Gilead Sciences, Inc. Posted September 9, 2026

Sr Director, IT Head of Security Operations

Foster City, United States Full time
Information Technology Senior Director
Notify me about similar jobs

Gilead Sciences, Inc. is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

At Gilead, we’re creating a healthier world for all people. For more than 35 years, we’ve tackled diseases such as HIV, viral hepatitis, COVID-19 and cancer – working relentlessly to develop therapies that help improve lives and to ensure access to these therapies across the globe. We continue to fight against the world’s biggest health challenges, and our mission requires collaboration, determination and a relentless drive to make a difference.

Every member of Gilead’s team plays a critical role in the discovery and development of life-changing scientific innovations. Our employees are our greatest asset as we work to achieve our bold ambitions, and we’re looking for the next wave of passionate and ambitious people ready to make a direct impact.

We believe every employee deserves a great leader. People Leaders are the cornerstone to the employee experience at Gilead and Kite. As a people leader now or in the future, you are the key driver in evolving our culture and creating an environment where every employee feels included, developed and empowered to fulfil their aspirations. Join Gilead and help create possible, together.

Job Description

Job Description

Gilead Sciences, Inc. is a research-based biopharmaceutical company founded in 1987. Together we deliver life-saving therapies to patients in need. With the commitment and drive you bring to the workplace every day, you will be part of a team that is changing the world and helping millions of people live healthier, more fulfilling lives. Our worldwide staff is a close community where you can see the tangible results of your contributions, where every individual matters, and everyone has a chance to enhance their skills through ongoing development. Our scientific focus has resulted in marketed products that are benefiting hundreds of thousands of people, a pipeline of late-stage drug candidates, and unmatched patient access programs to ensure medications are available to those who could otherwise not afford them. By joining Gilead, you will further our mission to address unmet medical needs and improve life by advancing the care of patients with life-threatening diseases.

 

 

Specific Responsibilities & Skills

 

The Senior Director, Head of Security Operations is a mission-critical leader responsible for safeguarding the integrity of Gilead’s scientific data, digital assets, and operational environments. Reporting to the CISO, this role will direct the teams that provide operational excellence for enterprise security capabilities that protect employees, patients, and the research that fuels Gilead’s innovation. Partnering closely with Gilead’s Managed Service Providers (MSPs), this role will lead the team to provide measurable operational results to support Gilead business outcomes.  As a senior member of the cross-functional Security Risk and Compliance organization, this leader will partner closely across Security Architecture, Engineering, Project delivery, Risk, Data Privacy, QA, Infrastructure, Network, and Business IT to translate complex and often ambiguous security requirements into clear guidance, ensuring the organization can innovate confidently while maintaining a strong security posture.

This is a site-based role in Foster City, CA at our global headquarters. Remote work is not available for this position.  We do offer optional work from home days on Monday and Friday with core collaboration days in the office. 

This position sits at the forefront of Gilead’s digital and AI-driven transformation and is uniquely positioned to support and secure the next generation of research platforms and data environments that accelerate the development and delivery of lifesaving therapies. The Head of Security Operations combines deep expertise in security policy, regulatory compliance, technology strategy, and MSP management practices with the ability to navigate ambiguity and influence senior stakeholders.  This leader will ensure that the business is aware and understand the importance of security across the enterprise, help business and other stakeholders to follow and comply with security, risk and compliance requirements.

The Head of Security Operations will be expected to demonstrate:

·       Domain Expertise: Expert level knowledge of Cyber Security capability areas, including Risk assessment and management, Identity and Access Management, Endpoint Security, Network Security, Platform Security, application security, and vulnerability management.

·       Strategic mindset with the ability to execute: Define and deliver against security strategies, especially in Identity and Access Management, to protect Gilead, implements automation, and drives for operational efficiencies.

·       Technology Strategy and Delivery: Position Security as a key requirement to support business operations and understand the value of scalable and efficient technical solutions that provide visibility to threats and allows team the ability to quickly respond to and block threats with low operational overhead and technical debt.

·       Business Partnership: Serve as a trusted advisor to leaders within Business functions and IT and supports their mission. Partner with senior IT Security leadership to create technology strategies that support the objectives of their functions. Understand the value drivers of the Business and ensures IT Security solutions consider the balance between Security and User experience. Strong ability to partner with Managed Service providers and manage them to agree upon outcomes.

·       Leadership: Proven ability to build, develop, and lead teams and rally organization around the vision.

 

Key responsibilities for this position include (but are not limited to):

·       Define and execute a multi-year Security Operations strategy and roadmap, aligning operational capabilities, automation, incident response, identity security, vulnerability management, application security and MSP performance to Gilead’s enterprise risk posture, digital transformation and business strategies.

·       Lead and manage the Security Operations function to provide operational excellence across all Security domains including Identity and Access Management, Endpoint Security, Network Security, Platform Security, and application security.

·       Lead and manage the Security Identity and Access Management team to deliver key Identity Security capabilities.

·       Lead and manage our Managed Service Provider (MSP) Operations team. Establish and monitor OKRs, KPIs, service levels and risk-reduction metrics.

·       Own operational budget planning, vendor performance, service cost transparency and cost-of-ownership optimization for Security Operations. Make informed trade-off decisions across risk reduction, operational resilience, user experience, cost and business need.

·       Lead continuous improvement and automation activities to reduce overall operational overhead, improve response times and strengthen cyber resilience.

·       Represent Security Operations in enterprise governance, leadership risk discussions, audit and compliance forums, and major IT initiatives.

·       Advise senior leaders on operational security risks, investment trade-offs and response priorities that affect Gilead-wide resilience. Leads a high-performing, inclusive Security Operations organization that develops and retains talent, encourages innovation and enables accountable, resilient and scalable delivery.

·       Maintain awareness of evolving cyber threats, regulatory expectations, security operations practices and peer benchmarks, bringing relevant insights into Gilead to inform roadmap decisions and operational priorities.

·       Support Merger & Acquisition related activities.

·       Lead and manage our application security team, including SAST/DAST application testing, penetration testing, security remediation, and tabletop exercises

·       Ensure IT activities, processes, and procedures meet defined requirements, policies and regulations.

·       Work with Internal Audit, Project Managers, System Managers and Engineers - Track project findings, identify and resolve issues, analyze evidence, communicate with stakeholders, and facilitate the completion of cybersecurity related projects.

·       Participate in other activities relating to information security or other functional areas as assigned.

 

Skills and Experience

 

Bachelor of Science degree in management information systems, computer science, engineering or another IT-related major is required

14+ years of relevant experience or 12+ years with a master’s or PhD

Information security related certifications such as CISSP, CRISC, CCSP, GIAC, etc.

·       A minimum of 8-10 years of leadership responsibilities.

·       Strong understanding of a wide variety of cybersecurity technologies relating to the following security domains: Audit and Monitoring, Risk Response & Recovery, SIEM, vulnerability management, Cryptography, Data Communications, Computer Operations Security, Telecommunications & Network Security, Security Architecture & Models, cloud security, Multi-Factor Authentication, Passwordless Authentication, Digital Rights Management, PKI, Security for AI and AI for Security solutions.

·       Strong understanding of NIST cyber security, and MITRE attack frameworks.

·       Deep knowledge of IT Security and Privacy concepts and controls, and ability to develop security standards and guidelines based on best practices and industry standards.

·       Able to lead teams through an incident from initial response, stakeholder communications and diagnosis to immediate and long-term remediation plans and activities.

·       Knowledge of information security risk management frameworks and compliance practices.

·       Knowledge of securing network technologies, client, and server operating systems.

·       Strong knowledge of Secure Software Development Lifecycle (SDLC) processes and methodologies.

·       Excellent interpersonal, communication, and presentation skills, including formal writing experience.

·       Understanding of common security standards and healthcare related regulations and data privacy.

·       Able to assess complex multi-location projects as well as identify and recommend appropriate corrective measures to resolve security and privacy related issues.

·       Strong customer service orientation and the ability to project that attitude to customers in remote locations.

·       Previous work experience in a Biopharma organization is a plus.

·       Previous work experience in a cloud centric environment is a plus.

The salary range for this position is: $243,100.00 - $314,600.00. Gilead considers a variety of factors when determining base compensation, including experience, qualifications, and geographic location. These considerations mean actual compensation will vary. This position may also be eligible for a discretionary annual bonus, discretionary stock-based long-term incentives (eligibility may vary based on role), paid time off, and a benefits package. Benefits include company-sponsored medical, dental, vision, and life insurance plans*.

For additional benefits information, visit:

https://www.gilead.com/careers/compensation-benefits-and-wellbeing

* Eligible employees may participate in benefit plans, subject to the terms and conditions of the applicable plans.

For jobs in the United States:

Gilead Sciences Inc. is committed to providing equal employment opportunities to all employees and applicants for employment, and is dedicated to fostering an inclusive work environment comprised of diverse perspectives, backgrounds, and experiences. Employment decisions regarding recruitment and selection will be made without discrimination based on race, color, religion, national origin, sex , age, sexual orientation, physical or mental disability, genetic information or characteristic, gender identity and expression, veteran status, or other non-job related characteristics or other prohibited grounds specified in applicable federal, state and local laws. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans' Readjustment Act of 1974, and Title I of the Americans with Disabilities Act of 1990, applicants who require accommodation in the job application process may contact ApplicantAccommodations@gilead.com  for assistance.

For more information about equal employment opportunity protections, please view the  'Know Your Rights' poster.

NOTICE: EMPLOYEE POLYGRAPH PROTECTION ACT

YOUR RIGHTS UNDER THE FAMILY AND MEDICAL LEAVE ACT

Gilead Sciences will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, (c) consistent with the  legal duty to furnish information; or (d) otherwise protected by law.

Our environment respects individual differences and recognizes each employee as an integral member of our company. Our workforce reflects these values and celebrates the individuals who make up our growing team.

Gilead provides a work environment free of harassment and prohibited conduct. We promote and support individual differences and diversity of thoughts and opinion.

For Current Gilead Employees and Contractors:

Please apply via the Internal Career Opportunities portal in Workday.

Job details

Seniority
Senior Director
Function
Information Technology
Therapeutic area
Not listed
Location
Foster City, United States
Employment type
Full time

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 54 comparable Senior Director Information Technology roles across 21 biopharma companies.

54Comparable roles tracked
47Currently active
21Companies hiring similar roles
6Countries represented

Salary context

24 of 54 peers report a salary range (USD, annualized)

Peers share this role's job function and a matching or adjacent seniority level -- not necessarily the same therapeutic area or country.

This roleSubject $243,100/yr – $314,600/yr
Lowest disclosed · Director, Information Security Governance Risk Compliance · Mylan Inc. $112,000/yr – $236,000/yr
Peer group range $174,000 – $400,000 (median $258,336)

Where these roles are based

Top locations among the 54 comparable roles

United States34
India15
United Kingdom2
Greece1
Ireland1
Germany1

Seniority mix

54 of 54 peers have a known seniority level

Director38
Senior Director13
Executive/VP3

Therapeutic area mix

0 of 54 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

No peers with a known therapeutic area yet.

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

60%similar
GlaxoSmithKline LLC Upper Providence, United States Senior Director
Same function Same seniority Same country
60%similar
E.R. Squibb & Sons,L.L.C. Cambridge Crossing, United States Senior Director
Same function Same seniority Same country
60%similar
E.R. Squibb & Sons,L.L.C. Cambridge Crossing, United States Senior Director
Same function Same seniority Same country
60%similar
E.R. Squibb & Sons,L.L.C. Princeton, United States Senior Director
Same function Same seniority Same country
60%similar
Amgen Inc. Remote, United States Senior Director
Same function Same seniority Same country
60%similar
Pfizer New York City, United States Senior Director
Same function Same seniority Same country

Notify me about similar jobs

Get an email when we spot other openings like this one – same job function, comparable seniority, roles you'd actually want to see.

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

60%
Senior Director, Automation Acceleration Hub
GlaxoSmithKline LLC · Upper Providence, United States · Senior Director
Function Therapeutic area Seniority Country
60%
Senior Director, Head of Commercialization Data and AI Delivery
E.R. Squibb & Sons,L.L.C. · Princeton, United States · Senior Director
Function Therapeutic area Seniority Country
60%
Senior Director, Product Management
Pharmacia & Upjohn Company · New York City, United States · Senior Director
Function Therapeutic area Seniority Country
50%
Director, IT Procurement Solutions
Gilead Sciences, Inc. · Foster City, United States · Director
Function Therapeutic area Adjacent seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.