Incident Response Lead – IT, Cybersecurity Fusion Center
Gilead SciencesAbout the role
At Gilead, we’re creating a healthier world for all people. For more than 35 years, we’ve tackled diseases such as HIV, viral hepatitis, COVID-19 and cancer – working relentlessly to develop therapies that help improve lives and to ensure access to these therapies across the globe. We continue to fight against the world’s biggest health challenges, and our mission requires collaboration, determination and a relentless drive to make a difference.
Every member of Gilead’s team plays a critical role in the discovery and development of life-changing scientific innovations. Our employees are our greatest asset as we work to achieve our bold ambitions, and we’re looking for the next wave of passionate and ambitious people ready to make a direct impact.
We believe every employee deserves a great leader. People Leaders are the cornerstone to the employee experience at Gilead and Kite. As a people leader now or in the future, you are the key driver in evolving our culture and creating an environment where every employee feels included, developed and empowered to fulfil their aspirations. Join Gilead and help create possible, together.
Job Description
POSITION SUMMARY
As a Cyber Security Incident Response Lead, you will be at the forefront of our organization's defense against Cyber threats. This hands-on technical role requires a seasoned Cybersecurity professional with extensive experience in Threat detection & Incident response, a strategic mindset, and the ability to guide and mentor other response teams. Your core role will be to orchestrate the response to complex cybersecurity incidents, ensuring effective mitigation strategies, and contributing to the enhancement of our overall cyber resilience. A key responsibility is to continually assess security monitoring effectiveness and to make recommendations to improve Cyber Security Incident Response capabilities. This position reports to the Director of Cyber Fusion Center (Global Cyber Security Operations) and works closely with key stakeholders in incident response roles company wide.
Office Location: Foster City, CA
ESSENTIAL JOB FUNCTIONS
Extensive knowledge and experience in handling Cyber Security threats and Incident response activities including Detection, Triage, Investigation, Remediation and Recovery from security issues.
Extensive experience as Security Incident commander, leading security investigations while liaising with IT Operations, legal, and business teams through security incidents
Extensive experience with designing, implementing, and optimizing a Security Incident Response process
Extensive experience with designing and implementing SOC and IR technologies including SIEM, EDR, UEBA, among other capabilities
Monitor security events to detect threats and analyze situations in context to detect advanced threats.
Alerts analysis
Investigate Incidents
Analyze Malware
Develop Security Operations Center detection tools, rules and intelligence to improve detection & investigation efficiency of the Center.
Assess new technologies, tests them in a lab environment and proposes them for SOC improvement.
Operate Security Operations Center devices to ensure high availability and security.
Maintain and operate SOC network, systems, workstations and other technical components.
On-call availability outside business hours.
REQUIRED SKILLS & JOB QUALIFICATIONS
Minimum 8+ years of IT experience with progressive responsibilities, and with at least 5 years of Cyber Security experience.
Security professional with a strong technical background in Cyber Security, Windows / Linux, Network Security, Security Operations Center (SOC), Cloud Security (AWS, Azure), MITRE ATT&CK or similar frameworks, Threat Analysis, IT Operations and Incident response
Strong verbal and written communication skills with the ability to adapt information delivery based on the target audience.
Ability to create or review procedures for protection of systems and applications.
Knowledge of information security principles, concepts, practices, systems software, database software, and immediate access storage technology to carry out activities relating to security certification and accreditation.
Ability to provide expert technical advice, guidance, and recommendations to management and other technical specialists on critical information technology security issues.
Recommends and coordinates the application of fixes, patches, & recovery procedures in the event of a security breach.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s