Eli Lilly and Company

Threat Mitigation Lead - Secure Software Development

United States

Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Pharmaceuticals, Healthcare, Information SecurityIndustries

About Lilly

At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We’re looking for people who are determined to make life better for people around the world.

Role Overview

We are looking for an experienced Cyber Threat Mitigation Lead with a focus on secure software development. This role is designed for someone who excels at working with cross-functional teams to drive down security risks and threats in applications and software. This lead will partner closely with cyber leadership to understand risk and prioritize efforts. The candidate will address challenging complex issues; therefore, creative problem-solving is essential.

As the Threat Mitigation Lead, you will be responsible for working with internal cyber teams, software engineers and developers, and other stakeholders to reduce the impact of identified threats. You will drive the implementation of mitigation strategies throughout the software development process and promote lessons learned that will enhance secure coding practices.

What You Will Do

Threat Mitigation

  • Partner with AppSec and cyber leadership to prioritize identified security threats.
  • Lead efforts to assess, track, and mitigate risks through engagement with software development teams.
  • Guide teams to address security vulnerabilities by integrating solutions into development and operational workflows.
  • Aid in developing solutions that bring risks within acceptable levels.
  • Provide guidance and raise awareness on mitigation activities that require monitoring to account for changing threat landscapes and residual risk.
  • Balance security and business objectives with a bias towards timely remediation.

‘Stay Secure’ Software Development Practices (SSDLC)

  • Partner with AppSec to promote the integration of secure coding practices throughout the SDLC to avoid repeated risk events.

Strategy Execution

  • Act as a key player in the creation and execution of threat mitigation strategies for vulnerabilities identified in ongoing development and within existing applications.
  • Ensure identified vulnerabilities are effectively tracked and managed through their lifecycle, from detection to remediation.
  • Develop and refine strategies that help teams respond to evolving threats, reducing their risk to production systems.

Leadership and Cross-functional Collaboration

  • Mentor cross-functional teams, ensuring that developers, security engineers, and architects are aligned in driving down cyber threats.
  • Facilitate collaboration between product, engineering, and security teams to align on mitigation strategies and best practices.
  • Assist the Cyber AppSec team through providing guidance to engineering teams on security best practices, focusing on practical implementation that enhances both security and development efficiency.

Continuous Improvement

  • Work with leadership and development teams to continuously improve threat mitigation and security integration processes.
  • Proactively recommend improvements in software development security practices and collaborate with teams to implement them.
  • Encourage and maintain a security-aware culture among development teams to make security an inherent part of their workflows.

Metrics and Reporting

  • Provide regular updates to cyber leadership on progress made toward reducing security risks and the overall security posture of software development efforts.
  • Ensure visibility into ongoing efforts to mitigate threats, escalating key issues as needed.

Basic Qualifications

  • Bachelor's or master’s degree in computer science, Information Security, or a related field, or equivalent practical experience.

Skills

Cyber Threat Mitigation
Secure Software Development
Risk Assessment
Vulnerability Management
Security Strategies
Cross-functional Collaboration
Secure Coding Practices
Threat Landscape Monitoring

Eli Lilly and Company

Develops and delivers prescription medicines globally

About Eli Lilly and Company

Eli Lilly and Company is a global pharmaceutical company that focuses on discovering, developing, and delivering medicines to improve health. The company has a long history of scientific achievements, including the creation of insulin, the first life-saving treatment for diabetes. Lilly's operations involve extensive research and development to create new medications and enhance existing ones, ensuring they are safe and effective. Their products are primarily prescription medicines sold to healthcare providers for various medical conditions, including diabetes, cancer, and pain management. What sets Lilly apart from its competitors is its strong commitment to ethical practices and the protection of its products from counterfeiting. The company's goal is to enhance lives through innovative medical solutions while maintaining high standards of quality and ethics.

Indianapolis, IndianaHeadquarters
1876Year Founded
$1,180.1MTotal Funding
IPOCompany Stage
Biotechnology, HealthcareIndustries
10,001+Employees

Risks

Competition from Novo Nordisk's Ozempic may impact tirzepatide's market share.
Potential construction delays in Indiana could affect GLP-1 drug production timelines.
Regulatory challenges may hinder Kisunla's expansion in new Alzheimer's markets.

Differentiation

Eli Lilly's rich history includes the first life-saving insulin treatment.
Lilly's strategic partnerships enhance its position in neurodegenerative disease treatments.
FDA approval of Zepbound opens new therapeutic markets for sleep disorder treatments.

Upsides

Lilly's $9 billion complex in Indiana boosts GLP-1 drug production capacity.
Kisunla's approval in China expands Lilly's Alzheimer's treatment market in Asia.
Collaboration with EVA Pharma enhances Lilly's reputation as socially responsible.

Land your dream remote job 3x faster with AI