Senior Cybersecurity Engineer
Travere TherapeuticsAbout the role
Department:
101180 IT-G&ALocation:
San Diego, USA- RemoteBe a part of a global team that is inspired to make a difference in the lives of people living with rare disease.
At Travere Therapeutics, we recognize that our exceptional employees are vital to our success. We are a dedicated team focused on meeting the unique needs of rare patients. Our work is rewarding – both professionally and personally – because we are making a difference. We are passionate about what we do.
We are seeking talented individuals who will thrive in our collaborative, diverse, fast-paced environment and share in our mission – to identify, develop and deliver life-changing therapies to people living with rare disease. We stick by our values centered on patients, courage, community, and collaboration to pursue our vision of becoming a leading biopharmaceutical company dedicated to the delivery of innovation and hope to patients in the global rare disease community.
At Travere Therapeutics, we are in rare for life. We continue to courageously forge new paths as we move toward a common goal of elevating science and service for rare patients.
Position Summary:
We are seeking a Senior, hands-on Cybersecurity Engineer with deep technical expertise and a strategic mindset to help lead and advance Travere’s security program.
In this role, you will shape and enforce cybersecurity practices, oversee daily security operations, and drive continuous improvement of our managed SOC services. You will play a critical role in managing core security platforms, leading incident investigations, guiding risk assessments, and ensuring audit and compliance readiness, while also managing and driving progress on the company's NIST roadmap.
Responsibilities:
Support and enhance the company’s cybersecurity program in alignment with NIST CSF 2.0 and related frameworks (e.g., NIST SP 800-53, 800-171).
Manages Travere’s NIST roadmap, driving progress and ensuring it remains current.
Oversees Travere’s SOC services, including:
Managing escalations, tuning detection logic.
Investigating security alerts and incidents.
Enhancing SOC workflows and playbooks.
Operate and maintain key security tools:
EDR, SIEM, firewalls, vulnerability scanners, etc.
Ensure integration and effectiveness across platforms.
Administer identity and access management using Okta and Microsoft Entra ID (Azure AD):
- Enforce MFA, SSO, and lifecycle access controls.
Oversees the integration and management for any new identity and access management solutions within the infrastructure.
Manage Travere’s Privileged Access Management (PAM) platform – Delinea “Secret Server”:
Onboarding privileged accounts, policy enforcement, and ongoing maintenance.
Perform vulnerability assessments and support remediation efforts with IT and cloud teams.
Document incidents, systems, tooling configurations, and audit evidence.
Support SOX, GxP, data privacy, and other compliance initiatives with technical input and control documentation.
Education/Experience Requirements:
Bachelors degree in related Computer Science discipline. Equivalent combination of education and applicable job experience may be considered.
6–8+ years of hands-on cybersecurity engineering or SOC experience.
CISSP certification required. OSCP, GCIH, or GCIA (or equivalent) preferred.
Prior experience in a regulated industry (i.e. life sciences, pharma, biotech, fintech).
Familiarity with SOX, GxP, ISO 27001, and other security/compliance standards.
Strong command of NIST frameworks and security operations best practices.
Experience with:
Okta, Azure/Entra ID, Delinea “Secret Server”, Microsoft Defender, Wiz CNAPP, Cylance/Aurora, Mimecast, Palo Alto.
Operating in hybrid cloud environments (Windows, Linux, AWS, Azure).
Scripting/automation experience with PowerShell, Python, or Bash.
Additional Skills/Experience/Requirements:
The ideal candidate will embody Travere’s core values: Courage, Community Spirit, Patient Focus and Teamwork.
Demonstrated ability to develop and mature enterprise security roadmaps.
Experience aligning cybersecurity initiatives with overall business strategy and risk tolerance.
Experience with third-party/vendor risk management in regulated industries.<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s