Senior Staff Engineer - DevSecOps
ExelixisAbout the role
SUMMARY/JOB PURPOSE (Basic purpose of the job):
Protect the organization’s digital infrastructure, data, and systems from internal and external cybersecurity threats by implementing, managing, and continuously improving security practices, tools, and operations with a focus on cloud applications and infrastructure.
ESSENTIAL DUTIES/RESPONSIBILITIES:
- Design and implement robust security architectures for cloud environments following best practices, industry standards, and regulatory requirements.
- Lead cross-functional collaboration on technology initiatives to strengthen security across systems and operations, ensuring alignment with organizational objectives and industry best practices.
- Lead the investigation and resolution of complex security events and incidents, including malware outbreaks, unauthorized access attempts, and significant security breaches. Develop and implement response strategies, coordinate cross-functional teams, and ensure lessons learned are integrated into security policies and controls.
- Analyze security logs and events from various sources to proactively develop and implement security measures that address current and emerging threats.
- Provide updates to leaders on latest threat landscape, emerging trends, and propose cybersecurity solutions to proactively identify and mitigate potential security risks.
- Enhance the organization’s security posture by assessing vulnerabilities and recommending solutions to address identified weaknesses.
- Collaborate with internal teams, vendors, and partners to provide guidance and expertise on security best practices and incident response.
- Ensure compliance with industry standards and organizational policies, including SOX and FDA regulatory requirements, by following established procedures and controls.
SUPERVISORY RESPONSIBILITIES:
- No supervisory responsibilities.
EDUCATION/EXPERIENCE/KNOWLEDGE & SKILLS:
Education:
- Bachelor’s degree in related discipline and 9 years of related experience; or
- Master’s degree in related discipline and 7 years of related experience; or
- Equivalent combination of education and experience
- CISSP, CISM, CEH, OSCP, GIAC or similar cybersecurity certification preferred
Experience:
- Experience with operation and implementation of cybersecurity tools.
- Experience in designing, implementing, and managing security controls within cloud platforms, such as IAM, VPC, Zero Trust principles, IaC, IAAS, Security Groups, Key Management Services, SDLC, Ci/Cd pipelines and Network Security.
- Experience in IT Security or related infrastructure administration role in an enterprise environment. Technical lead or management experience preferred.
- Experience in investigations and response to cyber events and incidents.
- Experience in enhancing organizational security awareness and resilience.
- Experience with cloud, system, and application security.
- Experience administering IT systems.
- Experience working in Agile environments and using ticketing systems (e.g., JIRA, JSM).
- Experience in regulated industries (e.g., biotech, pharma) with knowledge of GxP and SOX compliance preferred.
Knowledge, Skills and Abilities:
- Advanced analytical, problem solving, organizational, and communication skills.
- General knowledge of Agile, and Design-Thinking, User-centric Design methodologies.
- Able to plan, prioritize, and execute projects with minimum supervision and high reliability.
- Strong understanding of PII, PHI, and Sensitive Data concepts
- Knowledge of applicable laws and regulations such as GDPR and CPRA.
- Strong analytical, problem solving, organizational, and communication skills.
- Ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability.
- Ability to multitask and work collaboratively.
- Ability to work with ambiguity.
- Ability to work with confidential data.
- Ability to continuously learn and improve.
- Ability to work with minimal guidance, to adapt to frequent priority changes, and response to ad-hoc requests
- Architect secure cloud infrastructure using guardrails and golden paths using IaC patterns across AWS and Azure.
- Integrate SAST, SCA, DAST, and dependency scanning into GitHub pipelines and provide help and support
- AWS Certified Security - Specialty preferred
Work Environment/Physical Demands:
Our office is a modern, open space that fosters collaboration and creativity. Teams work closely together, shar
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s