SIGN IN
Director or Sr. Director, Information Security jobs in United States
cer-icon
Apply on Employer Site
company-logo

Kymera Therapeutics · 7 hours ago

Director or Sr. Director, Information Security

Kymera Therapeutics is a clinical-stage biotechnology company pioneering targeted protein degradation to develop innovative therapies. The Director/Sr. Director of Information Security will lead the enterprise information security program, combining strategic leadership with hands-on security engineering to protect the company's intellectual property and data while enabling secure scientific productivity.
BiotechnologyHealth CareMedicalTherapeutics
check
Growth Opportunities
check
H1B Sponsor Likelynote

Responsibilities

Own and evolve Kymera’s information security strategy, policies, and roadmap across hybrid on-prem and cloud environments
Serve as the technical authority for security architecture and engineering decisions, guiding how controls are designed, implemented, and integrated across the environment
Lead security operations in partnership with an external SOC, including hands-on involvement in incident response, investigation, and post-incident improvements across hybrid systems
Be accountable for firewall and network security architecture, including segmentation, secure connectivity, and rule governance supporting on-prem systems and cloud workloads, in partnership with a managed service provider
Design, implement, and operate core security controls across identity, endpoints, networks, and cloud platforms, while ensuring operational sustainability
Partner with IT and business stakeholders to embed security engineering into solution design and delivery, enabling R&D productivity without compromising security
Lead enterprise security risk assessments and third-party risk management across on-prem, cloud, and SaaS environments
Partner with Legal, Compliance, Finance, and Quality teams to support audits, assessments, and security reviews
Act as a trusted security advisor to senior leadership and provide clear, risk-based cybersecurity reporting with visibility to the Audit Committee of the Board of Directors

Qualification

Information Security StrategySecurity EngineeringHybrid Environment SecurityIncident ResponseSecurity GovernanceRisk ManagementNetwork SecurityCloud SecurityIAM ImplementationCommunication SkillsCollaborationAdaptability

Required

10+ years of progressive experience in information security, including ownership of an enterprise security program in a hybrid on-prem and cloud environment
Extensive hands-on experience in security engineering, including designing, implementing, and operating security controls across identity, network, endpoint, and cloud domains
Demonstrated experience securing hybrid architectures, not just selecting tools or managing vendors
Experience leading security governance, risk management, and operational security while remaining deeply engaged in technical decision-making
Proven experience partnering with a managed SOC or MDR provider, including hands-on involvement in incident response across hybrid systems
Strong understanding of security operations, monitoring, and response across on-prem systems, cloud environments, and SaaS services
Deep working knowledge of network security fundamentals, including firewalls, segmentation, and secure remote access, particularly in MSP-supported environments
Experience implementing and operating controls such as IAM, endpoint protection, vulnerability management, logging/monitoring, and cloud security tooling
Ability to communicate security risk and architectural decisions clearly to technical and non-technical audiences, including executive leadership
Familiarity with security frameworks such as NIST CSF, CIS Controls, or ISO 27001, and practical approaches to applying them

Preferred

Experience in biotech, pharmaceutical, life sciences, healthcare, or other IP- and data-sensitive environments
Direct responsibility for securing cloud platforms (e.g., AWS, Azure, or GCP) integrated with on-prem infrastructure
Experience supporting regulated or compliance-driven environments (e.g., GxP-adjacent systems, SOC 2, SOX IT controls, ISO 27001)
Experience designing and operating modern identity architectures (SSO, MFA, conditional access) in hybrid environments
Prior experience presenting cybersecurity risk, incidents, or security architecture decisions to executive leadership or board-level audiences
Relevant certifications such as CISSP, CISM, or GIAC (preferred but not required)

Benefits

Eligibility for annual bonus
Equity participation
Comprehensive benefits

Company

Kymera Therapeutics

twittertwittertwitter
company-logo
Kymera Therapeutics is a biotechnology company that specializes in the field of targeted protein degradation.

H1B Sponsorship

Kymera Therapeutics has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (5)
2024 (2)
2023 (4)
2022 (3)
2021 (3)

Funding

Current Stage
Public Company
Total Funding
$1.96B
Key Investors
Biotechnology Value FundBiotechnology Value Fund,Redmile Group6 Dimensions Capital,Bessemer Venture Partners,Pfizer Venture Investments
2025-12-10Post Ipo Equity· $602M
2025-06-26Post Ipo Equity· $250.8M
2024-08-19Post Ipo Equity· $225M

Leadership Team

leader-logo
Nello Mainolfi
Founder, President and Chief Executive Officer
linkedin
leader-logo
Jeremy Chadwick
Chief Operating Officer
linkedin
Company data provided by crunchbase