Lead Security Engineer (Full-/Part-time) (all genders)
Notify me about similar jobsAbout this opportunity
Your role
In your role as Lead Security Engineer in the Platform and Engineering Enablement team, you will own the security engineering vision, strategy, standards, and delivery roadmap across our products and shared platforms. You will simplify and harden CI/CD pipelines, establish secure defaults, improve software supply-chain and AWS cloud security, and automate controls and audit evidence using GitHub, JFrog, Atlassian, and AWS. Working with engineering, enterprise security, legal, privacy, risk, and compliance, you will translate ISO 27001, SOC 2, the EU Cyber Resilience Act, customer, and internal requirements into practical controls. You will combine long-term direction with hands-on implementation and enable teams to deliver secure software efficiently.
Who you are
You have extensive hands-on experience in security engineering, platform engineering, application security, cloud security, or a related field, with technical ownership across multiple teams.
You have defined security strategies and standards and turned them into production-ready implementations.
You have secured CI/CD pipelines, source control, build systems, artifacts, software releases, and cloud platforms using tools such as GitHub, JFrog, and AWS.
You have practical experience with identity and access management, infrastructure as code, vulnerability management, security testing, threat modeling, secrets, and software supply-chain security.
You understand risk-based control design and frameworks such as ISO 27001, SOC 2, or the EU Cyber Resilience Act and can translate requirements into automated controls and evidence.
You communicate clearly, influence across teams, and balance security, developer experience, delivery speed, and operational resilience.
Experience with software bills of materials, provenance, attestations, artifact signing, release integrity, or security considerations for AI-assisted software development is desirable.
Experience with Atlassian tools or relevant certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or ISO 27001 Lead Implementer or Lead Auditor is desirable.
Department: LS-TO-DP
Job evaluation: Expert 3
TA: Gap Rattimasakol
Job details
How this role compares
Computed from every other active Information Technology role in our database, not just this employer's listings.
We currently track 1376 comparable Information Technology roles across 76 biopharma companies.
Salary context
183 of 1376 peers report a salary range (USD, annualized)
Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.
Where these roles are based
Top locations among the 1376 comparable roles
+ 29 more countries
Seniority mix
693 of 1376 peers have a known seniority level
Therapeutic area mix
1 of 1376 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden
Similar opportunities
The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.
Notify me about similar jobs
Get an email when we spot other openings like this one – same job function, comparable seniority, roles you'd actually want to see.
How we calculate "similar"
No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.
Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.
0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.