Senior Manager, Cybersecurity
Xenon PharmaceuticalsAbout the role
Who We Are:
Xenon Pharmaceuticals (NASDAQ:XENE) is a neuroscience-focused biopharmaceutical company committed to discovering, developing, and commercializing innovative therapeutics to improve the lives of people living with neurological and psychiatric disorders. We are looking for great people who thrive in a respectful, collaborative, inclusive, and productive culture to join the Xenon team.
What We Do:
We are advancing an exciting product pipeline to address indications with high unmet medical need, including epilepsy and depression. Our flagship azetukalner program represents the most advanced potassium channel modulator in clinical development for multiple indications. Building upon the positive results and compelling data from our Phase 2b “X-TOLE” study in adult patients with focal epilepsy, our Phase 3 epilepsy program includes multiple clinical trials evaluating azetukalner in patients with focal onset seizures and primary generalized tonic-clonic seizures. In 2024, we are planning to initiate a Phase 3 azetukalner program in major depressive disorder, based on topline data from our Phase 2 “X-NOVA” clinical trial. In addition, we are proud of the leading-edge science coming out of our discovery labs, including early-stage research programs that leverage our extensive ion channel expertise and drug discovery capabilities to identify validated drug targets and develop new product candidates. Backed by a strong balance sheet to support our growth plans, we continue to build a fully integrated, premier neuroscience company with strong discovery, clinical development, corporate, and commercial operations.
About the Role:
We are seeking a Senior Manager, Cybersecurity to join our team. The Senior Manager, Cybersecurity will work closely with other members of the information technology team and a managed security services provider to monitor the company’s infrastructure and assist in responding to security events and/or incidents and the associated reporting, as well as the follow-through on findings from vulnerability assessments, penetration testing, and vendor risk assessments.
This position reports to the Senior Director, Information Security & IT Risk Management and will be in Boston, MA, USA. The level of the position will be commensurate with the candidate’s education and industry experience. This role is a hybrid position, requiring a minimum of 2 days per week in the office.
RESPONSIBILITIES:
• Oversee and work closely with the managed security services provider to monitor corporate infrastructure for security issues. This may include after-hours support in the event of security events and/or incidents.
• Manage security services provider resources and oversee performance of key operational tasks as determined by the managed security services provider agreement.
• Act as the first point of contact for incident escalations from managed security services provider and provide guidance on remediation.
• Investigate security events and incidents, and work with the managed security services provider and internal stakeholders to identify and execute follow up actions for remediation and security improvements.
• Continuously monitor, report on, and improve security posture metrics leveraging the M365 security stack.
• Test and evaluate security products and support the installation, updating, maintenance, and monitoring of security systems to protect corporate information and infrastructure.
• Spearhead vulnerability management and collaborate with the support and infrastructure teams to ensure that patches are deployed in a timely manner with minimal business impact.
• Report on organizational system vulnerabilities and patch status at regular intervals.
• Leverage threat intelligence from available sources to prioritize and guide risk mitigation efforts.
• Collaborate with business units and IT application leaders to assess and address security risks associated with new systems and vendors.
• Perform and document CRO, software, and software-as-a-service vendor cybersecurity risk assessments, SOC report reviews, and where necessary, contribute to privacy impact assessments.
• Work with third parties and internal stakeholders to plan, execute, and document vulnerability assessments and penetration testing, and consequent remediation.
• Contribute to the evolution of cybersecurity incident response, disaster recovery, and business continuity plans.
• Manage and update security standard documents and processes as needed in cooperation with internal stakeholders.
• Maintain internal security software tools and monitor internal and external policy compliance.
• Plan and lead regular tabletop exercises to test the cybersecurity incident response plan.
• Promote a culture of information security and risk aware
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s