Jobs and Careers
ER

Associate Director, IT Cyber Security

Erasca
San Diego, United StatesRemotefull_timeVerifiedPosted 18 Mar 2025
💰 $207,500/yr($185,000/yr$207,500/yr)

About the role

Erasca is a clinical-stage precision oncology company focused on discovering, developing and commercializing medicines for the benefit of patients with cancer. Our programs take novel approaches to shutting down one of cancer’s most commonly mutated signaling cascades, the RAS/MAPK pathway, which affects approximately 5.5 million lives each year worldwide. The name “Erasca” has an important embedded meaning: it is a contraction of our audacious hope to “erase cancer” that drives our mission and everything that we do on behalf of patients with cancer.

Position Summary: 

Reporting to the Director IT & Operations, the Associate Director IT Cyber Security will be responsible for designing and implementing robust security strategies to protect our organization’s assets and employees. The ideal candidate will have a strategic mindset and a deep understanding of Cyber Security, Security Protocols, Security Operations Centers (SOC), Risk Management, Compliance, Vulnerability Management, Patch Management, Penetration Testing and Auditing, and Disaster Recovery. Additionally, the Associate Director IT Cyber Security will play a key role in assisting with the revamp of our Security Strategic Roadmap. 

You will work closely with the Head of IT and the Systems Team to ensure that all security initiatives align with the company’s goals and regulatory requirements. You will lead organization-wide data security objectives, enforce compliance across all departments, and develop and deliver comprehensive security training programs. The successful candidate will have a proven track record in security management, strong leadership skills, and the ability to perform effectively under pressure. This role requires an effective communicator with a proactive, solutions-driven approach to identifying and mitigating security threats. Experience in the biotech sector (or related life-science industries) is strongly preferred, given the need to comply with industry-specific regulations and standards such as GxP. 

Essential Duties and Responsibilities:  

Security Governance & Strategy 

  • Develop and implement security policies and procedures to safeguard organizational assets. 
  • Lead the creation and execution of a comprehensive Security Program, focusing on Security Information and Incident Management (SIEM). 
  • Assist in the development and continuous improvement of the Security Strategic Roadmap, ensuring alignment with business objectives. 

Data Security Objectives & Cross-Departmental Compliance 

  • Lead organization-wide data security initiatives—defining objectives, metrics, and performance indicators to measure success. 
  • Enforce data security compliance across all departments, working with departmental heads to ensure alignment with relevant regulations (e.g., HIPAA, GDPR, GxP, SOX). 
  • Develop and deliver security awareness and training programs, ensuring every employee understands and follows security best practices and regulations. 

Security Operations 

  • Oversee daily security operations, including the management of tools and systems such as: 
    • Microsoft Security Tools (Sentinel, Microsoft Defender, Purview, XDR, EDR) 
    • Anti-virus and endpoint protection tools 
    • Security Information and Event Management (SIEM) 
    • Firewalls, Intrusion Detection and Prevention Systems (IDS/IPS) 
    • Cloud infrastructure and application security 
    • Patch and Vulnerability Management 
  • Coordinate with security vendors as needed to enhance system functionality. 

Risk Management & Assessments 

  • Perform regular risk assessments, security audits, and vulnerability assessments to proactively identify and address security risks. 
  • Apply NIST and CIS risk scoring methodologies to prioritize remediation efforts and measure risk levels over time. 
  • Review and update Information Security Standard Operating Procedures (SOPs) to ensure they align with evolving threats and industry best practices.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Erasca

View company profile →