Global Cybersecurity Lead
Als
Madrid, Spain
29 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Amazon Web Services
Microsoft Azure
Cyber Security
Supervisory Control and Data Acquisition (SCADA)
Laboratory Information Management Systems
Software Vulnerability Management
Google Cloud
Information Technology
Process Control Systems
GXP
Job description
- Contribute to the development and execution of the global cybersecurity strategy aligned with ALS’s corporate objectives and international regulatory frameworks (GxP, ISO 27001, NIST, GDPR, 21 CFR Part 11).
- Manage third-party risk assessments for technology vendors, partners, and digital supply chain providers.
- Lead global risk management initiatives, including threat assessment, vulnerability management, and mitigation plans for IT and OT environments.
- Oversee security across hybrid infrastructures, including laboratory information systems (LIMS, ELN, CDS), cloud platforms, and industrial control systems (SCADA, PLCs).
- Coordinate global incident response, ensuring timely communication, investigation, and remediation of security events.
- Review current security policies in place across the laboratories of the group to assess current practice and local requirements.
- Define corporate security policies and standards to support harmonisation and consistency of practice locally.
- Partner with global and regional teams to ensure compliance with corporate policies, GxP, data protection, and privacy regulations.
- Lead security awareness and training programs tailored to scientific, technical, and operational personnel.
- Collaborate with Quality, R&D, Production, and Legal to embed security by design into systems and processes.
- Monitor and report cybersecurity KPIs and maturity metrics to Chief Information Security Officer executive committees.
- Lead and coordinate responses to RFIs, security questionnaires, and due-diligence requests regarding IT security and compliance.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Information Security, Telecommunications, or a related field.
- Advanced training or postgraduate studies in cybersecurity or technology risk management.
- Recognized certifications such as CISM, CISSP, ISO 27001 Lead Implementer/Auditor, GICSP, NIST CSF Practitioner are highly valued.
- Minimum 8 years of professional experience in cybersecurity, with 3-5 years in a leadership or global coordination role.
- Proven experience in pharmaceutical, biotechnology, or scientific research environments.
- Strong knowledge of regulated environments (GxP) and industrial/OT security (ISA/IEC 62443).
- Experience managing security across cloud platforms (AWS, Azure, GCP) and hybrid infrastructures.
- Demonstrated ability to manage complex, multinational security programs.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.jobleads.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
LM
Luis Minvielle
What’s the Difference between a Junior, Mid, and Senior Developer?
about 3 years ago
LM
Luis Minvielle
Top-Paying Tech Jobs (with Salaries)
over 2 years ago
LM
Luis Minvielle
The Most Popular IT Jobs on the Market
over 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago