams do their best work when they feel supported — professionally and personally.</span></p><ul><li style="font-size: 10pt;"><span style="font-size: 10pt;">Hybrid work environment with in-office collaboration two days per week in either our NYC or Boston office</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Comprehensive medical, dental, and vision coverage, with up to 80% of premiums covered by Iterative Health</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Mental health and wellness support through Spring Health</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Health HSA or FSA options, and commuter FSA contributions supported by Iterative Health</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Unlimited PTO, 12 company holidays, and a company-wide shutdown between Christmas and New Years</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">401(k) program with a company match of up to 3% (up to $3,000 annually)</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Weekly in-office lunch benefit every Tuesday</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">100% company-paid short-term and long-term disability coverage</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">Annual wellness and professional development stipend to support your health and growth</span></li><li style="font-size: 10pt;"><span style="font-size: 10pt;">And more!</span></li></ul><p><br><br></p><div class="content-conclusion"><p><span style="font-size: 10pt;">At Iterative Health, we’re actively working towards creating an environment that is representative of the diversity of patients our technology serves. We are focused on building an equitable and inclusive culture, and by extension, hiring process. If you require any accommodations to make the application process or interviewing experience more accessible to you, please contact CandidateAccommodations@iterative.health.</span></p></div>