Back to jobs

IT

Associate Director/Director, Information Security

  • Axsome Therapeutics
  • New York, NY
  • Full-time
  • Salary not listed

About the role

Axsome Therapeutics is a biopharmaceutical company leading a new era in the treatment of central nervous system (CNS) conditions. We deliver scientific breakthroughs by identifying critical gaps in care and develop differentiated products with a focus on novel mechanisms of action that enable meaningful advancements in patient outcomes. Our industry-leading neuroscience portfolio includes FDA-approved treatments for major depressive disorder, excessive daytime sleepiness associated with narcolepsy and obstructive sleep apnea, and migraine, and multiple late-stage development programs addressing a broad range of serious neurological and psychiatric conditions that impact over 150 million people in the United States. Together, we are on a mission to solve some of the brain’s biggest problems so patients and their loved ones can flourish. For more information, please visit us at www.axsome.com and follow us on LinkedIn and X . About This Role Axsome Therapeutics is seeking an Associate Director/Director Information Security to take a leadership role in threat management, incident response, and vulnerability management functions. Operating as a hands-on leader, this role directs the cybersecurity team and service providers while remaining actively engaged in technical work. The role executes and advances the corporate Information Security Program and Management System owned by the Head of Information Security, and responsible for maintaining our security posture during non-standard hours, including active weekend and evening monitoring and rapid response to high-priority security incidents, and perform additional responsibilities as assigned by IT leadership. The Associate Director/Director Information Security will report to the Sr. Director, Information Security. This role is based at Axsome’s HQ in New York City with an on-site requirement of at least three days per week. We are unable to consider candidates who are looking for fully remote roles. Job Responsibilities and Duties include, but are not limited to, the following: Security Operations & Threat Management Lead security monitoring and detection across MSP, SIEM, IDS/IPS, and the broader security toolset; personally triage, analyze, and escalate high-severity alerts Set alert prioritization and detection-engineering standards; directly tune detections, correlation rules, and use cases to improve signal quality Perform hands-on threat hunting with advanced techniques and tooling; operationalize hunting strategies and resulting mitigations Drive continuous improvement of security controls based on threat intelligence, hunt findings, and incident trends Incident Response Act as incident lead for significant business-impact security events, leading identification, containment, eradication, and recovery — including direct investigation and forensic analysis Maintain and mature incident response plans, runbooks, and playbooks; alert optimization; design and lead tabletop exercises to validate readiness Lead post-incident reviews, author executive-facing reports, and drive remediation of process and control gaps Vulnerability & Risk Management Lead the vulnerability management program; execute or validate scans, analyze results, and confirm remediation Apply risk-based prioritization and remediation SLAs aligned to business impact; report progress and residual risk Partner with IT Infrastructure & Operations and Application Development to drive timely patching and configuration hardening Vendor, MSP & Third-Party Risk Manage the cybersecurity vendor and MSP relationships; ensure effective service delivery and enforce SLAs Define provider KPIs; lead service reviews and drive continuous improvement Manage the Third-Party Risk Management (TPRM) program — vendor assessments, risk ratings, contract security requirements, and remediation tracking Program Support, Awareness & Team Leadership Oversee the cybersecurity awareness and training program; champion best practices, measure effectiveness, and drive improvements Support security audits and contribute to the continuous improvement of security policies, standards, and procedures within the corporate InfoSec Management System Manage the InfoSec project portfolio and directly contribute to technical workstreams as needed Manage, mentor, and develop cybersecurity team members while modeling hands-on technical excellence Data Protection & Insider Risk Support data protection initiatives including data classification, DLP monitoring, SaaS security assessments, and insider risk investigations Investigate potential data leakage events and coordinate containment activities Identity & Access Security Oversee security requirements related to identity governance, privileged access management (PAM), multifactor authentication (MFA), conditional access, and account lifecycle controls Review privileged-access risks and support periodic access recertifications Cloud Security Governance Support cloud security monitoring, hardening, and governance across Microsoft 365, Azure, and AWS environments Assist in reviewing and remediating cloud security posture findings, misconfigurations, excessive permissions, and identity-related risks Partner with Infrastructure teams to implement Zero Trust security controls Security Metrics & Executive Reporting Develop and maintain cybersecurity KPIs, KRIs, and executive dashboards Present operational security metrics, risk trends, and program maturity updates to leadership Requirements / Qualifications Bachelor’s degree in computer science, Information Security, or a related field 8–10 years of progressive information security experience, including 3+ years leading security operations, incident response, or security engineering functions Demonstrated hands-on proficiency with SIEM platforms, EDR/endpoint security, email security, and vulnerability management tooling Hands-on experience with network, cloud and SaaS security, particularly in AWS, Azure, Microsoft 365, Defender and Windows ecosystem Proven experience as an incident commander, performing hands-on investigation, containment, and forensics Experience managing MSPs/MSSPs and third-party risk programs, including SLA enforcement and vendor performance management Working knowledge of security frameworks and standards (NIST CSF, CIS Controls, ISO 27001) and audit/compliance processes Ability to proactively plan, organize, deliver with limited oversight, prioritize, and quickly adapt to changing situations Strong collaboration and negotiation skills, with a high degree of self-motivation, and ability to work independently with minimal supervision Strong attention to detail and a meticulous approach to security-related tasks Strong analytical skills and the ability to translate technical risk into business terms for leadership audiences Ability to support non-standard hours, including active evening/weekend monitoring and rapid response to high-priority incidents as needed Ability to work on-site Monday, Tuesday & Thursday. We are unable to consider candidates who are looking for fully remote roles Experience, Knowledge and Skills Scripting and automation skills (e.g., PowerShell, Python) for detection tuning, remediation, and deployment Proficient in security tools: CrowdStrike Falcon and NextGEN SIEM, Microsoft Defender and KnowBe4 Relevant certifications: CISSP, CISM, CISA, GIAC (GCIH / GCIA / GCFA), or equivalent Experience contributing to a formal Information Security Program or Management System (e.g., ISO 27001 ISMS) Player-coach leadership — balances team development and program execution with direct technical contribution Sound risk judgment and the ability to prioritize under pressure during active incidents Strong written and verbal communication, including executive-level reporting Collaboration across IT, application development, and business stakeholders Salary and Benefits: The anticipated salary range for this role is $170,000 - $220,000. The salary offer will be based on a variety of factors, including experience, qualifications, internal equity and location. Axsome offers a competitive employment package that includes an annual bonus, significant equity and a generous benefits package. Axsome is committed to equal employment opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, sexual orientation, gender identity, ancestry, citizenship, marital status, physical or mental disability, medical condition, veteran status, genetic information, or any other characteristic protected by federal, state, or local law. Axsome Therapeutics does not accept unsolicited resumes from recruiters or third-party recruitment agencies and will not pay placement fees for unsolicited candidates that are sent to hiring managers, the HR team or other Axsome team members. Only approved vendors who have been explicitly asked to support a specific search will receive access to our Applicant Tracking System to submit candidates for consideration.