Associate Director, Cybersecurity
Reporting to the Senior Director, Cybersecurity and Risk Management, the Associate Director of Cybersecurity will be responsible for information security operations, to include planning and operation of cybersecurity tools, applications, and business intelligence. The selected candidate will assist in developing, implementing, overseeing, and optimizing the organization's cybersecurity program (tools, technologies, methodologies) to ensure that information security policies, standards and practices are in place to manage risk to the enterprise effectively. This mid-level leadership position will also assist in driving the tactical direction of Insmed's cybersecurity program to define and deliver reliable, secure, and scalable network systems, processes, and other services. Ideal candidates for this position will be hands-on leaders, able to do the work as well as accomplish results through others, in addition to demonstrating strong coaching, mentorship, and career development skills. What You'll Do: In this role, you'll have the opportunity to lead and mentor the Cybersecurity team creating a culture that fosters engagement, passion, and enthusiasm for Insmed's vision, mission, and values. You'll also:
- Build and mature a culture focused on proactive risk management and cyber security best practices.
- Participate in the development of Insmed's IT strategy as it relates to cybersecurity; implement and operationalize the strategy. Collaborate with the Senior Director on a strategy for building management support and ownership of cybersecurity.
- Responsible for developing, implementing, and executing information security and vulnerability assessments, testing applications, systems, and infrastructure to ensure appropriate protection of sensitive customer and company information; perform risk analysis and recommends remediation for deficiencies. Track and reassess remediation(s) to ensure compliance with policies and operational standards.
- To appropriately manage the program and enterprise risk, leverage cyber security metrics.
- Research and benchmark industry-leading security practices and tools, validating the organization is protected with industry-leading security solutions and services. Examine new technologies' impact on the organization's overall information security posture. Establish processes to review new technologies and ensure security compliance.
- Responsible for developing, implementing, and executing company-wide/departmental information security training and awareness programs.
- Manage production technology incidents to resolution, ensuring timely engagement, escalation, and effective communication to business, technology, and vendor partners.
- Develop, implement, maintain, and oversee Insmed's cybersecurity program ensuring Insmed can identify and detect threats, and protect, respond, and recover from threats and incidents.
- In collaboration with Senior Director, work with and actively engage security service providers to deliver necessary services and manage contract requirements and service level agreements.
- Execute security management tasks including the monitoring, installation, and activation of malicious software protection tools, applying security protocols to network connectivity, managing user identities and logical access, and providing security data as needed when investigations arise.
- Develop, implement, maintain, and oversee enforcement of policies, procedures, and associated plans for system security administration and user system access based on industry-standard best practices.
- Develop, implement, and test the IT elements in the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP).
- Responsible for developing, implementing, and executing a comprehensive set of security standards and guidelines, including but not limited to cybersecurity operations, incident response, vulnerability management, network security, data protection, and loss, endpoint security, compliance program, and identity and access management.
- Ensure program standards comply with applicable State and Federal regulatory requirements.
- 10+ years' experience developing, managing, and directing cybersecurity operations with planning and development requirements, to include assessing effectiveness of such programs.
- 10+ years' experience leading a team of highly skilled technical professionals.
- 5+ years' of leading information security risk assessments, vendor risk management programs, developing information security awareness and education programs, and managing information technology or security projects.
- 5+ years' of effectively managing a Cybersecurity team.
- Advanced knowledge of systems design methodologies & development, including core infrastructure and enterprise-wide applications, as well as online applications, and web-based systems, voice and data communications technologies, security frameworks & methodologies, open architecture systems, common programming languages, open-source software, business intelligence, and data analytics.
- Expertise in cybersecurity regulatory, compliance, and framework requirements, such as NIST, HITRUST, CIS, and ISO.
- Experience working with Security Incident and Event Management (SIEM) tools, endpoint detection and response tools, vulnerability management suites, and various security solutions.
- Experience with the following cyber security domain areas:
- Data encryption (rest, transit, memory)
- Public Key Infrastructure (PKI) key management systems
- Application security (secure coding, shift left)
- Identity and access management program (MFA, SSO, LCM, IGA)
- Data handling and classification
- Firewalls
- Network segmentation
- Cyber resiliency
- Data loss prevention
- Strong knowledge of operating system, application, network, and database security architectures.
- Proven ability to effectively utilize techniques designed to reduce frequency, duration, and impact of common business disruptions particularly as they relate to branch/contact center operations, electronic services, and telecommunications.
- Strong verbal and written communications skills including the ability to explain technical concepts and technologies to business leaders and senior executives.
- Strong leadership, inter-personal, and collaboration skills.
- Proven ability to increase employee engagement, build, retain, and manage a highly skilled and motivated team.
- In-depth knowledge of IT and cybersecurity practices/trends in the biopharma and/or financial services industry and operating policies.
- Strong project management skills and a track record of successfully managing change, process improvement, and operational performance.
- Ability to collaborate, build relationships, and influence individuals at all levels within the organization and strong vendor management skills.
- Strong budget management skills and ability to develop and obtain approval for significant business cases.
- Certifications - GIAC Security Essentials, GIAC Security Leadership, ISACA CISM, MCSE: Security, (ISC)2 SCCP, (ISC)2 CISSP, (ISC)2 ISSAP, CCISO, CISA, or CRISC.
- Expertise in cybersecurity frameworks, organizational profiles, and gap analysis processes.
- Experience with CI/CD security integration and DevSecOps practices.
- Knowledge of cloud security, container security, and Infrastructure-as-Code (IaC) security.
- Security automation experience (SAST, DAST).
$164,000.00-213,000.00 Annual Life at Insmed At Insmed, you'll find a culture as human as our mission-intentionally designed for the people behind it. You deserve a workplace that reflects the same care you bring to your work each day, with support for how you work, how you grow, and how you show up for patients, your team, and yourself. Highlights of our U.S. offerings include:
- Comprehensive medical, dental, and vision coverage and mental health support, annual wellbeing reimbursement, and access to our Employee Assistance Program (EAP)
- Generous paid time off policies, fertility and family-forming benefits, caregiver support, and flexible work schedules with purposeful in-person collaboration
- 401(k) plan with a competitive company match, annual equity awards, and participation in our Employee Stock Purchase Plan (ESPP), and company-paid life and disability insurance
- Company Learning Institute providing access to LinkedIn Learning, skill building workshops, leadership programs, mentorship connections, and networking opportunities
- Employee resource groups, service and recognition programs, and meaningful opportunities to connect, volunteer, and give back
Recommended Jobs
Carrier and Partner Management Professional US
CEVA Logistics provides global supply chain solutions to connect people, products, and providers all around the world. Present in 170+ countries and with more than 110,000 employees spread over 1,500…
Registered Nurse (RN) - Full Time Days - Medical Unit I
Req #: 0000220020 Category: Nurses Status: Full-Time Shift: Day Facility: RWJ Hamilton Department: Medical Unit-I Pay Range: $46.90 - $63.09 per hour Location: One Hamilt…
Field Service Validation and Calibration Technician
Job Title: Field Service Validation and Calibration Technician Location: Hackettstown, NJ Type: Direct Hire Compensation: $60- $65K Contractor Work Model: Onsite Hours: M-F Full Time …
Lead Technical Program Manager
Job Description Leverage your deep technical expertise and leadership to guide cutting-edge projects, fostering growth and innovation in a dynamic environment. As a Lead Technical Program Manag…
DIRECTOR CARE MANAGEMENT - RN REQUIRED
About Us At Cooper University Health Care , our commitment to providing extraordinary health care begins with our team. Our extraordinary professionals are continuously discovering clinical inno…
Network Dean of Climate and Culture
The Queen City Difference At Queen City Academy Charter School, teachers are our most treasured assets. We therefore need leaders who will enable them to amplify their impact on student learning. …
Senior Lead Software Engineer- Cloud Platform
Job Description We have an opportunity to impact your career and provide an adventure where you can push the limits of what's possible. Are you ready to bring your Lead Software Engineering expert…
Maintenance Mechanic I
Sun Pharma is the world’s fourth largest generics company with presence in Specialty, Generics and Consumer Healthcare products. Supported by more than 40 manufacturing facilities, we provide high-qua…
Licensed Mental Health Therapist
We are looking for a compassionate mental health therapist to be responsible for counseling individuals, groups, or families to diagnose and treat mental health disorders. The mental health therapist…
Practice Manager
Job Title: Practice Manager Location: RWJBH Orthopedics JC MOB Department Name: MG Orthopedics - North Req #: 0000220525 Status: Salaried Shift: Day Pay Range: $83,156.00 - $117,458.…