Stand out for this role — generate a tailored resume and cover letter in about a minute.
Neurocrine Biosciences seeks a hands-on Senior Systems Security Engineer to plan, implement, and drive enterprise security posture across Linux, Windows, cloud, and hybrid environments. You will lead vulnerability management, patch automation, and policy‑driven controls, serving as a key liaison to Cybersecurity, IT, and Compliance teams.
The role emphasizes KPI reporting and audit readiness. Responsibilities include scaling patch management (AWS, Azure, on‑prem), SOPs, and continuous
Neurocrine Biosciencesis a leading biopharmaceutical company with a simple purpose: to relieve suffering for people with great needs. We are dedicated to discovering, developing and commercializing life-changing treatments for patients with under-addressed neurological, psychiatric, endocrine and immunological disorders. The company's diverse portfolio includes FDA-approved treatments for tardive dyskinesia, chorea associated with Huntington's disease, classic congenital adrenal hyperplasia, hyperphagia in Prader-Willi syndrome, endometriosis* and uterine fibroids*, as well as a robust pipeline including multiple compounds in mid- to late-phase clinical development across our core therapeutic areas. For more than three decades, we have applied our unique insight into neuroscience and the interconnections between brain and body systems to treat complex conditions. We relentlessly pursue medicines to ease the burden of debilitating diseases and disorders, because you deserve brave science. For more information, visit neurocrine.com , and follow the company on LinkedIn , X , Facebook and YouTube . ( *in collaboration with AbbVie )
This is a hands-on, automation-driven senior systems security engineering role responsible for planning, implementing, and driving enterprise technology infrastructure security posture and regulatory compliance readiness across Linux, Windows, cloud, on-prem, and hybrid environments. The engineer serves as a senior technical resource for enterprise infrastructure vulnerability management, overseeing the process from initial alert through remediation and closure verification. The role also develops and improves patch automation using scripting, configuration management, and orchestration, while continuously evaluating tools and processes to adapt to changes in the infrastructure and threat landscape. The engineer applies deep systems engineering and enterprise systems administration expertise to plan and execute security patches, and translates Cybersecurity policy requirements into implemented, auditable controls, establishing KPIs to measure and report progress against security risk remediation goals. The engineer also establishes and maintains Standard Operating Procedures (SOPs) and change management controls to ensure infrastructure security changes are consistently documented and traceable. This provides objective evidence for security and access control audits while maintaining continuous organizational audit readiness. This role serves as a key technical resource and liaison between Cybersecurity, IT business partners, Internal Audit, and Compliance/Quality functions, ensuring that security requirements are operationalized consistently and remediation work is tracked to closure with measurable outcomes.
Lead complex infrastructure vulnerability remediation efforts and continuously improve the tools and automation used to detect, remediate, and verify security findings across Linux, Windows, cloud, network, and hybrid infrastructure
Plan and implement security patches across enterprise Linux and Windows server environments, including patch testing, sequencing, rollback planning, and post patch validation
Lead and coordinate the enterprise vulnerability remediation program across cloud (AWS/Azure), on prem, and hybrid infrastructure, prioritizing based on risk severity, exploitability, and business impact
Design and implement a scalable patch management framework across AWS, Azure, and hybrid infrastructure including Linux and Windows servers, network devices, and platform services, reducing reliance on manual, one-off remediation efforts
Apply enterprise systems administration expertise (OS hardening, configuration management, service dependencies) to assess patch impact and minimize disruption to production systems
Partner with Cybersecurity to translate vulnerability scan findings and audit action items into clear, actionable remediation plans with committed timelines and owners
Extend vulnerability management support to the application layer, partnering with Business teams and application owners to identify, prioritize, and drive remediation of application vulnerabilities alongside infrastructure remediation efforts
Administer and enhance the organization’s automation platforms, including AWS Systems Manager (SSM) Patch Manager, and integrate them with other automation and orchestration tools to scale vulnerability detection, patching, remediation tracking, and closure verification across AWS, Azure, and hybrid environments
Develop and maintain KPIs and reporting mechanisms (e.g., patch compliance rate, mean time to remediate, aging of open findings, risk trend over time) to measure and communicate progress of security risk remediation efforts to leadership and governance forums
Coordinate remediation activities across Technology Infrastructure, Network Engineering, Cloud Engineering, and Scientific Systems teams to ensure consistent execution and minimal disruption to operations
Continuously identify opportunities to shift from reactive, one-off patching toward standardized, repeatable, and automated remediation processes
Establish and maintain security vulnerability management SOPs, work instructions, and documentation standards for infrastructure security changes to ensure consistent, compliant execution across all systems
Implement, maintain and monitor controls designed to ensure infrastructure security changes (network, cloud, compute, storage, identity, and security configuration) are documented, approved, and traceable end to end
Build and maintain a long-term remediation evidence repository (change records, approvals, exceptions, risk acceptance artifacts, testing/validation artifacts, access reviews) that supports objective evidence for internal and external audits
Partner with Quality/Compliance and Cybersecurity to ensure change management and access control processes meet applicable regulatory requirements (e.g., GxP, SOX, data integrity) and industry frameworks
Lead or support periodic access reviews, control self-assessments, and audit response activities, ensuring evidence is complete, current, and readily retrievable
Identify and close gaps between current operational practices and documented SOPs; drive continuous improvement of change and compliance processes as environments evolve
Serve as a key point of contact during internal and external audits related to security and access controls, coordinating evidence gathering and responses across infrastructure teams
Serve as a senior technical liaison among Cybersecurity, Enterprise Technology Infrastructure, and IT business partners to translate security and compliance requirements into practical technical controls while supporting clear ownership, accountability, and operational execution
Provide technical input on cybersecurity policies and controls, assessing whether requirements are proportionate to business risk, technically sustainable at scale, and balanced against user experience and operational efficiency. Recommend practical, risk-based alternatives where controls introduce unnecessary friction or complexity
Participate in architecture and change advisory reviews to ensure security and compliance requirements are addressed early in design rather than retrofitted after implementation
Support the definition of RACI models and outcome-based security requirements so that policy ownership (Cyber) and implementation ownership (Infrastructure) remain clear
Contribute to the enterprise system security control baseline, including closing or formally risk accepting legacy assessment action items
Mentor and provide guidance to engineers on secure configuration standards, patching best practices, and documentation discipline
Other duties as assigned
Neurocrine Biosciences is an EEO/Disability/Vets employer.
We are committed to building a workplace of belonging, respect, and empowerment , and we recognize there are a variety of ways to meet our requirements. We are looking for the best candidate for the job and encourage you to apply even if your experience or qualifications don’t line up to exactly what we have outlined in the job description.
The annual base salary we reasonably expect to pay is $103,300.00-$141,000.00. Individual pay decisions depend on various factors, such as primary work location, complexity and responsibility of role, job duties/requirements, and relevant experience and skills. In addition, this position offers an annual bonus with a target of 20% of the earned base salary and eligibility to participate in our equity based long term incentive program.