Director, Cybersecurity
Zenas BioPharmaAbout the role
Zenas is a clinical-stage global biopharmaceutical company committed to becoming a leader in the development and commercialization of transformative therapies for patients with autoimmune diseases. Our core business strategy combines our experienced leadership team with a disciplined product candidate acquisition approach to identify, acquire and develop product candidates globally that we believe can provide superior clinical benefits to patients living with autoimmune diseases. Zenas is advancing two late-stage, potential franchise molecules, obexelimab and orelabrutinib. Obexelimab, Zenas’ lead product candidate, is a bifunctional monoclonal antibody designed to bind both CD19 and FcγRIIb, which are broadly present across B cell lineage, to inhibit the activity of cells that are implicated in many autoimmune diseases without depleting them. We believe that obexelimab’s unique mechanism of action and self-administered, subcutaneous injection regimen may broadly and effectively address the pathogenic role of B cell lineage in chronic autoimmune disease. Orelabrutinib is a potentially best-in-class, highly selective CNS-penetrant, oral, small molecule Bruton’s Tyrosine Kinase (BTK) inhibitor with the potential to address compartmentalized inflammation and disease progression in Multiple Sclerosis (MS). Zenas’ earlier stage programs include a preclinical, potentially best-in-class, oral, IL-17AA/AF inhibitor, and a preclinical, potentially best-in-class, oral, brain-penetrant, TYK2 inhibitor.
We are seeking top talent who share our commitment to patients and have a track record of success in acquiring, developing and commercializing products across the globe. Our colleagues have an opportunity to engage in a fast-paced learning environment and experience individual and organizational success as we work towards becoming a global immunology and autoimmune disease leader, while living our values of Transparency, Relationships, Urgency, Excellence and Innovation – TRUE Innovation!
Position Summary:
The Director of Cybersecurity will serve as the cybersecurity leader for Zenas BioPharma, responsible for defining, implementing, and managing the company’s cybersecurity program, data privacy initiatives, and third-party risk management framework. Reporting directly to the Head of Information Technology, this individual contributor role partners across the organization to protect sensitive intellectual property, clinical trial data, patient information, and corporate systems.
This is a hands-on leadership role well suited for a cybersecurity professional comfortable working in a fast-paced, lean biotech environment. The Director will own both strategic vision and tactical execution, working with managed security service providers (MSSPs) and vendor partnerships to deliver strong security capabilities. The right candidate will bring solid experience in regulated industries and the ability to operate effectively as Zenas advances toward commercial launch and increased regulatory scrutiny.
Key Responsibilities:
Cybersecurity Strategy & Operations
- Develop and execute the enterprise cybersecurity strategy, roadmap, and supporting policies aligned with business objectives, regulatory obligations, and the company’s risk appetite.
- Manage and continuously improve the cybersecurity program including threat detection and response, vulnerability management, endpoint protection, identity and access management, email security, and cloud security.
- Own the cybersecurity incident response plan; lead investigation and remediation efforts for security events and breaches, coordinating with external forensic resources as needed.
- Conduct regular risk assessments and penetration tests; drive remediation across on-premises, cloud, and SaaS environments.
- Stay current on emerging threats, including AI-driven threats, ransomware, and supply chain attacks targeting the pharmaceutical sector, and implement security technologies such as Zero Trust, SASE, MFA, and EDR.
- Establish and report on cybersecurity metrics and KPIs to IT leadership, executive management, and the Board of Directors.
- Develop and deliver a company-wide cybersecurity awareness and training program, building security awareness across all levels of the organization.
Data Privacy & Regulatory Compliance
- Serve as the IT operational lead for data privacy, partnering with Legal and Compliance to ensure adherence to HIPAA, GDPR, U.S. state privacy laws, and emerging global requirements.
- Develop and maintain data classification, data loss prevention (DLP), and data handling policies and procedures.
- Ensure alignment of the cybersecurity program with NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27001, and CIS Contro
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s