Global Cybersecurity Lead

Als
Madrid, Spain
29 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Cyber Security Supervisory Control and Data Acquisition (SCADA) Laboratory Information Management Systems Software Vulnerability Management Google Cloud Information Technology Process Control Systems GXP

Job description

  • Contribute to the development and execution of the global cybersecurity strategy aligned with ALS’s corporate objectives and international regulatory frameworks (GxP, ISO 27001, NIST, GDPR, 21 CFR Part 11).
  • Manage third-party risk assessments for technology vendors, partners, and digital supply chain providers.
  • Lead global risk management initiatives, including threat assessment, vulnerability management, and mitigation plans for IT and OT environments.
  • Oversee security across hybrid infrastructures, including laboratory information systems (LIMS, ELN, CDS), cloud platforms, and industrial control systems (SCADA, PLCs).
  • Coordinate global incident response, ensuring timely communication, investigation, and remediation of security events.
  • Review current security policies in place across the laboratories of the group to assess current practice and local requirements.
  • Define corporate security policies and standards to support harmonisation and consistency of practice locally.
  • Partner with global and regional teams to ensure compliance with corporate policies, GxP, data protection, and privacy regulations.
  • Lead security awareness and training programs tailored to scientific, technical, and operational personnel.
  • Collaborate with Quality, R&D, Production, and Legal to embed security by design into systems and processes.
  • Monitor and report cybersecurity KPIs and maturity metrics to Chief Information Security Officer executive committees.
  • Lead and coordinate responses to RFIs, security questionnaires, and due-diligence requests regarding IT security and compliance.

Requirements

  • Bachelor’s or Master’s degree in Computer Science, Information Security, Telecommunications, or a related field.
  • Advanced training or postgraduate studies in cybersecurity or technology risk management.
  • Recognized certifications such as CISM, CISSP, ISO 27001 Lead Implementer/Auditor, GICSP, NIST CSF Practitioner are highly valued.
  • Minimum 8 years of professional experience in cybersecurity, with 3-5 years in a leadership or global coordination role.
  • Proven experience in pharmaceutical, biotechnology, or scientific research environments.
  • Strong knowledge of regulated environments (GxP) and industrial/OT security (ISA/IEC 62443).
  • Experience managing security across cloud platforms (AWS, Azure, GCP) and hybrid infrastructures.
  • Demonstrated ability to manage complex, multinational security programs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobleads.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · WWC 2024

3:13 min

Core components of the internal Optimize ecosystem

Dominik Schneider Dominik Schneider · WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · WWC 2022

Videos

See all

Related articles

See all