Senior Pentest & Purple Team Expert

Reposted 7 Hours Ago
Be an Early Applicant
Sandoz, CA, USA
In-Office
Senior level
Biotech • Pharmaceutical
The Role
Lead penetration testing and purple team operations, collaborate on security strategies, and deliver actionable insights for vulnerability remediation.
Summary Generated by Built In

Job Description Summary

The Pentest & Purple Team Lead is responsible for conducting and leading penetration testing and purple team engagements, to proactively identify vulnerabilities and strengthen Sandoz security posture. As an individual contributor, the role drives hands on technical work while influencing security strategy through insights, reporting, and collaboration. Based in Prague, this position works cross functionally to continuously improve detection, prevention, and response capabilities across the organization.

Job Description

Sandoz continues to go through an exciting and transformative period as a global leader and pioneering provider of sustainable Biosimilar and Generic medicines. As we continue down this new and ambitious path, unique opportunities will present themselves, both professionally and personally. Join us, the future is ours to shape!

Your Key Responsibilities

  • Conduct and lead penetration testing engagements across infrastructure, cloud environments and network layers.
  • Plan and execute purple team exercises to simulate real-world attack scenarios and improve detection and response capabilities.
  • Collaborate closely within wider Security Operations teams to validate security controls and close detection gaps.
  • Develop and enhance adversary simulation techniques aligned with current threat intelligence and MITRE ATT&CK frameworks.
  • Identify, prioritize, and communicate vulnerabilities with clear remediation guidance and risk impact.
  • Produce detailed technical reports, executive summaries, and actionable recommendations for stakeholders.
  • Support security incident investigations with offensive expertise, root cause analysis, and attack reconstruction.
  • Stay current with emerging threats, tools, and techniques to continuously evolve testing methodologies.
  • Contribute to security awareness and knowledge sharing across teams.

 

What you’ll bring to the role:

  • Proven hands‑on experience in penetration testing, red teaming, or purple team operations within complex or regulated environments.
  • Demonstrated experience working closely with SOC / Blue Teams.
  • Strong technical expertise across network security, application security, cloud security, and common attack vectors.
  • Strong understanding of common web application vulnerability classes and exploitation techniques, including access control flaws, injections, XSS, SSRF, deserialization, crypto misuse, insecure direct object references, auth/session issues, and business logic vulnerabilities.
  • Experience designing and executing adversary simulations and purple team exercises.
  • Deep understanding of attack frameworks (e.g., MITRE ATT&CK), kill chain, and detection engineering principles.
  • Ability to translate technical findings into business risk and actionable remediation plans.
  • Strong proficiency with application testing toolsets such as:
  • Burp Suite, OWASP ZAP, Postman/Insomnia, API fuzzing tools, mobile proxies, and instrumentation.
  • Scripting/automation skills (e.g., Python, PowerShell, Bash) to build repeatable tests, proof‑of‑concepts, or automation hooks.
  • Familiarity with modern AppSec tooling (at least some of): SAST/DAST/IAST concepts, dependency scanning, secrets scanning, or code queries
  • Strong analytical and problem‑solving skills with a proactive, attacker‑mindset approach.
  • Excellent communication skills, with the ability to engage both technical and non‑technical stakeholders.
  • Ability to work independently as a senior individual contributor while influencing cross‑functional teams.
What you’ll receive:
  • Monthly pension contribution matching your individual contribution up to 3% of your gross monthly base salary

  • Risk Life Insurance

  • 5-week holiday per year (1 week above the Labor Law requirement)

  • Cafeteria employee benefit program – choice of benefits from Benefit Plus CZ in the amount of 12,000 CZK per year

  • Meal vouchers in amount of 120 CZK for each working day (full tax covered by company)

  • Multisport Card

  • Premium Health Care Program

  • Car Allowance

Why Sandoz? 

Sandoz is the global leader in Biosimilar and Generic medicines, a segment of the healthcare industry that delivers 80% of the world’s medicines at 30% of the cost, touching the lives of more than 1 billion people across 100+ countries! While we are proud of our achievements, we have an ambition to do more so that everyone can achieve the basic human right of good health. 

With investments in new development capabilities, production sites, new acquisitions, and partnerships, we have the opportunity to shape the future of Sandoz and help even more people gain access to low-cost, high-quality medicines, sustainably.  

Our momentum is powered by an open, collaborative culture driven by our talented and ambitious colleagues, who, in return for applying their skills, experience an agile and collegiate environment with impactful careers, where diversity of thought is welcomed and where personal growth is supported!  

  

Join us, help us make healthcare fairer and faster.  

Commitment to Diversity & Inclusion  

We are committed to building an outstanding, inclusive work environment and diverse teams representative of the patients and communities we serve. 

#Sandoz 

Skills Desired

Escalation, Information Security Audit, Information Security Risk Management, Quality Management, Root Cause Analysis (RCA), Sec Ops (Security Operations), Vendor Management

Skills Required

  • Proven hands-on experience in penetration testing, red teaming, or purple team operations within complex environments
  • Demonstrated experience working closely with SOC / Blue Teams
  • Strong technical expertise across network security, application security, and cloud security
  • Scripting/automation skills in Python, PowerShell, Bash
  • Experience designing and executing adversary simulations and purple team exercises
  • Strong analytical and problem-solving skills with a proactive, attacker-mindset approach

Sandoz Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sandoz and has not been reviewed or approved by Sandoz.

  • Healthcare Strength Health, dental, vision, and prescription coverage are consistently described as core components across U.S. roles and materials. Feedback suggests the medical offering is broad and a standard pillar of the package.
  • Retirement Support A 401(k) plan with a company match described as generous is commonly included for U.S. roles. This savings support is positioned alongside other primary benefits as part of total rewards.
  • Equity Value & Accessibility Equity eligibility is noted for many positions and a global all‑employee share program is being introduced from 2026. These elements add upside beyond base salary and annual bonus.

Sandoz Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Basel
17,135 Employees

What We Do

Sandoz is the global leader in generic and biosimilar medicines. ​ ​Our Purpose is to pioneer access to medicines for patients globally. We are on a mission to drive innovation in the healthcare industry by freeing up resources sustainably and responsibly while continuing to address global health challenges such as antimicrobial resistance.​ We are present in more than 100 countries and our medicines serve some 500 million people every year. We have two main global businesses: Generics - divided between standard generics and complex generics - and Biosimilars.

Similar Jobs

PwC Logo PwC

Connected Supply Chain, Planning - Kinaxis, Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
18 Locations
370000 Employees
99K-232K Annually

PwC Logo PwC

Strategy& Financial Services - AWM Consulting Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
14 Locations
370000 Employees
99K-232K Annually

PwC Logo PwC

Connected Supply Chain, Planning - Kinaxis, Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
18 Locations
370000 Employees
77K-202K Annually

Cox Enterprises Logo Cox Enterprises

Communications Specialist

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
50000 Employees
61K-92K Annually

Similar Companies Hiring

SOPHiA GENETICS Thumbnail
Software • Healthtech • Biotech • Big Data • Artificial Intelligence
Boston, MA
450 Employees
Pfizer Thumbnail
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
New York, NY
121990 Employees
Cencora Thumbnail
Healthtech • Logistics • Pharmaceutical
Conshohocken, PA
51000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account