Threat Mitigation Lead - Network and Systems Attack Surface

Posted Yesterday
Be an Early Applicant
Hiring Remotely in US
Remote
129K-253K Annually
Senior level
Healthtech • Biotech • Pharmaceutical
The Role
Leads cybersecurity threat mitigation and vulnerability burndown campaigns across enterprise teams. Translates vulnerability, exposure, and threat intelligence data into prioritized remediation plans, validates controls and evidence in GRC systems, and drives stalled work to closure. Serves as a technical subject matter expert, mentors analysts, collaborates with cyber defense and architecture teams, automates remediation workflows, and advises leadership on risk and mitigation priorities.
Summary Generated by Built In

At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us. 


Overview – Advisor - Cyber Programs, Mitigations, and Compliance 


The Cyber Threat Mitigations Team is looking for an experienced service-area lead with strong background in threat surface management and the technical control solutions that support it (ex. vulnerability scanning and prioritization platforms, EDR, SIEM).


This role is designed for someone who excels at working with cross-functional teams to drive down security risk across Lilly's technology estate, and who will build durable connections with adjacent cybersecurity teams to ensure emerging threats translate into prioritized, actionable mitigation work. 


As a Threat Mitigations Advisor, you will partner with internal cyber teams, platform and application owners, and business stakeholders to reduce the impact of identified vulnerabilities and threats. You will drive burndowns of targeted risks across the organization and support application teams in executing their cyber mitigation plans.


You will also serve as a technical anchor for the threat surface management squad, raising the capability of the analysts around you. 


Key Responsibilities: 


Threat Mitigation & Burndown Execution 

  • Assist in the intake of vulnerability, exposure, and threat intelligence data from across the cyber organization and translate it into scoped, executable burndown campaigns with clear owners, targets, and timelines. 
  • Develop solutions that accelerate burndown execution, including automation of triage, deduplication, ownership identification, and notification. 
  • Drive burndowns to closure — tracking progress against targets, unblocking remediation owners, and escalating stalled or high-severity work. 
  • Capture root cause, technical recommendations, and lessons learned, and package them for the teams that can act on them to drive durable process improvement. 

Threat Mitigation Plan Validation & Support 

  • Assist platform, application, and infrastructure teams in interpreting mitigation requirements and completing their security plans, removing friction rather than simply tracking overdue items. 
  • Serve as a technical resource for the ‘how’  
  • Confirm implementation of threat mitigation requirements in our GRC tool — validating that required controls are in place, evidence is attached, and records are accurate before closure. 

Threat Surface Management Squad Leadership 

  • Serve as the subject matter expert for the wider analyst pool, leading deep technical dives into vulnerabilities, adversary TTPs, and threat intelligence to build the team's capability. 
  • Upskill the Mitigation Analyst Pool by identifying skill gaps and closing them to sustain service area delivery. 
  • Develop and refine capabilities and strategies that expand what the threat surface management squad can deliver to the wider organization. 

Cross-functional Collaboration 

  • Build and sustain working relationships with adjacent cybersecurity teams including Cyber Defense, Identity and Access Management, Security Architecture & Engineering, and Platforms.  
  • Serve as a technical advisor to cyber leadership and their stakeholders across the wider organization, translating threat and remediation data into decisions leadership can act on. 

Basic Qualifications: 


  • Bachelor’s degree in Computer Science, Information Systems, or Cyber Security
  • 5+ years of experience in threat surface management, vulnerability management, cyber defense, or a related security discipline. 
  • 3 years+ experience scoping and driving remediation or mitigation campaigns to closure across teams you do not directly manage. 
  • 3 years+ of threat intelligence and exposure data, and how to apply it to prioritization (e.g., CVSS, EPSS, KEV, adversary TTPs, active exploitation reporting). 

Preferences:


  • Demonstrated technical leadership — mentoring analysts, running deep technical dives, and raising the capability of a team without formal authority. 
  • Hands-on experience with the security control platforms that generate and enforce mitigation work — vulnerability scanning and prioritization tooling, EDR, and SIEM. 
  • Certifications such as Certified Information Systems Security Professional (CISSP), Offensive Security Certified Professional (OSCP), GIAC Enterprise Vulnerability Assessor (GEVA), or equivalent. 
  • Experience automating triage, deduplication, ownership identification, or notification within a remediation workflow. 
  • Experience working alongside a cyber defense, SOC, or threat intelligence function. 
  • Experience in a regulated industry with formal control validation and audit expectations. 
  • Excellent stakeholder communication, with the ability to translate technical threat and remediation data into decisions for leadership and business owners. 
  • Strong problem-solving and analytical skills, with a keen eye for detail and risk management. 

Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.


Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status.


Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia (AMECA), Black Employees at Lilly (BE@Lilly), Chinese Culture Network (CCN), EnAble, Evolve, Lilly Indian Network (LIN), Organization of Latinx at Lilly (OLA), Pride (LGBTQ+ Allies), Veterans Leadership Network (VLN) and Women’s Initiative for Leading at Lilly (WILL).


Actual compensation will depend on a candidate’s education, experience, skills, and geographic location.  The anticipated wage for this position is

$129,000 - $253,000

Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly’s compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees.

#WeAreLilly

Skills Required

  • Bachelor's degree in Computer Science, Information Systems, or Cyber Security
  • 5+ years of experience in threat surface management, vulnerability management, cyber defense, or a related security discipline
  • 3+ years of experience scoping and driving remediation or mitigation campaigns to closure across teams not directly managed
  • 3+ years of experience with threat intelligence and exposure data and applying it to prioritization, including CVSS, EPSS, KEV, adversary TTPs, and active exploitation reporting
  • Technical leadership experience mentoring analysts and leading deep technical dives
  • Hands-on experience with vulnerability scanning and prioritization tools, EDR, and SIEM
  • CISSP, OSCP, GEVA, or equivalent certification
  • Experience automating triage, deduplication, ownership identification, or notification in remediation workflows
  • Experience working alongside a cyber defense, SOC, or threat intelligence function
  • Experience in a regulated industry with formal control validation and audit expectations
  • Excellent stakeholder communication and ability to translate technical threat and remediation data into leadership decisions
  • Strong problem-solving, analytical, detail-oriented, and risk management skills

Eli Lilly and Company Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Eli Lilly and Company and has not been reviewed or approved by Eli Lilly and Company.

  • Retirement Support — Feedback suggests long-term savings are bolstered by a defined-benefit pension alongside a company 401(k) match and retiree health options. These elements make total compensation feel strong beyond base salary.
  • Leave & Time Off Breadth — Feedback suggests paid time off is expansive, with substantial vacation, company shutdown days, and milestone time. This breadth of leave is viewed as a meaningful part of overall rewards.
  • Parental & Family Support — Feedback suggests family-building and caregiving support are robust, including paid parental leave, adoption or surrogacy assistance, and backup care. These programs enhance the perceived value of benefits across life stages.

Eli Lilly and Company Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Indianapolis, IN
39,451 Employees
Year Founded: 1876

What We Do

Eli Lilly and Company engages in the discovery, development, manufacture, and sale of products in pharmaceutical products business segment. For more than a century, we have stayed true to a core set of values – excellence, integrity, and respect for people – that guide us in all we do: discovering medicines that meet real needs, improving the understanding and management of disease, and giving back to communities through philanthropy and volunteerism.

Similar Jobs

PNC Bank Logo PNC Bank

Product Manager

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
100K-223K Annually

PNC Bank Logo PNC Bank

Principal Software Engineer

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
112K-250K Annually

Comcast Logo Comcast

Account Executive

Digital Media • Information Technology • News + Entertainment
Remote or Hybrid
New York, NY, USA
115000 Employees
65K-139K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
12 Locations
40000 Employees
45K-85K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Vitalize Thumbnail
Artificial Intelligence • Healthtech • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account