PCI Pharma Services Logo

PCI Pharma Services

Senior Security Engineer / AppSec Engineer

Reposted Yesterday
In-Office or Remote
Hiring Remotely in Philadelphia, PA
Senior level
In-Office or Remote
Hiring Remotely in Philadelphia, PA
Senior level
The Senior Security Engineer leads technical security efforts, manages vulnerability programs, ensures compliance, and develops security architecture in a regulated pharma environment.
The summary above was generated by AI

Life changing therapies. Global impact. Bridge to thousands of biopharma companies and their patients.


We are PCI. 


Our investment is in People who make an impact, drive progress and create a better tomorrow. Our strategy includes building teams across our global network to pioneer and shape the future of PCI.

   

Position Summary

The Senior Security Engineer will serve as the technical security lead for PCI Pharma, responsible for security architecture, application security, vulnerability management, and security engineering across enterprise and manufacturing environments. This role combines hands-on technical work with strategic security advisory, ensuring protection of pharmaceutical intellectual property, patient data, and compliance with industry regulations.

Key Responsibilities
  • Design and implement security architecture for cloud (Azure, AWS), on-premises, and hybrid environments
  • Lead application security program including SAST/DAST integration, secure code reviews, and developer training
  • Manage enterprise vulnerability management using Nessus, including scan scheduling, risk prioritization, and remediation tracking
  • Architect and maintain Zero Trust security framework including identity-centric access controls
  • Conduct security assessments for new applications, infrastructure changes, and M&A integrations
  • Design network segmentation strategies for IT/OT environments and manufacturing systems
  • Implement and manage endpoint security solutions (EDR, AV) in coordination with RUN team
  • Lead security incident response for complex technical investigations
  • Develop security standards, policies, and technical guidelines aligned with pharmaceutical regulations
  • Evaluate and recommend security tools and technologies for continuous improvement
  • Coordinate penetration testing activities and remediation of findings
  • Provide security consultation for cloud migrations and digital transformation initiatives
Required Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, or related field
  • 7+ years of progressive cybersecurity experience with 3+ years in security engineering/architecture
  • Deep expertise in vulnerability management tools (Nessus, Qualys, or Rapid7)
  • Strong application security knowledge including OWASP Top 10, secure SDLC, and DevSecOps practices
  • Experience with cloud security in Azure and/or AWS (security groups, IAM, encryption)
  • Proficiency in network security including firewalls, IDS/IPS, and segmentation
  • Knowledge of endpoint security solutions and EDR platforms
  • Strong scripting abilities (PowerShell, Python) for security automation
  • Experience in regulated industries with compliance requirements
  • CISSP, CISM, or equivalent security certification
Preferred Qualifications
  • Master's degree in Cybersecurity or Information Assurance
  • Pharmaceutical or healthcare industry experience with GxP knowledge
  • GPEN, OSCP, or other hands-on security certifications
  • Experience with IT/OT security and industrial control systems
  • Knowledge of 21 CFR Part 11 and computer system validation
  • Cloud security certifications (AZ-500, AWS Security Specialty)
Technical Skills & Tools

Nessus / Tenable.io vulnerability management  •  SAST/DAST tools (SonarQube, Checkmarx, Burp Suite)  •  Azure Security Center / AWS Security Hub  •  EDR platforms (CrowdStrike, Defender for Endpoint)  •  SIEM platforms (Splunk, Sentinel)  •  Firewall management (Palo Alto, Cisco ASA)  •  PowerShell / Python security scripting  •  Git and CI/CD security integration

Key Performance Indicators
  • Critical vulnerability remediation SLA (target: <7 days)
  • Application security review coverage (target: 100% of new apps)
  • Security incident response time (target: <1 hour for P1)
  • Penetration test finding closure rate (target: >90% within 90 days)
  • Zero Trust implementation milestones (per roadmap)

Join us and be part of building the bridge between life changing therapies and patients. Let’s talk future

Equal Employment Opportunity (EEO) Statement:
PCI Pharma Services is an Equal Opportunity/Affirmative Action Employer. We do not unlawfully discriminate on the basis of race, color, religion, age, sex, creed, national origin, ancestry, citizenship status, marital or domestic or civil union status, familial status, affectional or sexual orientation, gender identity or expression, genetics, disability, military eligibility or veteran status, or any other protected status.

At PCI, Equity and Inclusion are at the core of our company’s purpose: Together, delivering life-changing therapies. We are committed to cultivating an inclusive workplace by holding ourselves accountable to the highest standards of understanding, fairness, respect, and equal opportunity – at every level. We envision a PCI community where everyone can belong and grow, and we strive to bring this vision to reality by continuously and intentionally assessing our people practices, policies and programs, marketing approach, and workplace culture.

Top Skills

AWS
Azure
Edr Platforms
Git
Nessus
Owasp
Powershell
Python
Qualys
Rapid7
Siem Platforms

Similar Jobs

7 Hours Ago
Remote or Hybrid
USA
196K-245K Annually
Expert/Leader
196K-245K Annually
Expert/Leader
Edtech • Information Technology • Software
The VP of Global Professional Services strategizes and executes a services organization, leveraging AI and analytics to drive platform adoption and customer satisfaction. Responsibilities include overseeing service offerings, financial performance, delivery excellence, and leading a global team.
11 Hours Ago
Remote or Hybrid
United States
125K-159K Annually
Senior level
125K-159K Annually
Senior level
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Design, build, and maintain secure, scalable SecOps platforms using C++, Rust, and scripting. Implement CI/CD and DevOps practices, integrate systems via APIs/webhooks and AI-driven tools, architect cloud (AWS/Azure/GCP) environments, optimize Linux/kernel configurations, automate infrastructure, and collaborate with SecOps on monitoring, detection, and response to protect enterprise assets.
Top Skills: Scripting Languages,C++,Rust,Linux,Linux Kernel,Aws,Azure,Gcp,Apis,Webhooks,Ci/Cd,Devops,Ai-Driven Tools
13 Hours Ago
Remote
2 Locations
174K-261K Annually
Senior level
174K-261K Annually
Senior level
Artificial Intelligence • Productivity • Software • Automation
As a Sr. Software Engineer at Zapier, you'll build and scale robust backend systems for their automation platform, collaborating on various impactful projects, improving user workflows, and ensuring smooth execution of automations.
Top Skills: Ai ToolingDjangoMySQLNext.JsNode.jsPostgresPythonReactRestful ApisTypescript

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account