Director of Cloud Security Architecture - Evinova

    • AstraZeneca
  • Gaithersburg, MD
  • Posted 23 days ago | Updated 2 hours ago

Overview

On Site
Full Time

Skills

Policies and procedures
Data-flow diagrams
Amazon Web Services
Attention to detail
Cloud security
Life sciences
Artificial intelligence
Cyber security
IT architecture
Customer facing
Data security
Network security
Identity management
Security operations
Professional development
Problem solving
Security controls
Risk management
Product engineering
Threat analysis
Vulnerability management
Continuous improvement
Business continuity planning
Computer science
Software design
Security architecture
Software security
Web applications
Access control
Policies
Continuous monitoring
Information security
Network design
Microsoft Azure
Functional requirements
Project management
Process improvement
Critical thinking
Information systems
Clinical research
Clinical trials
Collaboration
Social media
Employment authorization
Health care
Data
Leadership
Science
Innovation
Reporting
Roadmaps
NATURAL
Hardening
Articulate
Cloud computing
Network
Storage
Documentation
Regulatory Compliance
Auditing
Metrics
SaaS
Firewall
Design
Kubernetes
Authentication
Cryptography
Management
Multi-factor authentication
SAML
OAuth
OIDC
Computer networking
Communication
CISSP
Cisco Certifications
Privacy
Pharmaceutics
LinkedIn
Facebook
Recruiting

Job Details

Are you ready to be part of the future of healthcare? Can you think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you !

Transform billions of patients' lives through technology, data, and innovative ways of working. You're disruptive, decisive, and transformative. Someone excited to use technology to improve patients' health. We're building a new Health-tech business - Evinova, a fully-owned subsidiary of AstraZeneca Group.

Evinova delivers market-leading digital health solutions that are science-based, evidence-led, and human experience-driven. Thoughtful risks and quick decisions come together to accelerate innovation across the life sciences sector. Be part of a diverse team that pushes the boundaries of science by digitally empowering a deeper understanding of the patients we're helping. Launch pioneering digital solutions that improve the patients' experience and deliver better health outcomes. Together, we have the opportunity to combine deep scientific expertise with digital and artificial intelligence to serve the wider healthcare community and create new standards across the sector.

The Cloud Security Architecture Lead role presents a unique opportunity to join Evinova from the beginning and implement innovative cyber security practices that are designed by industry, for industry. This role, reporting to the Evinova Head of Cyber Security, will be hands-on in ensuring that security requirements are adequately addressed across Evinova's entire technology architecture (i.e., corporate infrastructure and customer-facing digital solutions). This role will encompass various architectural domains, such as Data Protection, Network Security, Cloud Security, Identity and Access Management, and Security Operations. In addition to developing Evinova-wide Cloud Security architecture methodologies and future roadmaps, the Cloud Security Architecture Lead will also proactively identify and promote opportunities to optimize and simplify our cyber defenses. Additionally, this role will closely collaborate with globally dispersed technology teams - enabling excellent opportunities for professional development across technology domains and international geographies. Success in this role requires leading by influence, exhibiting strong emotional intelligence, and a natural disposition toward problem-solving. The ideal candidate will think holistically and deliver on critical initiatives to leverage next-generation security solutions.

Key responsibilities include:
  • Develop and maintain the Evinova Cloud Security Architecture methodology and reference materials (e.g., designs, hardening guides, standards).
  • Develop and maintain a multi-year roadmap outlining key protection measures and their planned maturity/investment targets.
  • Determine and articulate risk-based protection schemes for relevant data, cloud environments, corporate infrastructure, and end-customer-facing digital solutions - addressing all applicable layers (e.g., data, transport, network, storage, etc.).
  • Ensure complete isolation of Evinova's sensitive customer information from our partner company through physical and logical isolation, policies, and procedures.
  • Establish and maintain authoritative documentation articulating established security controls/technologies and system descriptions.
  • Evaluate proposed security architectures and designs to determine the coverage and effectiveness of planned cyber risk reduction measures.
  • Perform periodic reviews over critical components to identify gaps in the architecture and ensure developed platforms, systems, and architectures are consistent with the Evinova Cyber security Architecture guidelines.
  • Contribute to Security Risk Management Plans and Data Flow diagrams for products and solutions.
  • Provide subject matter expertise level advisory to platform and product engineering teams, enabling timely consideration of cyber protection controls and integration with relevant cyber services (e.g., Security Monitoring, Threat Intelligence, etc.).
  • Partner with the Quality and Compliance Team to ensure the effectiveness of engineering security practices, aligned with relevant standards, and fully documented in policies/procedures. Track and develop remediation strategies to ensure continued compliance with relevant regulations and audit requirements.
  • Provide leadership and hands-on implementation support for cyber capability/tooling deployments.
  • Provide guidance and direction to distributed Security Engineers and Security Leads to ensure standardization and risk-aligned protection measures.
  • Collaborate with the Security Operations Lead and outsourced partners to optimize our security monitoring, vulnerability management, and detection capabilities.
  • Drive continuous improvement initiatives to enhance the effectiveness and efficiency of the cyber security program, using feedback, metrics, and lessons learned.
  • Provide advisory-based perspectives to the CTO leadership team on appropriate technology solutions to align residual risk to the organizational risk appetite.
  • Actively collaborate with Evinova and AstraZeneca Group leadership to align and share best practices for cyber security, business continuity, and other related policies and procedures.
Minimum Qualifications:
  • Bachelor's degree in Technology, Computer Science, Engineering, or a related field.
  • 8+ years of combined experience in the following: software design, distributed technologies, cloud security, security architecture, and enterprise security solutions for multiple technology platforms/frameworks/ languages.
  • Current experience securing platforms and workloads in the AWS cloud.
  • Prior experience providing cybersecurity architecture-related capabilities at a SaaS/cloud service provider.
  • Prior experience architecting cyber security solutions for multi-tenant cloud environments across a global customer base.
  • Well-versed with application security implementations, firewalls, web application firewalls, DMZs, and network architectures.
  • Ability to guide the development, design, and implementation of security standard methodologies for all layers of the application stack.
  • Solid understanding of deploying applications in a cloud environment, containerization (e.g., Kubernetes, EKS, etc.), cloud patterns, and cloud service/user authentication.
  • Strong understanding of Identity and Access Management (IAM), Cryptography / Key Management, Access Controls and Security Protocols, Secrets Modernization, and Secrets Management (e.g., MFA, SAML, OAuth, OIDC, etc.).
  • Demonstrable experience establishing cloud security strategies, securing multi-tenant environments, and implementing data segregation/isolation controls in AWS.
  • Demonstrable experience securing cloud-based custom-developed solutions (e.g., policy development, controls identification and implementation, continuous monitoring, audit response, etc.).
  • Deep understanding of information security technologies, networking, and network architecture is required - preferably in-depth exposure to Amazon Web Services and Microsoft Azure security concepts/services.
  • Ability to make pragmatic decisions by analyzing highly sophisticated situations, assessing risks, and balancing strategic and tactical compliance/quality requirements.
  • Ability to work independently in a fast-paced environment with a demonstrable ability to manage competing priorities.
  • Excellent written and verbal communication skills, project management, process improvement, attention to detail, and critical thinking skills are highly preferred.
  • At least one of the following professional certifications: AWS Security Architect, AWS Certified Solution Architect, AWS Security Principles, Certified Information Systems Security Professional (CISSP), and/or Certified Cloud Security Professional (CCSP).
Desired Qualifications:
  • Master's degree in computer science, engineering, or similar relevant area of study
  • Experience in ensuring compliance within a highly regulated sophisticated global business environment, particularly in the healthcare and/or clinical research industry.
  • A global perspective on privacy, security, and data protection issues and trends (experience with Asia-Pacific data privacy and protection regulations is a strong plus).
  • Demonstrate initiative, strong customer orientation, and cross-cultural working.
Why Evinova (AstraZeneca)?

Evinova draws on AstraZeneca's deep experience developing novel therapeutics, informed by insights from thousands of patients and clinical researchers. Together, we can accelerate the delivery of life-changing medicines, improve the design and delivery of clinical trials for better patient experiences and outcomes, and think more holistically about patient care before, during, and after treatment. We know that regulators, healthcare professionals, and care teams at clinical trial sites do not want a fragmented approach. They do not want a future where every pharmaceutical company provides its own, different digital solutions. They want solutions that work across the sector, simplify their workload, and benefit patients broadly. By bringing our solutions to the wider healthcare community, we can help build more unified approaches to how we all develop and deploy digital technologies, better serving our teams, physicians, and ultimately patients. Evinova represents a unique opportunity to deliver meaningful outcomes with digital and AI to serve the wider healthcare community and create new standards for the sector. Join us on our journey of building a new kind of health tech business to reset expectations of what a bio-pharmaceutical company can be. This means we're opening new ways to work, pioneering cutting-edge methods, and bringing unexpected teams together. Interested? Come and join our journey.

So, what's next?

Are you already imagining yourself joining our team? Good, because we can't wait to hear from you.

Where can I find out more?

Our Social Media, Follow AstraZeneca on LinkedIn

Follow AstraZeneca on Facebook

Follow AstraZeneca on Instagram

Learn more about Evinova

AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.