11 ago
|
Jobtailor
|
Madrid
Responsibilities
Contribute to the development and execution of the general cybersecurity strategy aligned with ALS’s corporate objectives and international regulatory frameworks (GxP, ISO 27001, NIST, GDPR, 21 CFR Part 11).
Manage third‑party risk assessments for technology vendors, partners, and digital supply chain providers.
Lead global risk management initiatives, including threat assessment, vulnerability management, and mitigation plans for IT and OT environments.
Oversee security across hybrid infrastructures, including laboratory information systems (LIMS, ELN, CDS), cloud platforms, and industrial control systems (SCADA, PLCs).
Coordinate global incident response, ensuring timely communication, investigation, and remediation of security events.
Review current security policies in place across the laboratories of the group to assess current practice and local requirements.
Define corporate security policies and standards to support harmonisation and consistency of practice locally.
Partner with global and regional teams to ensure compliance with corporate policies, GxP, data protection, and privacy regulations.
Lead security awareness and training programs tailored to scientific, technical, and operational personnel.
Collaborate with Quality, R&D;, Production,
and Legal to embed security by design into systems and processes.
Monitor and report cybersecurity KPIs and maturity metrics to Chief Information Security Officer executive committees.
Lead and coordinate responses to RFIs, security questionnaires, and due‑diligence requests regarding IT security and compliance.
Requirements
Bachelor’s or Master’s degree in Computer Science, Information Security, Telecommunications, or a related field.
Advanced training or postgraduate studies in cybersecurity or technology risk management.
Recognized certifications such as CISM, CISSP, ISO 27001 Lead Implementer/Auditor, GICSP, NIST CSF Practitioner are highly valued.
Minimum 8 years of professional experience in cybersecurity, with 3–5 years in a leadership or global coordination role.
Proven experience in pharmaceutical, biotechnology, or scientific research environments.
Strong knowledge of regulated environments (GxP) and industrial/OT security (ISA/IEC 62443).
Experience managing security across cloud platforms (AWS, Azure, GCP) and hybrid infrastructures.
Demonstrated ability to manage complex, multinational security programs.
#J-18808-Ljbffr
📌 Global Cybersecurity Lead – Pharmaceutical Division (Madrid)
🏢 Jobtailor
📍 Madrid