Sr. Analyst, Cyber Security

Information Management - Philadelphia, PA - Full Time

Adaptimmune is a fully integrated cell therapy company, designed and built from the ground up with four U.K.- and U.S.-based biotechnology hub locations. Our comprehensive capabilities and teams include preclinical research, clinical development, translational sciences, autologous and allogeneic manufacturing, and in-house commercial and corporate operations.

Our company culture is rooted in trust, inclusion, our capacity to collaborate, and our commitment to being honest and brave in our desire to successfully transform the lives of people with cancer.


Primary Responsibility

The Sr. Analyst, Cyber Security plays an integral part in the active development, execution, monitoring, and oversight of security controls across the enterprise to safeguard company information and systems. Responsibilities include and not limited to:
  • Providing strategic support to the Director, Global Infrastructure & Cyber Security, and other key stakeholders to mature and deploy security capabilities.
  • Establishing and managing tools and processes to ensure that systems and information are regularly assessed for compliance to controls in alignment to level of inherent risk.
  • Managing tools for and executing initial and ongoing assessments of third-party security control environments to ensure appropriateness for nature of services and information.
  • Manage the execution of security assessments / penetration tests from scoping through execution, analysis, and remediation; with engagement and management of external services where required.
  • Acting as a focal point and trusted advisor for IM and business functions in providing expert security consultation on solutions for security risk and compliance issues.
  • Supporting Cyber Security team members as necessary in the execution of the company’s security incident response procedure, including after action reviews.
  • Overseeing security training and awareness initiatives, including ongoing phishing campaigns, to ensure that staff are aware of key risks and their responsibilities to protect company systems and information.
The Sr. Analyst must be able to balance and prioritize across hands-on IT security operational activities and longer-term cyber security efforts.

Key requirements of the positions include: influencing for outcomes, collaboration, communication and presentation skills, technical and IT security competency, analytical and critical thinking, operational excellence, and the ability to identify needs, risks and take initiative.

Key Responsibilities

Strategic Support
  • Work with the Director, Global Infrastructure & Cyber Security, business stakeholders, users, and IT specialists to mature and deploy capabilities to address cyber-risk and business security requirements.
  • Work with the Director, Global Infrastructure & Cyber Security to establish and report metrics that effectively communicate successes and progress of the Information Security program.
Security Control Assessments
  • Establish and manage tools and processes to verify adherence to IT security policies, procedures, and methods.
  • Ensure security is factored into evaluation and installation of new software and hardware.
  • Assist staff in identifying / responding to risks, including recommendation of treatment plans and analysis of residual risk.
  • Report on a routine basis compliance with IT security policies, procedures, requirements, and methods.
  •  Aid the Director, Global Infrastructure & Cyber Security in the identification of systemic issues that require further analysis/treatment.
Third Party Security Assessments
  • Manage initial and ongoing security assessments for third party suppliers to ensure that control environments are appropriate to nature of services and information sensitivity.
  • Identify and track ongoing remedial actions and coordinate periodic governance for critical suppliers.
Security Assessment and Penetration Testing
  • Coordinate and execute security assessments / penetration tests as required to identify control weaknesses and assess the effectiveness of existing controls.
  • Manage the engagement of third-party professional services as required for the execution of assessments or penetration tests.
  • Analyze recommendations to translate into internal action plans and oversee resulting remedial actions through completion or risk acceptance.
Security Consulting/Advisory Services
  • Develop a strong working relationship with the IT and business functions to aid them in development and implementation of controls and configurations aligned with security policies and legal, regulatory and audit requirements.
Security Incident Response
  • Investigate, evaluate risk, and act on security alerts, intrusion attempts, breaches, incidents, and false alarms across the IT eco-system where required as backup to the Cyber Security team.
  • Support analysis as part of after action review during and after a security incident. Assists technical administrators in the resolution of reported security incidents as required.
Security Awareness & Training
  • Oversee the identification, selection and delivery of security training for all employees – for both new starters and ongoing periodic training.
  • Manage the delivery and reporting of ongoing phishing exercises and associated training and education as required.
  • Manage intranet presence and articles for regular security awareness communications to audiences which may range from senior leaders to field staff to the entire company.
  • Ensure staff are adequately trained on technical control requirements, risk parameters and related operational tools as required.
Other duties as assigned by IT management in support of rapidly growing company.

Qualifcations & experience 

Required
  • A strong technologist with a record of accomplishment in the field of IT security with 7 to 10 years of relevant experience.
  • 10+ years professional experience
  • A bachelor's degree in information systems, related degree, or equivalent work experience
  • Information Security certification based on industry best practices (e.g., CISSP, CISA, CISM, CASP+).
  • Proficiency in security risk management to include an understanding of security threats, business impacts, and the associated best practice treatment strategies.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate information security and risk-related concepts to technical and nontechnical audiences at various hierarchical levels.
  • A thought leader, influencer, and builder of consensus who can build bridges between various IT roles and functions.
Desirable
  • Knowledge of security of Cloud technology and technical integrations.
  • ITIL Certification, GxP training, Privacy, EU General Data Protection Regulations (GDPR) and/or IT Security training.
  • Advanced degree in Computer Science, Engineering, or Business.
  • Any equivalent combination of education, experience and training that provides the required knowledge, skills, and abilities.
  • Global IT experience.
  • Previous pharmaceutical or biotechnology experience.
Other RequIREMENTS  
  • Travel to Adaptimmune sites and Adaptimmune vendors as necessary to support Cyber Security team needs

At Adaptimmune we embrace diversity and equality of opportunity. We believe that the more inclusive we are, the better our work will be. We welcome applications to join our team from all qualified candidates, regardless of age, colour, disability, marital status, national origin, race, religion, gender, sexual orientation, gender identity, veteran status or other legally protected category. It is our intent that all qualified applicants will receive equal consideration for employment.

Apply: Sr. Analyst, Cyber Security
* Required fields
First name*
Last name*
Email address*
Location *
Phone number*
Resume*

Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or paste resume

Paste your resume here or attach resume file

By continuing with and submitting your application, you are agreeing to the following:

1. You have read and understood the statements made in the consent form and the ways in which your personal data will be stored and processed.
2. To the storing and processing of your personal information by Adaptimmune, members of the Adaptimmune group of companies and third parties working on behalf of Adaptimmune as set out in the consent form.
3. To the storing and processing of your personal information outside of the European Union and to the transfer of personal information between the EU and the United States.
4. To the storing of personal information for the periods set out in the Privacy Notice.
5. You understand that you can withdraw your consent at any time.*
Do you have the independent right to live and work in this country without the need for Visa sponsorship?*
The following questions are entirely optional.
To comply with government Equal Employment Opportunity and/or Affirmative Action reporting regulations, we are requesting (but NOT requiring) that you enter this personal data. This information will not be used in connection with any employment decisions, and will be used solely as permitted by state and federal law. Your voluntary cooperation would be appreciated. Learn more.
Gender
Race/Ethnicity

Invitation for Job Applicants to Self-Identify as a U.S. Veteran
  • A “disabled veteran” is one of the following:
    • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
    • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran status
I IDENTIFY AS ONE OR MORE OF THE CLASSIFICATIONS OF PROTECTED VETERAN LISTED ABOVE
I AM NOT A PROTECTED VETERAN
I DON’T WISH TO ANSWER

Voluntary Self-Identification of Disability
Voluntary Self-Identification of Disability Form CC-305
OMB Control Number 1250-0005
Expires 04/30/2026
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Please check one of the boxes below:
YES, I HAVE A DISABILITY, OR HAVE HAD ONE IN THE PAST
NO, I DO NOT HAVE A DISABILITY AND HAVE NOT HAD ONE IN THE PAST
I DO NOT WANT TO ANSWER

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

Name Date
Human Check*