Jobs and Careers
EX

Senior Staff Engineer - DevSecOps

Exelixis
Alameda HQ, United States, United Statesfull_timeVerifiedPosted 29 Jul 2026
💰 $231,000/yr($163,000/yr$231,000/yr)

About the role

SUMMARY/JOB PURPOSE (Basic purpose of the job):

Protect the organization’s digital infrastructure, data, and systems from internal and external cybersecurity threats by implementing, managing, and continuously improving security practices, tools, and operations with a focus on cloud applications and infrastructure.

ESSENTIAL DUTIES/RESPONSIBILITIES:

  • Design and implement robust security architectures for cloud environments following best practices, industry standards, and regulatory requirements.
  • Lead cross-functional collaboration on technology initiatives to strengthen security across systems and operations, ensuring alignment with organizational objectives and industry best practices.
  • Lead the investigation and resolution of complex security events and incidents, including malware outbreaks, unauthorized access attempts, and significant security breaches. Develop and implement response strategies, coordinate cross-functional teams, and ensure lessons learned are integrated into security policies and controls.
  • Analyze security logs and events from various sources to proactively develop and implement security measures that address current and emerging threats.
  • Provide updates to leaders on latest threat landscape, emerging trends, and propose cybersecurity solutions to proactively identify and mitigate potential security risks.
  • Enhance the organization’s security posture by assessing vulnerabilities and recommending solutions to address identified weaknesses.
  • Collaborate with internal teams, vendors, and partners to provide guidance and expertise on security best practices and incident response.
  • Ensure compliance with industry standards and organizational policies, including SOX and FDA regulatory requirements, by following established procedures and controls.

SUPERVISORY RESPONSIBILITIES:

  • No supervisory responsibilities.

EDUCATION/EXPERIENCE/KNOWLEDGE & SKILLS:

Education:

  • Bachelor’s degree in related discipline and 9 years of related experience; or
  • Master’s degree in related discipline and 7 years of related experience; or
  • Equivalent combination of education and experience
  • CISSP, CISM, CEH, OSCP, GIAC or similar cybersecurity certification preferred

Experience:

  • Experience with operation and implementation of cybersecurity tools.
  • Experience in designing, implementing, and managing security controls within cloud platforms, such as IAM, VPC, Zero Trust principles, IaC, IAAS, Security Groups, Key Management Services, SDLC, Ci/Cd pipelines and Network Security.
  • Experience in IT Security or related infrastructure administration role in an enterprise environment. Technical lead or management experience preferred.
  • Experience in investigations and response to cyber events and incidents.
  • Experience in enhancing organizational security awareness and resilience.
  • Experience with cloud, system, and application security.
  • Experience administering IT systems.
  • Experience working in Agile environments and using ticketing systems (e.g., JIRA, JSM).
  • Experience in regulated industries (e.g., biotech, pharma) with knowledge of GxP and SOX compliance preferred.

Knowledge, Skills and Abilities:

  • Advanced analytical, problem solving, organizational, and communication skills.
  • General knowledge of Agile, and Design-Thinking, User-centric Design methodologies.
  • Able to plan, prioritize, and execute projects with minimum supervision and high reliability.
  • Strong understanding of PII, PHI, and Sensitive Data concepts
  • Knowledge of applicable laws and regulations such as GDPR and CPRA.
  • Strong analytical, problem solving, organizational, and communication skills.
  • Ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability.
  • Ability to multitask and work collaboratively.
  • Ability to work with ambiguity.
  • Ability to work with confidential data.
  • Ability to continuously learn and improve.
  • Ability to work with minimal guidance, to adapt to frequent priority changes, and response to ad-hoc requests
  • Architect secure cloud infrastructure using guardrails and golden paths using IaC patterns across AWS and Azure.
  • Integrate SAST, SCA, DAST, and dependency scanning into GitHub pipelines and provide help and support
  • AWS Certified Security - Specialty preferred

Work Environment/Physical Demands:

Our office is a modern, open space that fosters collaboration and creativity. Teams work closely together, shar

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Exelixis

View company profile →