- Company Name
- Summit Therapeutics, Inc.
- Job Title
- Senior Manager, IT Security, Compliance & Infrastructure
- Job Description
-
**Senior Manager, IT Security, Compliance & Infrastructure**
**Role Summary:** Senior IT security leadership role overseeing security program development, compliance with regulatory standards, and Microsoft cloud infrastructure management. Focus on risk mitigation, data protection, and system validation for GxP-regulated environments.
**Expectations:** Minimum 8+ years IT experience, 2+ years in security leadership roles. Demonstrated proficiency in regulatory compliance (GxP, SOX, HIPAA, GDPR) and cloud technology (Azure, Microsoft 365). Strong analytical, communication, and cross-functional collaboration skills required.
**Key Responsibilities:**
- Establish and lead IT security program aligned with NIST Cybersecurity Framework.
- Design, implement, and manage security policies compliant with FDA, HIPAA, GDPR, and 21 CFR Part 11.
- Scale Microsoft security tools (Defender, Sentinel, Entra ID, Purview, Intune) for threat protection and data governance.
- Conduct risk assessments, vulnerability management, incident response, and audit readiness for regulatory inspections (FDA/EMA).
- Develop AI/ML security policies ensuring ethical compliance and data security.
- Lead system validation practices for GxP-regulated systems and manage Change Control Board (CCB) processes.
- Drive security awareness training and culture across the organization.
- Support Microsoft Azure/M365 infrastructure optimization, including patch management, SaaS stability, and vendor evaluation.
- Collaborate with infrastructure teams on identity, networking, endpoint operations, and cloud scalability initiatives.
**Required Skills:**
- Proficiency in Microsoft security platforms ( Defender, Sentinel, Entitlement Governance) and cloud infrastructure (Azure, Microsoft 365).
- Regulatory compliance expertise (SOX, FDA GxP, HIPAA, GDPR, NIST CSF).
- System validation practices and audit preparation for GxP environments.
- Knowledge of AI/ML security frameworks and ethical compliance.
- Strong leadership and cross-functional collaboration with technical/non-technical stakeholders.
- Experience with threat protection, identity/endpoint security, and vendor license optimization.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, MIS, or related field.
- Active certifications preferred: CISSP, CISM, CISA, Microsoft Security Certifications (e.g., Azure Security Engineer Associate).
- Ongoing pursuit of advanced security certifications aligned with NIST standards.
---
**Word Count**: 498