- Company Name
- Rhythm Pharmaceuticals Inc.
- Job Title
- Senior Cyber Security Specialist
- Job Description
-
**Job Title:** Senior Cyber Security Specialist
**Role Summary:**
Senior member of the cybersecurity team responsible for governance, compliance, risk and vulnerability management, incident response, threat hunting, and security awareness across the organization. Leverages risk‑based assessments and industry threat intelligence to improve security posture and ensures alignment with regulatory frameworks.
**Expectations:**
- Identify, prioritize, and drive remediation of security risks in systems, data, and third‑party relationships.
- Respond to security incidents promptly, including after‑hours coverage.
- Maintain up‑to‑date documentation, policies, and training programs.
- Collaborate with cross‑functional teams and support security aspects of projects and contracts.
**Key Responsibilities:**
- Execute the vulnerability management program and meet defined SLA targets.
- Act as first responder for security incidents: detection, analysis, containment, eradication, and recovery.
- Conduct threat‑hunting and digital‑forensics investigations.
- Perform third‑party security assessments and validate contractual security requirements.
- Deliver cybersecurity training and awareness for all employees.
- Keep cybersecurity policies, procedures, playbooks, and hardening guides current and accessible.
- Monitor compliance with CIS Controls, NIST CSF, and internal security standards.
**Required Skills:**
- ≥5 years experience in governance/compliance, risk management, vulnerability management, cloud security, and incident response.
- Hands‑on with Microsoft Defender, CrowdStrike, Azure, AWS.
- Strong knowledge of CIS Controls and NIST Cybersecurity Framework.
- Familiarity with NIST, GDPR, ISO, SOC 2 compliance requirements.
- Proven full‑lifecycle incident response capability.
- Project‑management experience in collaborative environments.
- Excellent written and verbal communication skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant certifications such as Security+, GSEC, or comparable are a plus.