Global Head, Cyber Defense & Security Operations

Posted Yesterday
Be an Early Applicant
Sandoz, CA, USA
In-Office
Expert/Leader
Biotech • Pharmaceutical
The Role
Lead and run global Security Operations and Cyber Defense, owning IDS/SIEM/SOAR tooling, detection and response, incident forensics, threat hunting, red team exercises, and security program development to protect enterprise assets and report cyber risk to stakeholders.
Summary Generated by Built In

Job Description Summary

Lead the Information Security Operations organization to ensure all Sandoz assets are protected and monitored based on the leading practices for Information Security. This role is solely responsible for overseeing the security posture of our environment in line with commitments made to the Risk Committee of the Board. Responsible for running and engineering all systems that defend the enterprise, by owning the tools used by the security team to maintain the protective state of Sandoz assets and to lead post incident root cause analysis. Oversee and lead the Sandoz Cyber Security Operations Center (SOC), which includes monitoring, detection, coordinated response and management of security incidents and cyber security threats.

Job Description

Global Head, Cyber Defense & Security Operations

Sandoz continues to go through an exciting and transformative period as a global leader and pioneering provider of sustainable Biosimilar and Generic medicines. As we continue down this new and ambitious path, unique opportunities will present themselves, both professionally and personally. Join us, the future is ours to shape!

Job Summary

Lead the Information Security Operations organization to ensure all Sandoz assets are protected and monitored based on the leading practices for Information Security. This role is solely responsible for overseeing the security posture of our environment in line with commitments made to the Risk Committee of the Board. Responsible for running and engineering all systems that defend the enterprise, by owning the tools used by the security team to maintain the protective state of Sandoz assets and to lead post incident root cause analysis. Oversee and lead the Sandoz Cyber Security Operations Center (SOC), which includes monitoring, detection, coordinated response and management of security incidents and cyber security threats.

Your Key Responsibilities:

Your responsibilities include, but are not limited to:

  • Provide full visibility of cyber–risk and exposure across the threat landscape, enabling prediction, detection, and response to attacks in near real–time 
  • Define the standard for security events and log creation 
  • Responsible for all maintenance of the IDS, SIEM, SOAR and email hygiene systems to include configuration changes, updates, and creation of custom detection logic, reporting, and dashboards to provide actionable threats to security operators 
  • Develop policies procedures and guidelines for a security incident response program 
  • Identify, escalate and communicate security incidents to stakeholders. 
  • Perform recovery and restoration of incidents 
  • Create, design, and implement test plans for testing the security of systems, processes, and their environment 
  • Provide applications teams with comprehensive security testing services and support to minimize the number of vulnerabilities which are released into production 
  • Conduct attack and penetration assessments aimed at demonstrating the actual risk that is caused by a cyber security breach and the extent of the security risk exposure to the organization 
  • Establish process and capabilities to gather, process, interpret, and to use digital evidence to provide a conclusion such as incident timeline, threat vectors, and threat actors 
  • Establish a process detailing different phases of data handling from identification, collection, acquisition to preservation 
  • Perform log, network, system memory, and system configuration and file structure collection and analysis to identify what has happened, where it happened, the foothold of the attacker, data at risk, and how to stop the infection and prevent it from happening again 
  • Create processes to identify critical security processes and systems supporting the organization and document recovery and restoration procedures 
  • Leverage a collection of cyber threat data points for analysis, evaluation against priority intelligence requirements, and synthesis to provide timely, accurate and actionable reporting to security operators and decision makers 
  • Leverage threat and business intelligence to craft use cases and detection logic for security tooling 
  • Scan the environment to identify threat, malware, perform investigations on those items, and execute a strategy to mitigate the threat or eliminate the malware from the environment 
  • Identify, analyse, and address flaws or vulnerabilities in hardware or software that could serve as attack vectors 
  • Perform threat hunting proactively to iteratively search through the enterprise to detect and isolate threats attempting to evade existing security controls 
  • Perform regular tabletop and red team exercises and incident simulations to test and exercise incident response plans

Minimum Requirements

What you’ll bring to the role:

  • At least 15 years of experience in Information Security; experience of running security operations and a Cyber Defense Center (SOC) in regulated environment  
  • Excellent negotiation, communication, and interpersonal skills ability to develop influential relationships with different stakeholders across all level 
  • Knowledge and experience of industry standards such as ISO 27001, CIS Controls, NIST, Cyber Essentials 
  • Change Management Champion with experience in leading teams through large-scale IT change / transformation programs 
  • Highly experienced people leader with the ability to lead and develop diverse teams across wide geographies 
  • An entrepreneurial mindset driven by curiosity, continuous improvement, and interest in technical advancements and trends. 
  • Strong project management skills with the ability to multitask and properly delegate work

 Preferred Requirements:

  • Master of Science degree or equivalent experience in computer science, engineering or information technology or other relevant field. 
  • Certification or accreditation in Information Security (e.g.: CISM, CISA, CISSP, etc.)
  • Worked in a regulated environment

Why Sandoz?

Generic and Biosimilar medicines are the backbone of the global medicines industry. Sandoz, a leader in this sector, provided more than 900 million patient treatments across 100+ countries in 2024 and while we are proud of this achievement, we have an ambition to do more!

With investments in new development capabilities, production sites, new acquisitions, and partnerships, we have the opportunity to shape the future of Sandoz and help more patients gain access to low-cost, high-quality medicines, sustainably.

Our momentum is powered by an open, collaborative culture driven by our talented and ambitious colleagues, who, in return for applying their skills experience an agile and collegiate environment with impactful, flexible-hybrid careers, where diversity is welcomed and where personal growth is supported!

Join us!

#Sandoz

Skills Desired

Escalation, Information Security Audit, Information Security Risk Management, Innovation, IT Governance, Secops (Security Operations), Strategic Leadership, Vendor Management

Skills Required

  • At least 15 years of experience in Information Security, including running security operations and a Cyber Defense Center (SOC) in a regulated environment.
  • Proven experience maintaining and configuring IDS, SIEM, SOAR, and email hygiene systems, including creating custom detection logic, dashboards, and reporting.
  • Deep experience in incident response, digital forensics, log/network/memory analysis, threat hunting, penetration testing, and red team/tabletop exercises.
  • Knowledge and experience with industry standards and frameworks such as ISO 27001, CIS Controls, NIST, and Cyber Essentials.
  • Strong people leadership experience managing and developing distributed, diverse global teams.
  • Excellent negotiation, communication, and stakeholder management skills.
  • Change management experience leading large-scale IT change and transformation programs.
  • Strong project management skills with ability to multitask and delegate effectively.
  • Master of Science degree or equivalent experience in computer science, engineering, IT, or related field.
  • Certifications in Information Security (e.g., CISM, CISA, CISSP)

Sandoz Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sandoz and has not been reviewed or approved by Sandoz.

  • Healthcare Strength Health, dental, vision, and prescription coverage are consistently described as core components across U.S. roles and materials. Feedback suggests the medical offering is broad and a standard pillar of the package.
  • Retirement Support A 401(k) plan with a company match described as generous is commonly included for U.S. roles. This savings support is positioned alongside other primary benefits as part of total rewards.
  • Equity Value & Accessibility Equity eligibility is noted for many positions and a global all‑employee share program is being introduced from 2026. These elements add upside beyond base salary and annual bonus.

Sandoz Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Basel
17,135 Employees

What We Do

Sandoz is the global leader in generic and biosimilar medicines. ​ ​Our Purpose is to pioneer access to medicines for patients globally. We are on a mission to drive innovation in the healthcare industry by freeing up resources sustainably and responsibly while continuing to address global health challenges such as antimicrobial resistance.​ We are present in more than 100 countries and our medicines serve some 500 million people every year. We have two main global businesses: Generics - divided between standard generics and complex generics - and Biosimilars.

Similar Jobs

MetLife Logo MetLife

Group Insurance Administrator

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
42K-57K Annually

Datadog Logo Datadog

Account Executive

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Hybrid
San Francisco, CA, USA
6500 Employees
105K-105K Annually

Datadog Logo Datadog

Technical Support

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Hybrid
3 Locations
6500 Employees
66K-88K Annually

Coursera + Udemy  Logo Coursera + Udemy

Chief Of Staff

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
181K-273K Annually

Similar Companies Hiring

SOPHiA GENETICS Thumbnail
Software • Healthtech • Biotech • Big Data • Artificial Intelligence
Boston, MA
450 Employees
Pfizer Thumbnail
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
New York, NY
121990 Employees
Cencora Thumbnail
Healthtech • Logistics • Pharmaceutical
Conshohocken, PA
51000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account