
Black Swans Exist
We are looking for an experienced Information Security (Senior) Manager to join a growing, international life science company on an exciting journey of scaling and maturing its information security and governance setup.
This role is especially relevant for someone who has helped a biotech, pharma, medtech, or life science organisation mature its information security system from research and clinical-stage operations toward late-stage development, launch readiness, commercial operations, or marketed products.
The position can be based in either our Copenhagen or Boston site, with close collaboration across an international organisation.
This is an opportunity to play a key role in strengthening a modern security program in an organisation where research, innovation, collaboration, and operational excellence are central to the business. You will work closely with senior security leadership and stakeholders across the organisation to ensure that information security enables the business – rather than slows it down.
As Information Security Manager, you will help drive the implementation, execution, and continuous improvement of security controls, risk management processes, and compliance activities across the organisation. The role sits at the intersection of information security, IT risk, IT compliance, data protection, business continuity, and regulated life science operations.
You will help mature and maintain the company’s Information Security Management System and support the organisation in embedding strong, pragmatic security practices into daily operations and future commercial readiness.
Your responsibilities will include:
· Driving the implementation and execution of information security controls aligned with frameworks and regulations such as ISO 27001, GDPR, NIS2, relevant IT financial controls, and applicable life science compliance expectations
· Supporting, improving, and scaling the company’s Information Security Management System as the organisation grows internationally
· Driving risk assessments, control evaluations, remediation activities, and control documentation across business-critical systems and processes
· Collaborating with stakeholders across IT, R&D, clinical development, quality/GxP, finance, legal/privacy, business operations, and commercial-readiness functions to ensure security requirements are built into processes, systems, and ways of working
· Translating business and regulatory needs into practical security controls for areas such as vendor risk, data protection, validated or GxP-relevant systems, clinical and quality processes, medical or commercial platforms, and sensitive patient, HCP, or research data
· Preparing security reporting, risk summaries, control-status updates, and governance documentation for senior security leadership and business stakeholders
· Supporting internal audits, external assessments, due diligence activities, and compliance work related to information security, IT risk, privacy, financial controls, and regulated life science operations
· Strengthening security awareness, training, and the overall security culture across the organisation
It’s important that you have previously supported a biotech mature its information security system as it has moved from research and clinical-stage operations toward late-stage development, launch readiness, commercial operations, or marketed products.
You have experience working with information security, risk management, continuity planning, IT compliance, or security governance in environments where governance, structure, audit readiness, and compliance matter.
Candidates from other regulated or high-stakes industries, such as financial services, healthcare, critical infrastructure, technology, or other environments where risk has real consequences, may also be relevant if they can translate that experience into a life science context.
You are someone who can translate business needs into practical controls and security processes that work in the real world. You understand that effective security is not about creating unnecessary friction – it is about helping the business operate safely, confidently, and efficiently.
You are comfortable working hands-on in a growing organisation, where not everything is fully built yet, and where pragmatic judgement is as important as framework knowledge.
We imagine that you bring:
· A bachelor’s or master’s degree within information security, law, technology, business, life sciences, or another relevant discipline
· 5+ years of experience within information security, IT risk, IT compliance, security governance, risk management, compliance, or continuity planning
· Experience from pharma, biotech, medtech, life science, healthcare, or another regulated environment; experience with late-stage development, launch readiness, commercial operations, or marketed products is a strong advantage
· A strong process mindset and an ability to build fit-for-purpose security governance in a growing organisation
· Familiarity with cybersecurity regulations and frameworks such as NIS2, GDPR, ISO 27001, NIST, or comparable regulatory frameworks
· Experience working with security policies, control frameworks, risk registers, audits, remediation plans, vendor risk, control testing, or compliance documentation
· Exposure to GxP, computer system validation, GAMP 5, EU Annex 11, FDA 21 CFR Part 11, pharmacovigilance, medical affairs, clinical systems, or commercial life science systems is considered a strong advantage, but not an absolute requirement
· The ability to communicate clearly with both technical teams and business stakeholders across an international organisation
· A pragmatic and proactive mindset, with a strong interest in continuously improving security maturity and enabling the business
· Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, CISA, or similar are considered an advantage, but not a requirement.
This is a chance to join an ambitious, international life science organisation at an important stage of growth, where information security is becoming increasingly important as the company matures.
You will have the opportunity to help shape and mature the security function, work closely with committed colleagues across the business, and contribute to building a strong, resilient, and scalable security setup for a regulated environment preparing for its next stage of development and growth.

Managing Director & Co-founder
Per is the Managing Director and Co-founder of Black Swans Exist, a role he has held since the company's inception in June 2020. Based in Copenhagen, Per brings a visionary approach to the business, helping companies discover rare, high-impact talent, or "Black Swans," that drive extraordinary performance.
View Profile