
Information Security Officer
ScreenPoint Medical
Information Security Officer
ScreenPoint Medical, The Breast AI Company, seeks an Organizational Information Security Officer to lead and mature its information security program. The role focuses on ISO 27001 and SOC 2, working with cross-functional teams to embed security into operations, including AI-native governance. Requires strong knowledge of ISO 27001/SOC 2, risk management, and security architecture.
Information Security Officer
ScreenPoint Medical, The Breast AI Company, seeks an Organizational Information Security Officer to lead and mature its information security program. The role focuses on ISO 27001 and SOC 2, working with cross-functional teams to embed security into operations, including AI-native governance. Requires strong knowledge of ISO 27001/SOC 2, risk management, and security architecture.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Own, maintain, and continuously improve the ISMS, including governance processes, documentation, security objectives, management reviews, KPIs, and an organization-wide roadmap aligned with business goals and the QMS.
- Lead the implementation, operation, and continuous improvement of the security control environment for ISO 27001 and SOC 2, maintaining the control set, clarifying control ownership, defining operating cadences, collecting evidence, supporting audits, and tracking remediation.
- Build and operate a pragmatic security governance model, including policies, standards, risk assessments, risk treatment plans, exception handling, and leadership reporting.
- Partner with Infrastructure and Engineering to strengthen secure foundations across IAM, endpoint security, cloud security, logging and monitoring, encryption, backup and recovery, and vulnerability management.
- Own incident response planning and coordination, including playbooks, tabletop exercises, escalation paths, communication plans, and post-incident reviews.
- Establish and run a vendor risk management process, including supplier security reviews, contract/security requirement input, risk-based monitoring, and follow-up for critical suppliers.
- Build a security-first culture through practical training, clear guidance, and stakeholder enablement, acting as the primary point of contact for security inquiries, customer assurance requests, audits, and security-related decision-making.
- Support ScreenPoint's transition into an AI-native organization by helping define practical security principles for the responsible use of AI tools, data, automation, and emerging technologies.