Cybersecurity Manager

Discovery Life SciencesHuntsville, AL
$90,000 - $130,000Onsite

About The Position

Discovery Life Sciences (Discovery) is a leading provider of highly characterized human biospecimens and cellular starting materials to advance cell and gene therapy and precision medicine programs for cancer, infectious disease, and other complex conditions. We routinely manage hundreds of studies and expertly test thousands of biospecimens simultaneously. Leading biopharma, diagnostic and academic institutions trust us to quickly deliver high-quality biospecimens and reliable, reproducible biomarker data, so they can outpace their competition and push the leading edge of innovation using our Science at your Service TM business model. Position Summary: Discovery Life Sciences is seeking an experienced Cybersecurity Manager to join our Information Technology team as a hands-on individual contributor responsible for protecting the company's people, data, systems, and regulated operations. This role combines cybersecurity operations with governance, risk, and compliance (GRC) responsibilities, requiring both strategic thinking and technical execution. The Cybersecurity Manager will play a key role in maintaining and enhancing the organization's security posture by leading incident response, vulnerability management, audit readiness, risk management, and compliance initiatives across global operations. This position serves as a trusted security partner to stakeholders across IT, Quality, Legal, Privacy, HR, Finance, and business functions, while helping scale a mature cybersecurity program that supports Discovery's continued growth.

Requirements

  • Must live near or be willing to relocate to Huntsville, AL
  • Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field; equivalent practical experience will also be considered.
  • CISSP, CISA, CRISC, Security+, or a comparable cybersecurity certification preferred.
  • Certifications are valued but are not a substitute for demonstrated hands-on experience.
  • Five (5)+ years of progressive experience in cybersecurity, security operations, IT risk management, IT audit, or a comparable hands-on role.
  • Demonstrated expertise in either Security Operations or Governance, Risk, and Compliance (GRC), with practical experience across both disciplines.
  • Experience in life sciences, healthcare, biotechnology, financial services, or another regulated industry required
  • Hands-on experience with several of the following: Microsoft Sentinel, Microsoft Defender, Microsoft Intune, Microsoft Purview, Tenable, firewalls, endpoint security, cloud security, identity and access management, KQL, or PowerShell.
  • Practical experience investigating and responding to security incidents, coordinating remediation, and exercising sound judgment under pressure.
  • Experience supporting or operating security controls aligned to SOC 2, ISO 27001, NIST, or similar frameworks; able to produce clear, defensible audit evidence.
  • Experience with vulnerability management, third-party risk, policy and exception management, and risk tracking.
  • Familiarity with 21 CFR Part 11, GxP, GDPR, data privacy, customer security reviews, or regulated validation practices.
  • Experience with Microsoft Purview, DLP, data classification, DSPM, eDiscovery, Azure, AWS, or Microsoft 365 security capabilities.
  • Demonstrated ability to automate repeatable security and compliance tasks through scripting or workflow tools.
  • Strong written and verbal communication skills, with the ability to explain technical risk and recommended action to executive, audit, and non-technical audiences.

Nice To Haves

  • CISSP, CISA, CRISC, Security+, or a comparable cybersecurity certification preferred.

Responsibilities

  • Monitor and investigate security alerts, coordinate incident response activities, and lead remediation efforts to minimize business risk.
  • Partner with internal teams and external auditors to maintain compliance with SOC 2 Type II, ISO 27001, NIST, and regulatory requirements.
  • Review vulnerability and penetration testing results, prioritize remediation activities, and track progress through resolution.
  • Collaborate with Infrastructure, Cloud, Applications, Legal, Privacy, Quality, and business leaders to address emerging risks and strengthen security practices.
  • Monitor, triage, investigate, and respond to security alerts and incidents, lead containment, recovery coordination, and post-incident reporting.
  • Administer and tune security controls across firewalls, network security technologies, endpoint compliance, patching, encryption, and security baselines.
  • Own or coordinate joiner, mover, and leaver controls, including timely access provisioning, deprovisioning, privileged access review, and periodic access certifications.
  • Maintain security operations runbooks, escalation paths, incident procedures, and metrics; participate in periodic after-hours response as required by the incident and team coverage model.
  • Operate the security compliance cadence for SOC 2 Type II, ISO 27001, and the NIST Cybersecurity Framework, including control mapping, audit planning, evidence collection, issue tracking, and auditor coordination.
  • Partner with Quality / Validation, Legal, Privacy, and business stakeholders on 21 CFR Part 11, GxP, GDPR, and customer security requirements; provide security controls and evidence within each function's accountability.
  • Run the third-party and vendor risk lifecycle: security due diligence, assessments, risk ratings, ongoing monitoring, remediation follow-up, and documented risk acceptance.
  • Maintain the enterprise security risk register and coordinate risk assessments, accountable owners, due dates, compensating controls, and escalation of overdue or material risks.
  • Maintain the security policy, standard, exception, and attestation lifecycle; communicate changes and support adoption across the organization.
  • Partner with Operations, Legal, and IT on data classification, Data Loss Prevention / data security controls, security investigations, and eDiscovery support where appropriate.
  • Run the vulnerability management lifecycle, including prioritization based on exploitability, asset criticality, exposure, and business impact.
  • Coordinate internal and third-party penetration tests, track findings, validate remediation, and report residual risk to accountable owners and leadership.
  • Use automation, KQL, PowerShell, and available platform capabilities to improve detection, evidence collection, reporting, and control consistency.
  • Serve as a trusted leader for operational continuity, risk discussions, incident coordination, and selected leadership meetings.
  • Mentor and help develop the Cybersecurity Analyst; provide direction to project teams, manage service providers, and control owners without requiring direct reporting lines.
  • Build productive working relationships with Infrastructure, Cloud, Applications, HR, Legal, Quality, Privacy, Finance, and business leaders.
  • Prepare concise security metrics, risk summaries, audit updates, and recommendations for executive stakeholders.
  • Other duties as assigned by supervisor. These may, on occasion, be unrelated to the position described here.
  • Consistent and predictable attendance is an essential function of the position.

Benefits

  • Competitive salary and benefits package options, including a free dental, vision package, life insurance, and disability coverage which start on your first day of employment.
  • 401(k) match program which starts on your first day of employment.
  • Time away from work (Generous vacation and paid time off, paid parental leave, paid family leave, etc.).
  • Professional development opportunities and reimbursement for relevant certifications and tuition.
  • Collaborative and inclusive work environment that values diversity.
  • Team-building activities and social events.
  • Employee Referral Program and Colleague Recognition Program.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service