Manager, Security Architecture & Cloud
Listed on 2025-12-05
-
IT/Tech
Cybersecurity, Cloud Computing
Overview
Kyowa Kirin is a fast-growing global specialty pharmaceutical company that applies state-of-the-art biotechnologies to discover and deliver novel medicines in four disease areas: bone and mineral; intractable hematologic; hematology oncology; and rare disease. A Japan-based company, our goal is to translate science into smiles by delivering therapies where no adequate treatments currently exist, working from drug discovery to product development and commercialization.
In North America, we are headquartered in Princeton, NJ, with offices in California, North Carolina, and Mississauga, Ontario.
We are seeking a highly skilled Manager, Security Architecture & Cloud to join our Global Information Security team. This role will be responsible for designing, reviewing, and implementing secure architectures across enterprise and cloud environments, ensuring alignment with our global strategy and pharmaceutical regulatory requirements. The ideal candidate will be hands-on, detail-oriented, and capable of advising business and technology leaders to ensure that security is embedded in the design and delivery of IT and cloud solutions.
Responsibilities- Develop and maintain secure architecture patterns and reference models for cloud, hybrid, and enterprise environments.
- Partner with Infrastructure, Application and Business teams to conduct threat modeling, risk assessments, and architecture reviews for critical pharmaceutical systems, including GxP and digital health platforms.
- Ensure cloud security controls (IAM, encryption, logging, monitoring) are consistently applied across AWS and Azure and GCP environments.
- Lead security design input into enterprise IT and application development, embedding Dev Sec Ops practices into CI/CD pipelines.
- Collaborate with global and regional security teams to ensure architectural alignment with enterprise standards.
- Contribute to incident response and remediation planning by providing architectural insights.
- Act as a trusted advisor to IT leadership, translating complex risks into business-focused guidance.
Education
Bachelor’s degree in Computer Science, Information Security, Engineering, or related field required;
Master’s degree preferred.
Experience
At least 7 years of progressive experience in information security or enterprise architecture, with 3+ years focused on cloud security;
Experience in regulated industries (pharma, biotech, healthcare), with knowledge of HIPAA, FDA, and 21 CFR Part 11;
Hands-on experience with security in AWS, Azure, and/or GCP;
Familiarity with microservices, containerization, and Dev Sec Ops approaches.
Certifications
Required:
CISSP or CCSP
Preferred: AWS Security Specialty, Azure Security Engineer, or TOGAF.
Technical Skills
• Deep expertise in Security Architecture and Cloud Security Design, including hybrid and multi-cloud environments (AWS, Azure, GCP).
• Proficiency in Identity and Access Management (IAM), encryption, logging, monitoring, and configuration of cloud-native security controls.
• Experience conducting threat modeling, risk assessments, and architecture reviews for enterprise and regulated (GxP, HIPAA, 21 CFR Part 11) systems.
• Knowledge of Dev Sec Ops practices and secure integration of automated security testing within CI/CD pipelines.
• Familiarity with containerization and microservices (Docker, Kubernetes) and associated security controls.
• Strong understanding of security frameworks and standards such as NIST CSF, ISO 27001, and CSA CCM, and their application to architecture governance.
• Experience supporting incident response and remediation through architectural analysis and secure design recommendations.
Requires up to 10% domestic and international travel
Salary and BenefitsThe anticipated salary for this position will be $125,000 to $140,000. The actual salary offered for this role at commencement of employment may vary based on several factors including but not limited to relevant experience, skill set, qualifications, education (including applicable licenses and certifications, job-based knowledge, location, and other business and organizational needs).
The listed salary is one…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).