SMBC

Celcuity
·TodayCelcuity
·TodayCybersecurity engineer
Location
remote, United States
Salary
$120k – $130k/yr
Commitment
Full Time
Level
Senior (5+ years)
Required skills
Job Description
Reporting to the Executive Director, Information Security and GRC, the Cybersecurity Engineer will focus on supporting Celcuity’s day-to-day cybersecurity operations and maintaining the effectiveness of the company’s information security controls, processes, and technologies. Serving as a key technical resource, the Cybersecurity Engineer will support security monitoring, incident investigation and response, vulnerability and patch management, security awareness, and the administration of essential cybersecurity systems and tools. Key responsibilities include reviewing and investigating security alerts, coordinating incident response and remediation activities, monitoring vulnerabilities and patching activities, administering security awareness initiatives, and maintaining information security policies, procedures, and operational documentation. The role will also review security advisories, support security assessments and compliance activities, evaluate the effectiveness of security controls, coordinate with internal technology teams and external service providers, and identify opportunities to continuously strengthen Celcuity’s cybersecurity posture.
Responsibilities:
- Review, triage, and investigate security alerts and events.
- Perform investigation and analysis of security events and incidents, including suspicious activity, phishing, malware, unauthorized access, and potential account or system compromise.
- Coordinate incident response activities with the Security Operations Center (SOC), technology service providers, and internal stakeholders, including containment, remediation, and recovery.
- Document investigations, findings, and response activities, and recommend improvements based on lessons learned and emerging threats.
- Coordinate vulnerability and patch management activities, including oversight of patching performed by technology service providers.
- Review vulnerability assessment results, prioritize remediation using a risk-based approach, monitor remediation progress, and report outstanding vulnerabilities and risks to appropriate stakeholders.
- Administer the organization’s security awareness and phishing simulation program, including training, communications, and employee follow-up.
- Administer and support security tools and platforms used for monitoring, vulnerability management, threat detection, and incident response.
- Review firewall events, participate in periodic firewall rule and configuration reviews, and recommend improvements to endpoint, identity, email, firewall, and network security controls.
- Maintain information security policies, standards, procedures, operational documentation, and playbooks, and recommend updates based on evolving threats, technology changes, and business requirements.
- Support security assessments, audits, compliance activities, and operational metrics and reporting.
- Review vendor security advisories, assess potential organizational impact, and coordinate remediation or mitigation activities as appropriate.
- Provide cybersecurity input for new technologies and solutions and assist with vendor security questionnaires and related documentation.
- Perform other related duties as assigned.
Qualifications:
- AS or BS degree and 5 years’ work experience in cybersecurity, information security, security operations, or a related field, or equivalent combination of education and work experience.
- 1 year of experience supporting systems and services in a regulated environment; experience in an FDA-regulated environment is preferred.
- Security+, CySA+, SSCP, GSEC, or other relevant cybersecurity certifications highly desired.
- Experience investigating security alerts and supporting incident response activities.
- Experience assessing and prioritizing vulnerabilities and coordinating remediation and patch management activities.
- Experience administering or supporting security technologies, including security monitoring, endpoint protection, email security, and vulnerability management solutions.
- Strong knowledge of common cybersecurity threats and attack techniques, including phishing, ransomware, malware, identity-based attacks, and endpoint compromise.
- Working knowledge of network security concepts, including firewalls, VPNs, network segmentation, and access controls.
- Familiarity with cybersecurity frameworks and industry best practices, such as the NIST Cybersecurity Framework or CIS Controls.
- Strong analytical and problem-solving skills with the ability to investigate technical issues and assess risk.
- Strong written and oral communication skills with the ability to communicate effectively with technical and non-technical stakeholders.
- Strong attention to detail with the ability to plan and prioritize work, follow documented procedures, and meet established timelines.
- Demonstrated independent and sound decision-making skills; ability to think critically and make decisions in a fast-paced environment.
- Continuous improvement mindset; seeking ways to drive innovation and efficiencies throughout the organization.
- Flexible and willing to learn; adapting to business and site needs in a dynamic environment.
- Maintain a positive, approachable and professional attitude.
About Celcuity
Celcuity is a commercial biotechnology company pursuing development of targeted therapies for treatment of multiple solid tumor indications. The company's first FDA-approved product is REVTORPYK (gedatolisib), a potent, pan-PI3K and mTORC1/2 inhibitor that comprehensively blockades the PAM pathway. REVTORPYK is approved to treat adults with HR+/HER2- advanced breast cancer that progressed on prior endocrine therapy in the metastatic setting. The Phase 3 VIKTORIA-2 trial is evaluating gedatolisib in combination with palbociclib and either fulvestrant or letrozole for the first-line treatment of HR+/HER2- locally advanced or metastatic breast cancer. A Phase 1/2 clinical trial evaluating gedatolisib in combination with darolutamide in patients with metastatic castration resistant prostate cancer, is ongoing.
Celcuity is an Equal-Opportunity Employer. Celcuity is committed to fair and equitable compensation practices, and we strive to provide employees with total compensation packages that are competitive. For this role, the anticipated base pay range is $120,000 to $130,000 DOE. The exact base pay offered for this role will depend on various factors, including but not limited to the candidate’s geography, qualifications, skills, and experience.
The successful candidate will be eligible for an annual performance incentive bonus and a new hire equity package. Celcuity also offers various benefits offerings, including, but not limited to, medical, dental, vision insurance, 401(k) match, PTO, and paid holidays.
Notice to Recruiters/Staffing Agencies: Recruiters and staffing agencies should not contact Celcuity through this page. All recruitment vendors (search firms, recruitment agencies, and staffing companies) are prohibited from contacting our hiring manager(s), executive team members, or employees directly.
We require that all recruiters and staffing agencies have a fully executed, formal written agreement on file. Celcuity’s receipt or acceptance of an unsolicited resume submitted by a vendor organization to this website or employee does not constitute an actual or implied contract between Celcuity and such organization and will be considered unsolicited. Celcuity will not be responsible for related fees.
Ready to join the team?
Apply nowSimilar Jobs:
- Today
remote, NC, United States
$133k/yr
Full Time
Middle (2-4 years)
TodayBusiness Wire
Cybersecurity engineer
remote, United States
Full Time
Junior (<2 years)
TodayPhoenix Cyber
Cybersecurity analyst [job id 20260910]
remote, Phoenix, AZ, United States
Full Time
Middle (2-4 years)
2 days agoUniversity of Maine
Cybersecurity analyst
remote, United States
$60k – $70k/yr
Full Time
Senior (5+ years)
- 3 days ago
Our client
Cybersecurity (soar / vulnerability management)po
remote, New York, NY, United States
Full Time
Junior (<2 years)
3 days agoBNSF Railway
Cybersecurity engineer i/ii (vulnerability & patch management) (remote - us)
remote, United States
$94k/yr
Full Time
Junior (<2 years)
6 days agoZensar
Cyber security engineer
remote, United States
Full Time
Junior (<2 years)