IDEXX Laboratories logo

Senior InfoSec Risk & Compliance Specialist

IDEXX Laboratories
  • Westbrook, Idaho
  • Autofill and Review
3 days ago

Job Description

Our cybersecurity and information security teams at IDEXX contribute to a more resilient, adaptable, and security-aware enterprise prepared to navigate today’s evolving threat landscape. We have complex, multi-dimensional programs across the organization that support all the technology needed to deliver products and solutions to customers - enabling them to focus on delivering high quality patient care.


IDEXX's Information Security team safeguards the organization against cyber risk and ensures compliance with industry standards and regulations. The Governance, Risk & Compliance (GRC) group leads governance policy, cyber risk management, third-party risk, SOX compliance, SOC 2 compliance, global privacy compliance, and cyber risk training and assessments.


The InfoSec Compliance team supports SOC 2, SOX, and PCI audits, and its coverage is expanding quickly: new European requirements could bring approximately 33 additional products into scope, including products without existing SOC 2 reports, and emerging state-level cybersecurity requirements (including Colorado and California) are adding further obligations. Because headcount will not scale at the same pace as this expanding scope, technology and automation are central to how the team succeeds.


As a Senior InfoSec Risk & Compliance Specialist, you will help modernize how the compliance function operates — moving the team from point-in-time, retrospective evidence collection toward continuous control monitoring and a shared foundation of evidence that supports multiple audits and regulatory obligations at once.


In This Role…

  • You will support SOC 2, SOX, and PCI audits, coordinating with external auditors and internal teams, and act as the first line of defense before internal or external review.
  • You will move the team beyond screenshot collection and backward-looking reviews of whether a control operated over the prior period, designing continuous monitoring that surfaces control failures as they happen.
  • You will identify opportunities to modernize compliance work — through API integrations, configurable GRC/compliance platforms, dashboards and visualizations, practical AI use, or well-built Excel solutions — and take ownership of implementing them.
  • You will connect compliance findings to organizational risk, distinguishing significant control failures (for example, missing encryption) from lower-risk documentation gaps, and drive appropriately prioritized remediation.
  • You will help build a common foundation of controls and evidence that can flex to support multiple regulatory obligations — SOC 2, SOX, PCI, and emerging EU and state requirements — without a one-to-one increase in headcount.
  • You will support and provide some coaching and feedback to a Grade 600 teammate who owns aspects of the SOC 2 program; this role can appeal to someone building toward future people leadership, though no management progression is guaranteed.
  • You will communicate tactical and strategic updates to business teams and leaders, and bring an autonomous, curious, and forward-thinking approach rather than repeating the same audit the same way each year.

What You Will Need to Succeed…

  • 5 to 7+ years of experience within IT Audit, GRC, Controls, Risk Assessment, or Internal Audit. Experience across all of SOC 2, SOX, and PCI is not required — core audit skills transfer well.
  • At least one year of experience performing readiness assessments for SOC 2 (or comparable) compliance.
  • One of these certifications: CISA, CISM, CISSP, CRISC, CRMA, or certification-eligible.
  • Working knowledge of control and risk frameworks such as NIST, COSO, and COBIT, and how to develop and implement controls through them.
  • Practical, hands-on use of AI tools in your day-to-day work — for example, using AI to digest and research complex or unfamiliar regulations. Experience building AI agents or automated compliance workflows is a strong plus, not a requirement.
  • A track record of proactively identifying problems, proposing technology-based improvements (automation, integrations, dashboards, or similar), and owning them through implementation — autonomy, accountability, curiosity, and adaptability are central to this role.
  • Comfort approaching unfamiliar or emerging requirements (for example, the EU AI Act or the NIST AI Risk Management Framework) by structuring the work yourself — scoping what exists, identifying gaps, and building a plan — rather than following an established playbook.
  • Strong written and verbal communication, with the ability to build relationships at all levels of the organization and to coach or mentor less experienced teammates.
  • The ability to handle difficult issues in a professional, assertive, and proactive manner.
  • Location: We are only considering those within the New England area of Maine, New Hampshire or Massachusetts. If local, we offer a flexible, hybrid of 8 days per month on site and we will consider less if you are further away.

What You Can Expect From Us:

  • Base annual salary starting at $120,000, with flexibility based on experience
  • Opportunity for annual cash bonus
  • Health / Dental / Vision Benefits Day-One
  • 5% matching 401k
  • Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!

Why IDEXX?

We’re proud of the work we do, because our work matters. An innovation leader in every industry we serve, we follow our Purpose and Guiding Principles to help pet owners worldwide keep their companion animals healthy and happy, to ensure safe drinking water for billions, and to help farmers protect livestock and poultry from diseases. We have customers in over 175 countries and a global workforce of over 10,000 talented people.

So, what does that mean for you? We enrich the livelihoods of our employees with a positive and respectful work culture that embraces challenges and encourages learning and discovery.   At IDEXX, you will be supported by competitive compensation, incentives, and benefits while enjoying purposeful work that drives improvement. 

Let’s pursue what matters together. 


IDEXX values a diverse workforce and workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply.

IDEXX is an equal opportunity employer. Applicants will not be discriminated against because of race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition, or any protected category prohibited by local, state, or federal laws.

#LI-EV1

Numbers & Facts

LocationWestbrook, Idaho
IndustryBiotechnology/Pharmaceuticals
Company Size5,000 to 9,999 employees
Year Founded1983

About Company

7,000 people, one global focus - enhancing the health and well-being of pets, people, and livestock

We are passionate about what we do at IDEXX – and why wouldn’t we be? When you’re working to raise the standard of care for pets, make drinking water safe for billions and keep our livestock population around the globe healthy and free of disease, it’s no wonder that what we do each day is more than just a job. There’s an energy across IDEXX that is contagious – where caring and committed people come together to make things better.

Skills

  • Artificial Intelligence (AI)unmatched
  • Artificial Intelligence (AI) Agentsunmatched
  • Automationunmatched
  • Building Regulationsunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Coachingunmatched
  • Committee of Sponsoring Organizations of the Treadway Commission (COSO)unmatched
  • Compensation and Benefitsunmatched
  • Control Objectives for Information and related Technology (COBIT)unmatched
  • Cryptographyunmatched
  • Diseaseunmatched
  • Documentationunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • External Auditunmatched
  • Federal Laws and Regulationsunmatched
  • Financial Supportunmatched
  • Fundraising Programunmatched
  • Identify Issuesunmatched
  • Industry Standardsunmatched
  • Information Technology/Systems Auditunmatched
  • Information/Data Security (InfoSec)unmatched
  • Insuranceunmatched
  • Internal Auditunmatched
  • Internet Privacyunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Mentoringunmatched
  • Online Trainingunmatched
  • PCIunmatched
  • Patient Careunmatched
  • Presentation/Verbal Skillsunmatched
  • Process Improvementunmatched
  • Psychiatry and Mental Healthunmatched
  • Regulationsunmatched
  • Reporting Dashboardsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Risk Management Framework (RMF)unmatched
  • Sarbanes-Oxley Act (SOX)unmatched
  • Tactical Communicationsunmatched
  • Technical Deliveryunmatched
  • Technical Supportunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder