Cybersecurity Manager
Discovery Life SciencesAbout Discovery Life Sciences:
Discovery Life Sciences (Discovery) is a leading provider of highly characterized human biospecimens and cellular starting materials to advance cell and gene therapy and precision medicine programs for cancer, infectious disease, and other complex conditions. We routinely manage hundreds of studies and expertly test thousands of biospecimens simultaneously. Leading biopharma, diagnostic and academic institutions trust us to quickly deliver high-quality biospecimens and reliable, reproducible biomarker data, so they can outpace their competition and push the leading edge of innovation using our Science at your Service TM business model.
Position Summary:
Discovery Life Sciences is seeking an experienced Cybersecurity Manager to join our Information Technology team as a hands-on individual contributor responsible for protecting the company's people, data, systems, and regulated operations. This role combines cybersecurity operations with governance, risk, and compliance (GRC) responsibilities, requiring both strategic thinking and technical execution.
The Cybersecurity Manager will play a key role in maintaining and enhancing the organization's security posture by leading incident response, vulnerability management, audit readiness, risk management, and compliance initiatives across global operations. This position serves as a trusted security partner to stakeholders across IT, Quality, Legal, Privacy, HR, Finance, and business functions, while helping scale a mature cybersecurity program that supports Discovery's continued growth.
A Day in the Life of a Cybersecurity Manager at Discovery Life Sciences:
- Monitor and investigate security alerts, coordinate incident response activities, and lead remediation efforts to minimize business risk.
- Partner with internal teams and external auditors to maintain compliance with SOC 2 Type II, ISO 27001, NIST, and regulatory requirements.
- Review vulnerability and penetration testing results, prioritize remediation activities, and track progress through resolution.
- Collaborate with Infrastructure, Cloud, Applications, Legal, Privacy, Quality, and business leaders to address emerging risks and strengthen security practices.
Must-Have Qualifications (Education, Skills, Experience):
- Must live near or be willing to relocate to Huntsville, AL
- Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field; equivalent practical experience will also be considered.
- CISSP, CISA, CRISC, Security+, or a comparable cybersecurity certification preferred.
- Certifications are valued but are not a substitute for demonstrated hands-on experience.
- Five (5)+ years of progressive experience in cybersecurity, security operations, IT risk management, IT audit, or a comparable hands-on role.
- Demonstrated expertise in either Security Operations or Governance, Risk, and Compliance (GRC), with practical experience across both disciplines.
- Experience in life sciences, healthcare, biotechnology, financial services, or another regulated industry required
- Hands-on experience with several of the following: Microsoft Sentinel, Microsoft Defender, Microsoft Intune, Microsoft Purview, Tenable, firewalls, endpoint security, cloud security, identity and access management, KQL, or PowerShell.
- Practical experience investigating and responding to security incidents, coordinating remediation, and exercising sound judgment under pressure.
- Experience supporting or operating security controls aligned to SOC 2, ISO 27001, NIST, or similar frameworks; able to produce clear, defensible audit evidence.
- Experience with vulnerability management, third-party risk, policy and exception management, and risk tracking.
- Familiarity with 21 CFR Part 11, GxP, GDPR, data privacy, customer security reviews, or regulated validation practices.
- Experience with Microsoft Purview, DLP, data classification, DSPM, eDiscovery, Azure, AWS, or Microsoft 365 security capabilities.
- Demonstrated ability to automate repeatable security and compliance tasks through scripting or workflow tools.
- Strong written and verbal communication skills, with the ability to explain technical risk and recommended action to executive, audit, and non-technical audiences.
Key Responsibilities:
Security operations and incident response:
- Monitor, triage, investigate, and respond to security alerts and incidents, lead containment, recovery coordination, and post-incident reporting.
- Administer and tune security controls across firewalls, network security technologies, endpoint compliance, patching, encryption, and security baselines.
- Own or coordinate joiner, mover, and leaver controls, including timely access provisioning, deprovisioning, privileged access review, and periodic access certifications.
- Maintain security operations runbooks, escalation paths, incident procedures, and metrics; participate in periodic after-hours response as required by the incident and team coverage model.
Governance, risk, and compliance:
- Operate the security compliance cadence for SOC 2 Type II, ISO 27001, and the NIST Cybersecurity Framework, including control mapping, audit planning, evidence collection, issue tracking, and auditor coordination.
- Partner with Quality / Validation, Legal, Privacy, and business stakeholders on 21 CFR Part 11, GxP, GDPR, and customer security requirements; provide security controls and evidence within each function's accountability.
- Run the third-party and vendor risk lifecycle: security due diligence, assessments, risk ratings, ongoing monitoring, remediation follow-up, and documented risk acceptance.
- Maintain the enterprise security risk register and coordinate risk assessments, accountable owners, due dates, compensating controls, and escalation of overdue or material risks.
- Maintain the security policy, standard, exception, and attestation lifecycle; communicate changes and support adoption across the organization.
- Partner with Operations, Legal, and IT on data classification, Data Loss Prevention / data security controls, security investigations, and eDiscovery support where appropriate.
- Vulnerability management and remediation
- Run the vulnerability management lifecycle, including prioritization based on exploitability, asset criticality, exposure, and business impact.
- Coordinate internal and third-party penetration tests, track findings, validate remediation, and report residual risk to accountable owners and leadership.
- Use automation, KQL, PowerShell, and available platform capabilities to improve detection, evidence collection, reporting, and control consistency.
Leadership and business partnership:
- Serve as a trusted leader for operational continuity, risk discussions, incident coordination, and selected leadership meetings.
- Mentor and help develop the Cybersecurity Analyst; provide direction to project teams, manage service providers, and control owners without requiring direct reporting lines.
- Build productive working relationships with Infrastructure, Cloud, Applications, HR, Legal, Quality, Privacy, Finance, and business leaders.
- Prepare concise security metrics, risk summaries, audit updates, and recommendations for executive stakeholders.
- Other duties as assigned by supervisor. These may, on occasion, be unrelated to the position described here.
- Consistent and predictable attendance is an essential function of the position.
Compensation and Benefits:
Discovery Life Sciences is committed to fair and equitable compensation practices, and we strive to provide employees with total compensation packages that are market competitive. For this role, the anticipated base pay range is $90,000 - $130,000 annually. Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate’s offer letter. The exact base pay offered for this role will depend on various factors, including the candidate's qualifications, skills, and experience. Your annual salary is only one part of your total compensation package. Other benefits include:
- Competitive salary and benefits package options, including a free dental, vision package, life insurance, and disability coverage which start on your first day of employment.
- 401(k) match program which starts on your first day of employment.
- Time away from work (Generous vacation and paid time off, paid parental leave, paid family leave, etc.).
- Professional development opportunities and reimbursement for relevant certifications and tuition.
- Collaborative and inclusive work environment that values diversity.
- Team-building activities and social events.
- Employee Referral Program and Colleague Recognition Program.
Location, work hours, and application details:
- Onsite – Huntsville, AL; relocation assistance will be considered
- Monday - Friday 8am – 5pm local time
- Less than 5% domestic or international travel required for mandatory site meetings and trainings
We are actively seeking motivated, dedicated individuals like you to join our thriving organization. As a leader in our industry, we offer unparalleled opportunities for professional growth and success.
Discovery Life Sciences values building direct relationships with candidates and primarily manages its hiring process internally. While we may engage select recruitment partners for specific searches, we do not accept unsolicited resumes or candidate submissions from agencies or recruiters. Any unsolicited resumes submitted to Discovery Life Sciences will be considered the property of Discovery Life Sciences, and the company assumes no obligation to pay any associated fees or commissions.
We are unable to sponsor or take over sponsorship of any applicant work visas at this time.
Apply Now to join our team!
Visit dls.com/careers for more details.