Nature and Scope of JobSenior IT / Security Engineer will drive the execution of IT, information security, and GxP computerized-systems projects. Resource will take prioritized initiatives from the IT & Security roadmap(s) and deliver them end-to-end: planning, coordinating stakeholders and vendors, implementing, validating, documenting, and handing off to steady-state operations. This is a high-capacity, high-output role. Your job is to turn business decisions and objectives into shipped, well-documented outcomes-often several at a time. Project management and communication skills are weighted equally with technical skills.
Primary ResponsibilitiesProject Management & Delivery- Run multiple concurrent IT and security projects end-to-end: define scope and success criteria with the Associate Director, build the plan, track dependencies and risks, and drive to completion on schedule.
- Maintain a transparent project portfolio in Jira/Confluence with clear owners, dates, and status; publish concise weekly status updates and escalate blockers early with recommended options.
- Coordinate vendors, MSP/MSSP partners, and consultants on assigned projects; track deliverables against statements of work and hold partners accountable.
- Produce clean, reusable project artifacts: requirements, designs, test evidence, runbooks, and handoff documentation.
Technical Implementation- Implement and configure identity and access controls on Okta or Microsoft Entra ID: SSO/MFA rollouts, SCIM provisioning, conditional access policies, and access-review cycles.
- Deploy and maintain endpoint management and security for macOS and Windows: MDM enrollment, EDR (e.g., CrowdStrike, Microsoft Defender), hardening baselines, and patch/vulnerability remediation.
- Execute cloud and SaaS workstreams in Microsoft 365, Azure/AWS, and Google Workspace: security configuration, DLP/information protection, backup, and integrations.
- Support network and site infrastructure projects (LAN/WLAN, firewalls, VPN/ZTNA) for the Palo Alto, Switzerland, and future campuses.
- Automate repetitive work with scripting (PowerShell, Python) and APIs; document what you build.
Security Operations Support- Triage and investigate security alerts from the SIEM/EDR; execute incident response procedures and document findings; coordinate with the MSSP as directed.
- Run the vulnerability remediation cycle: track findings, drive owners to closure, and report progress.
- Complete vendor security assessments and customer/partner security questionnaires.
GxP Compliance & Computerized System Validation- Execute validation activities for GxP cloud and SaaS systems using risk-based principles (GAMP 5 / CSA) in compliance with 21 CFR Part 11 and EU Annex 11.
- Author and maintain validation lifecycle documentation including:
- Validation Plans and Validation Summary Reports
- User Requirements Specifications (URS) and Functional/Configuration Specifications
- Risk Assessments and Traceability Matrices
- IQ/OQ/PQ (or equivalent) protocols and test evidence
- Support change control, periodic reviews, audit-trail reviews, and inspection readiness in partnership with Quality.
Communication & Collaboration- Communicate clearly and proactively with stakeholders across Quality, R&D, Clinical, Finance, and HR; translate technical detail into plain language for non-technical audiences.
- Present project status and results to leadership when required, including executive and C-level audiences.
- Provide escalated (Tier 3) support and mentor IT support staff and contractors.
Additional Responsibilities - Performs other related duties and assignments as required
Required Qualifications- 7+ years of hands-on IT infrastructure and/or information security engineering experience, with a demonstrated record of delivering multiple projects concurrently and on time.
- Hands-on experience in at least two of: identity (Okta/Entra ID), endpoint management/EDR, Microsoft 365/Azure or AWS administration and security, network security, SIEM/alert triage.
- Working knowledge of IAM concepts (SSO, MFA, SAML/OIDC, SCIM, conditional access).
- Scripting ability (PowerShell, Python, or similar) for automation and integration tasks.
- Computerized System Validation experience in a GxP-regulated biotech, pharmaceutical, or medical device environment (21 CFR Part 11, EU Annex 11, GAMP 5).
- Strong project management fundamentals: planning, task tracking, vendor coordination, risk/issue management, and structured status reporting (Jira/Confluence or equivalent).
- Exceptional written and verbal English communication skills; comfortable presenting to executive and C-level leadership.
- Organized, detail-oriented, and comfortable with ambiguity; strong bias for action and follow-through.
- Ability to work on-site in Palo Alto, CA, 40 hours per week, with occasional after-hours availability for maintenance windows and incidents.
Preferred Qualifications- Experience at a clinical-stage or emerging biotech with a lean IT team.
- Certifications such as CompTIA Security+, CISSP, Microsoft SC-300/AZ-104, Okta Certified Professional, PMP/CAPM, or ISPE GAMP training.
- Familiarity with security frameworks (NIST CSF, SOC 2, CIS Controls) and with SASE/ZTNA platforms (Zscaler, Cloudflare).
- Experience with DocuSign, Veeva, or other common GxP SaaS platforms and with e-signature/Part 11 configurations.
Education & Certifications - Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent practical experience.
Working ConditionsThe working conditions described here are representative of those that must be met by an employee to successfully perform the essential responsibilities and functions of the job and are not meant to be all-inclusive. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential responsibilities and functions of the job.
Unless reasonable accommodations can be made, while performing this job the staff member shall:
- Prolonged periods of sitting or standing at a desk and working on a computer in an environmentally controlled home office environment.
- Operate other office productivity machinery, such as a calculator, scanner, or printer.
- Frequently communicate with stakeholders via telephone, email, or instant message. Must be able to exchange accurate information in these situations.
CompensationSalary/Hourly Rate Range (W2): USD 70.00 - 80.00
The base salary/hourly rate range represents the anticipated low and high end of the USDM's compensation range for this position. Actual salaries/hourly rates will vary and will be based on various factors, such as the candidate's qualifications, skills, competencies, and proficiency for the role. The compensation described above is subject to change and could be higher or lower than the range described based on market survey data or budget.
Full-time employees are eligible for health, vision, and dental insurance, life insurance, short and long-term disability, hospital indemnity, accident, and critical care coverage.
Both full and part-time employees, who are at least 21 years of age, are eligible to participate in USDM's 401k plan. Full and part-time employees may be eligible for paid time off.
All employees are eligible for USDM's rewards and recognition program.
For more details about our benefits, visit us here: https://usdm.com/careers