IT Security SpecialistLocation: Onsite - South San Francisco, CA, 94080
Manager: Director of IT
Key ResponsibilitiesCompliant Security Foundations- Design and configure technical security controls (MFA, EDR, network segmentation) to meet strict GxP data integrity and 21 CFR Part 11 requirements.
- Architect audit trails, ensuring all critical GxP software and infrastructure generate immutable, centralized security logs capable of withstanding regulatory audits.
- Own vulnerability and patch management end-to-end - scanning, prioritizing, and remediating vulnerabilities - while ensuring patches do not compromise validated system states.
- Manage and optimize SIEM, EDR, email security, and identity protection platforms to improve threat detection and response capabilities.
MSP Security Guardrails & Escalation- Govern and audit the MSP's administrative access to Neurona's network, preventing unauthorized changes or potential supply-chain breaches.
- Serve as the advanced technical escalation tier for Tier 1/2 incidents flagged by the MSP's Security Operations Center (SOC).
- Act as the internal on-site incident responder - isolating threats and leading technical containment of security anomalies.
- Support disaster recovery planning and business continuity testing to ensure critical systems remain resilient against cyber incidents.
- Perform security assessments of new technologies, applications, and integrations prior to deployment.
Scalable Identity & Lifecycle Management- Standardize secure identity management (IdP) and single sign-on (SSO) integrations across all GxP applications.
- Enforce Privileged Access Management (PAM) and the principle of least privilege, ensuring no user - including MSP technicians - holds permanent or unmonitored admin rights.
- Own the provisioning and deprovisioning lifecycle to support scalable, auditable identity governance as the organization grows.
Required Qualifications- Bachelor's degree in Information Security, Computer Science, or a related field (or equivalent experience).
- 3-5+ years of experience in IT security, with direct exposure to regulated environments (GxP, 21 CFR Part 11, HIPAA, or similar).
- Hands-on experience with MFA, EDR, network segmentation, and centralized logging/SIEM platforms.
- Experience managing or auditing MSP/third-party vendor access and supply-chain security risk.
- Strong understanding of IdP/SSO architecture and PAM tools.
- Demonstrated incident response experience, including threat isolation and containment.
- Relevant certifications preferred (Security+, CISSP, CEH, or similar).
- Excellent communication skills, with the ability to work cross-functionally and explain technical risk to non-technical stakeholders.
- Familiarity with NIST Cybersecurity Framework (CSF) and Zero Trust architectures.
Preferred Qualifications- Experience in a clinical-stage biotech, pharma, or life sciences environment.
- Familiarity with SOC 2 or ISO 27001 frameworks.
- Knowledge of cloud security best practices for Azure, AWS, or Google Cloud.
- Experience validating security tooling within a GxP-computerized systems framework.
Please note that this job description is not exhaustive and may be subject to changes and additions in alignment with the evolving needs of the organization. The role may entail additional responsibilities beyond those specified herein, as delegated by management.