USDM Life Sciences is hiring a Senior IT/Security Engineer to lead end-to-end delivery of IT, information security, and GxP computerized-systems projects in a regulated environment. This onsite role in Palo Alto, CA combines hands-on engineering across identity, endpoints, and cloud/SaaS with validation documentation and cross-functional stakeholder communication.
What you’ll do
- Run multiple concurrent IT and security projects end-to-end by defining scope and success criteria, building delivery plans, managing dependencies and risks, and driving completion on schedule.
- Maintain a transparent project portfolio in Jira/Confluence, including clear owners, dates, and status, with weekly status updates and early escalation of blockers with recommended options.
- Coordinate vendors and MSP/MSSP partners and consultants, tracking deliverables against statements of work and holding partners accountable.
- Create reusable project artifacts such as requirements, designs, test evidence, runbooks, and handoff documentation.
- Implement identity and access control using Okta or Microsoft Entra ID, including SSO/MFA rollouts, SCIM provisioning, conditional access policies, and access review cycles.
- Deploy and support endpoint management and security for macOS and Windows, including MDM enrollment, EDR (for example, CrowdStrike or Microsoft Defender), hardening baselines, and patch or vulnerability remediation.
- Deliver cloud and SaaS workstreams across Microsoft 365, Azure/AWS, and Google Workspace, covering security configuration, DLP and information protection, backup, and integrations.
- Support network and site infrastructure projects across Palo Alto, Switzerland, and future campuses, including LAN/WLAN, firewalls, VPN, and ZTNA.
- Automate repetitive tasks using PowerShell and Python (and relevant APIs) and document the solutions.
- Triage and investigate security alerts from SIEM/EDR, execute incident response procedures, document findings, and coordinate with the MSSP as directed.
- Run the vulnerability remediation cycle by tracking findings, driving owners to closure, and reporting progress.
- Complete vendor security assessments and respond to customer or partner security questionnaires.
- Execute GxP validation activities for cloud and SaaS systems using risk-based principles (GAMP 5 / CSA) in compliance with 21 CFR Part 11 and EU Annex 11.
- Author and maintain validation lifecycle documentation such as Validation Plans and Validation Summary Reports; URS and functional or configuration specifications; risk assessments and traceability matrices; and IQ/OQ/PQ (or equivalent) protocols and test evidence.
- Support change control, periodic reviews, audit-trail reviews, and inspection readiness with Quality.
- Communicate proactively with stakeholders across Quality, R&D, Clinical, Finance, and HR, translating technical detail for non-technical audiences.
- Provide escalated (Tier 3) support and mentor IT support staff and contractors.
- Perform other related duties and assignments as required.
What you bring
- 7+ years of hands-on IT infrastructure and/or information security engineering experience, with a proven ability to deliver multiple projects concurrently and on time.
- Hands-on experience in at least two areas: identity (Okta/Entra ID), endpoint management/EDR, Microsoft 365/Azure or AWS administration and security, network security, and SIEM alert triage.
- Working knowledge of IAM concepts including SSO, MFA, SAML/OIDC, SCIM, and conditional access.
- Scripting experience with PowerShell, Python, or similar for automation and integration.
- Computerized System Validation experience in a GxP-regulated biotech, pharmaceutical, or medical device environment (including 21 CFR Part 11, EU Annex 11, GAMP 5).
- Strong project management fundamentals including planning, task tracking, vendor coordination, risk or issue management, and structured status reporting in Jira/Confluence (or equivalent).
- Exceptional written and verbal English communication skills, with comfort presenting to executive and C-level leadership.
- Organized and detail-oriented approach, comfortable working through ambiguity, with a bias for action and follow-through.
- Ability to work onsite in Palo Alto, CA, 40 hours per week, with occasional after-hours availability for maintenance windows and incidents.
Benefits
- Full-time employees: eligibility for health, vision, and dental insurance, life insurance, short and long-term disability, plus hospital indemnity, accident, and critical care coverage.
- Full and part-time employees (age 21+): eligibility to participate in USDM’s 401k plan.
- Full and part-time employees may be eligible for paid time off.
- All employees: eligibility for rewards and recognition program.
Technologies you may work with
Okta, Microsoft Entra ID, SSO, MFA, SCIM, conditional access, macOS, Windows, MDM, EDR, CrowdStrike, Microsoft Defender, Microsoft 365, Azure, AWS, Google Workspace, DLP, VPN, ZTNA, PowerShell, Python, SIEM, Jira, Confluence, GAMP 5, CSA, 21 CFR Part 11, EU Annex 11, IQ/OQ/PQ, SAML/OIDC, NIST CSF, SOC 2, CIS Controls, Zscaler, Cloudflare, DocuSign, Veeva, e-signature.
Preferred qualifications
- Experience in clinical-stage or emerging biotech settings with a lean IT team.
- Certifications such as CompTIA Security+, CISSP, Microsoft SC-300/AZ-104, Okta Certified Professional, PMP/CAPM, or ISPE GAMP training.
- Familiarity with security frameworks (NIST CSF, SOC 2, CIS Controls) and SASE/ZTNA platforms (Zscaler, Cloudflare).
- Experience with DocuSign, Veeva, or other common GxP SaaS platforms, including e-signature and Part 11 configurations.
Compensation: USD 70 - 80 per hour.
Working conditions
- Prolonged periods of sitting or standing at a desk and working on a computer in an environmentally controlled home office environment.
- Ability to operate other office productivity machinery such as a calculator, scanner, or printer.
- Frequent communication with stakeholders via telephone, email, or instant message, with ability to exchange accurate information.