Role Description
The Staff Engineer - DevSecOps is responsible for protecting the organization's AI infrastructure, data, and systems from internal and external cybersecurity threats by implementing, managing, and continuously improving security practices, tools, and operations with a focus on AI, cloud applications, and infrastructure.
-
Build AI-assisted development tools, such as coding copilots or agentic coding tools.
-
Design, implement, and continuously improve security solutions, AI guardrails, and procedures.
-
Improve the organization's security posture by identifying weaknesses and vulnerabilities in its security infrastructure and implementing traditional and AI-centric solutions to address them.
-
Integrate with various teams on technology initiatives to improve security of our applications, cloud, and AI infrastructure.
-
Assist in investigating and responding to security events and incidents, such as malware infections, unauthorized access attempts, and other potential security breaches.
-
Determine best procedures to contain threats, document findings, and escalate issues as needed.
-
Monitor and analyze security logs and events from various sources.
-
Stay current with the latest threat landscape, emerging trends, and solutions in AI and cybersecurity to proactively identify and mitigate potential security risks.
-
Assist with and provide cyber expertise to internal staff, vendors, and partners on security practices and issues.
-
Follow industry and Exelixis best practices and procedures in a SOX and an FDA regulated environment.
-
Perform other duties as assigned.
-
Comply with all policies and standards.
Qualifications
-
Bachelorβs degree in related discipline and 7 years of related experience; or
-
Masterβs degree in related discipline and 5 years of related experience; or
-
Equivalent combination of education and experience.
-
CISSP, CISM, CEH, OSCP, GIAC or similar cybersecurity certification preferred.
Requirements
-
Experience with operation and implementation of cybersecurity tools.
-
Experience in designing, implementing, and managing security controls within cloud platforms, such as IAM, VPC, Zero Trust principles, IaC, IAAS, Security Groups, Key Management Services, SDLC, Ci/Cd pipelines and Network Security.
-
Experience in IT Security or related infrastructure administration role in an enterprise environment. Technical lead experience is preferred.
-
Experience in investigations and response to cyber events and incidents.
-
Experience in enhancing organizational security awareness and resilience.
-
Experience with cloud, system, and application security.
-
Experience administering IT systems.
-
Experience working in Agile environments and using ticketing systems (e.g., JIRA, JSM).
-
Experience in regulated industries (e.g., biotech, pharma) with knowledge of GxP and SOX compliance preferred.
Benefits
-
Comprehensive employee benefits package, including a 401k plan with generous company contributions.
-
Group medical, dental and vision coverage.
-
Life and disability insurance.
-
Flexible spending accounts.
-
Discretionary annual bonus program, or if field sales staff, a sales-based incentive plan.
-
Opportunity to purchase company stock and receive long-term incentives.
-
15 accrued vacation days in the first year.
-
17 paid holidays including a company-wide winter shutdown in December.
-
Up to 10 sick days throughout the calendar year.
Company Description
Our office is a modern, open space that fosters collaboration and creativity. Teams work closely together, sharing ideas and solutions in a supportive atmosphere. We provide all necessary equipment, including dual monitors and ergonomic chairs, to ensure a comfortable workspace.