Back to jobs
New

Incident Response Manager (Contractor)

Company Information

Legend Biotech is a global biotechnology company dedicated to treating, and one day curing, life-threatening diseases. Headquartered in Somerset, New Jersey, we are developing advanced cell therapies across a diverse array of technology platforms, including autologous and allogenic chimeric antigen receptor T-cell and natural killer (NK) cell-based immunotherapy. 

Legend Biotech entered into a global collaboration agreement with Janssen, one of the pharmaceutical companies of Johnson & Johnson, to jointly develop and commercialize ciltacabtagene autolecuel (cilta-cel) in 2017. Our strategic partnership is designed to combine the strengths and expertise of both companies to advance the promise of an immunotherapy in the treatment of multiple myeloma.


Legend Biotech is seeking an Incident Response Manager (Contractor) as part of the IT team based in Somerset, NJ. 

Role Overview

Legend needs to establish a strong effective Cybersecurity function to protect assets within it's organization as the attack surfaces expands. Identify, protect, detect, respond and recover framework needs to be implemented to defend against threat actors. Team will contribute to protecting valuable assets while mitigating potential business damage that is intensifying currently in Cybersecurity threats, vulnerabilities, risks and regulatory requirements compliance globally.             

Key Responsibilities  

  • Point of contact to drive all cyber incidents managed by Cybersecurity Team
  • Logging & Monitoring intelligence sources to maintain situational awareness of the cyber threat landscape
  • Security Incident and Event Monitoring (SIEM)
  • Advance Breach Detection Analytics (End –Point, Network, Internet)
  • Containment, Level 1 Incident Response and end to end investigations
  • Security Operations Management (SOC) management for security incidents
  • Forensics, eDiscovery, DLP
  • Create security incident reports and metrics
  • Building and executing Vulnerability analysis programs
  • Building and executing Threat and Intelligence hunting Programs
  • Identification and validation of security flaws
  • Keep cybersecurity incident status up to date through regular updates
  • Facilitate Pentesting, red teaming blue teaming, tabletop exercises
  • Oversee all aspects of cybersecurity incident management process from evaluation to driving incidents to resolution based on criticality level
  • Coordinate with external parties involved with incident response
  • Document and define improvements over cybersecurity incident playbooks
  • Conduct ad-hoc testing on an as needed basis to assist with development activities or vulnerability remediation
  • Collaborate with all stakeholders as required for incident response

Requirements

  • A minimum of a Bachelor’s Degree in a relevant discipline, advanced degree is preferred.
  • A minimum 8 years relevant working experience, 5 years within pharmaceutical, biotech or cybersecurity regulated industries.  
  • Familiar with risk management and controls frameworks, cyber kill chain and NIST incident response life cycle
  • Understanding of Security Governance, Risk & Compliance
  • Strong DLP tools knowledge
  • 5+ years of experience with cybersecurity related activities
  • Experienced in dealing with cyber incidents
  • Proven experience in security operations and monitoring
  • Working knowledge about SIEM architecture
  • Hands on experience with Exabeam, LogRhythm, Splunk, Elastic Stack, or industry equivalent at a user level
    • Being able to work with a diverse set of stakeholders in the organization from technical through executive management. Strong report writing and communication skills.
  • Strong written and verbal communication in English
  • Understanding crisis management, business continuity and disaster recovery procedures
  • Ability to understand technical topics dealing with technical teams and explain and present them to management level executives
  • Being able to handle multiple completing priorities in a fast-paced environment to proceed high priority tasks to a resolution
  • Familiarity with related publications such as: NIST 800-61(Incident Handling), NIST 800-30(Risk Assessment), NIST 800-52(Security Controls)
  • Specialized experience with Blue Teaming or experience working with a Security Operations Center performing a variety of services listed above in responsibilities.
  • Relevant Certifications CGIH, CISM, CISSP

#Contractor

#Li-BZ1


Legend Biotech is a proud equal opportunity/affirmative action employer committed to attracting, retaining, and maximizing the performance of a diverse and inclusive workforce. It is Legend’s policy to ensure equal employment opportunity without discrimination or harassment based on race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, national origin, marital or domestic/civil partnership status, genetic information, citizenship status, uniformed service member or veteran status, or any other characteristic protected by law.

Legend Biotech maintains a drug-free workplace.

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Legend Biotech US’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.