Cyber Security Specialist
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Capricor Therapeutics (NASDAQ: CAPR) is a biotechnology company dedicated to advancing transformative cell and exosome-based therapies for rare diseases. At the forefront of our innovation is Deramiocel (
* CAP-1002
* ), our lead cell therapy in late-stage development for Duchenne muscular dystrophy. We are also harnessing our proprietary StealthX™ exosome platform to unlock new possibilities in targeted delivery and vaccinology. Every program reflects our commitment to pushing the boundaries of science and delivering life-changing treatments to patients and families who need them most.
We are seeking a detail-oriented Security Analyst to protect our cybersecurity operations within our regulated biotech/pharmaceutical environment. This role combines hands‑on security operations with compliance governance, focusing on protecting GMP systems, regulated data, and financially relevant systems in scope for SOX compliance.
This is a unique opportunity to work at the intersection of threat operations and regulatory compliance, ensuring adherence to GMP, SOX IT General Controls (ITGCs), and industry security frameworks while actively defending against evolving cyber threats.
Monitor and Respond to Security Threats- Monitor, triage, and respond to security alerts across endpoint, email, and SIEM platforms
- Investigate security incidents impacting:
- GMP systems and regulated environments
- SOX in-scope systems (financial applications, identity systems, etc.)
- Execute incident response procedures aligned with validated and auditable processes
- Maintain detailed, audit-ready documentation of all incidents and remediation actions
- Administer and implement Crowd Strike Falcon for endpoint detection and response (EDR)
- Manage Abnormal Security for phishing, business email compromise (BEC), and account takeover threats
- Perform vulnerability assessments using
Rapid7
InsightVM - Oversee
Know Be4 security awareness training and phishing simulations - Coordinate with SIEM platforms for log analysis and threat correlation
- Support SOX ITGC control execution and evidence collection, including:
- User Access Reviews (UARs)
- Logical access controls (joiner/mover/leaver processes)
- Change management controls
- Logging and monitoring controls
- Prepare and maintain audit-ready documentation for SOX compliance testing
- Coordinate with Finance and IT teams on control execution and remediation
- Draft, review, and maintain information security policies, standards, and SOPs aligned with:
- GxP requirements (GMP, GCP, GLP)
- SOX IT General Controls
- 21 CFR Part 11 (where applicable)
- NIST CSF, NIST 800-53, or CIS Controls
- Ensure all policies are version‑controlled, formally approved, and audit-ready
- Partner with IT, Finance, QA, and Compliance to align controls across regulated and financial systems
- Support internal and external audits including SOX, FDA, SOC 2, and regulatory inspections
- Prepare control evidence and documentation packages
- Track audit findings and coordinate remediation activities
- Maintain relationships with internal audit and external assessors
- Conduct regular vulnerability scans across the environment
- Prioritize remediation based on:
- Regulatory impact (GMP systems)
- Financial/reporting risk (SOX systems)
- Threat landscape and exploitability
- Coordinate remediation through appropriate change control processes
- Track and document remediation evidence for compliance reporting
- Administer security awareness training programs for all staff
- Deliver targeted training for users with access to:
- Regulated systems
- Financial/SOX in-scope systems
- Conduct phishing simulation campaigns and analyze results
- Track training metrics and maintain compliance records
- Develop and maintain security playbooks, SOPs, and runbooks
- Contribute to security metrics, KPIs, and executive reporting
- Identify gaps in controls, detection capabilities, and governance processes
- Recommend and implement security improvements aligned with business objectives
- Minimum 3 years of hands‑on cybersecurity experience
- At least 2…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).