Back to jobs
New

US: Associate Director, Cloud Security & Integration Architect

Somerset, New Jersey, United States

Legend Biotech is a global biotechnology company dedicated to treating, and one day curing, life-threatening diseases. Headquartered in Somerset, New Jersey, we are developing advanced cell therapies across a diverse array of technology platforms, including autologous and allogenic chimeric antigen receptor T-cell, T-cell receptor (TCR-T), and natural killer (NK) cell-based immunotherapy. From our three R&D sites around the world, we apply these innovative technologies to pursue the discovery of safe, efficacious and cutting-edge therapeutics for patients worldwide.

 

Legend Biotech entered into a global collaboration agreement with Janssen, one of the pharmaceutical companies of Johnson & Johnson, to jointly develop and commercialize ciltacabtagene autolecuel (cilta-cel). Our strategic partnership is designed to combine the strengths and expertise of both companies to advance the promise of an immunotherapy in the treatment of multiple myeloma.

 

Legend Biotech is seeking an Associate Director, Cloud Security & Integration Architect as part of the IT team based in Somerset, NJ.

Role Overview

This individual will lead cloud security and integration initiatives with system hardening and tooling initiative across the enterprise. Be able to leverage leading-edge technologies, and improve efficiency, support aggressive growth, and improve the organization’s overall security posture. Drive continuous improvement of the cloud security strategy and lead designing and facilitating cloud security specific implementations and workflows enabled by tooling, templates and cloud native services. Will collaborate with cloud platform owners to create security guardrails controls guidance and perform as a subject matter expert on cloud security with expertise and responsibilities to review and assess cloud infrastructure architectures. This person will also lead and own the Identity and access management program and establish process and procedures for Legend globally and contribute to a zero trust strategy. In this role you will develop and maintain security frameworks and architectures, technical standards and guidelines across the security domains of identity, networks infrastructure and endpoints. This role will be leading a Global team will play an advisory role for all entity. The individual will lead and own the Security and Design control and process for all applications on-premise and cloud. Evaluating security tooling, work with the ISO team to understand any gaps in the tooling/environment, assist with researching new tools the business plans to implement. In addition, will provide security architecture guidance for GxP environments to mitigate potential cyber threats and risks. The right candidate must have team oriented approach that balances security needs and user experience to provide best in class security to the organization with subject matter expertise in enterprise security architecture governance and industry standard cybersecurity frameworks, cloud computing and cloud architecture. You will collaborate with various Business units to ensure cybersecurity controls and investments are aligned with the company business and strategic goals. 

Key Responsibilities

Cloud Security Architecture & Strategy

  • Define and maintain cloud security architecture standards for AWS, Azure, and/or GCP.
  • Design and enforce secure landing zones, network segmentation, identity models, and encryption strategies.
  • Lead implementation of Zero Trust, defense-in-depth, and least-privilege access models. 
  •  Align cloud security architecture with enterprise security frameworks (e.g., NIST, ISO 27001, CIS).

Cloud & Hybrid Integration Architecture

  • Architect secure integrations between cloud, on-premises, SaaS, and third-party platforms. 
  • Define patterns for API security, event-driven architectures, middleware, and data integration.
  • Ensure resilience, scalability, and observability of integrated systems.
  • Oversee identity federation and SSO integrations (Azure AD / Entra ID, IAM, SAML, OAuth, OIDC).

Governance, Risk & Compliance 

  • Ensure cloud environments meet regulatory and compliance requirements (e.g., SOC 2, HIPAA, PCI-DSS, SOX, GDPR).
  • Partner with risk, audit, and compliance teams on security assessments and remediation plans.
  • Lead threat modeling and security architecture reviews for cloud initiatives.

Leadership & Stakeholder Engagement 

  • Act as a technical authority and advisor for cloud security and integration decisions.
  • Mentor architects and senior engineers across cloud and security domains. 
  • Collaborate with application, DevOps, and platform teams to drive secure cloud adoption. 
  • Present architecture decisions and risk tradeoffs to senior leadership and executives. 

Operational Excellence

  • Guide selection and implementation of cloud security tooling (CSPM, CWPP, SIEM, CASB, CNAPP).
  • Support incident response and forensic analysis for cloud-related security events.
  • Drive automation of security controls and policy enforcement. 
  • Evaluate emerging cloud and security technologies and recommend adoption strategies.
  • Lead security and system documentation Non GxP and Non-GxP 
  • Lead and provide oversight with Enterprise Cyber Security in mind
  • Lead the Security efforts for modern workplace
  • Lead OT data and system Governance program and operations
  • Oversee Legend’s Global Identity & Access Management (IAM)
  • Oversee User Access Management (UAM), Privilege Access Management (PAM/PIM) Services

Requirements

Education

 A minimum of a Bachelor’s Degree in a relevant discipline, advanced degree is preferred.

Experience 

  • A minimum 15 years in Cybersecurity strategy, architecture and operations (programs and capabilities). 
  • Relevant working experience, 10 years within pharmaceutical, biotech or cybersecurity industries.

 IT Skills

  • Cloud security services (IAM, KMS, WAF, Shield, Defender, GuardDuty, Sentinel, etc.). I
  • Identity and access management, including federation and privileged access management.
  • Network security: VPC/VNet design, firewalls, private connectivity, VPNs, and ExpressRoute/Direct Connect.
  • Infrastructure as Code (Terraform, Bicep, CloudFormation).
  • CI/CD and DevSecOps integration.
  • API security, integration platforms, and messaging systems

 

#Li-LB1

#Li-Hybrid

The base pay range below is what Legend Biotech USA Inc. reasonably expects to offer at the time of posting. Actual compensation may vary based on experience, skills, qualifications, and geographic location. The company reserves the right to modify this range as needed and in accordance with applicable laws.

Other Types of Pay: Performance-based bonus and/or equity is available to employees in eligible roles.

Benefits and Paid Time Off: Medical, dental, and vision insurance as well as a 401(k) retirement plan with a company match that vests fully on day one. We offer eight (8) weeks of paid parental leave after just three (3) months of employment, and a paid time off policy that includes vacation time, personal time, sick time, floating holidays, and eleven (11) company holidays. Additional voluntary benefits include flexible spending and health savings accounts, life and AD&D insurance, short- and long-term disability coverage, legal assistance, and supplemental plans such as pet, critical illness, accident, and hospital indemnity insurance. We also provide voluntary commuter benefits, family planning and care resources, well-being initiatives, and peer-to-peer recognition programs; demonstrating our ongoing commitment to building a culture where our people feel empowered, supported, and inspired to do their best work.

Pay Range (Base Pay):

$168,372 - $220,988 USD

Please note: These benefits are offered exclusively to permanent full-time employees. Contractors are not eligible for benefits through Legend Biotech.

 

EEO Statement

It is the policy of Legend Biotech to provide equal employment opportunities without regard to actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth, related medical conditions and lactation), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, disability, genetic information, or any other protected characteristic under applicable federal, state or local laws or ordinances.

 

Employment is at-will and may be terminated at any time with or without cause or notice by the employee or the company.

 
For information related to our privacy notice, please review: Legend Biotech Privacy Notice.

Create a Job Alert

Interested in building your career at Legend Biotech US? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...
Select...

Please add the link to your LinkedIn profile if applicable. If you do not have a LinkedIn, please write down N/A.

Select...
Select...

I (the candidate) enter into this Non-Disclosure Agreement (the “Agreement”) with Legend Biotech USA Inc. (the “Company”), effective as of the date of my acknowledgement below, for the purpose of enabling the Company to evaluate a possible employment relationship with me.

  1. Access to Company Confidential Information. I acknowledge that for the sole and limited purpose of evaluating a possible employment relationship with me, the Company might disclose, or enable me to have access to, certain Confidential Information of the Company, as defined below.  I agree that, except for purposes of evaluating a possible employment relationship with the Company or as expressly authorized in writing by the Company, I will (a) not use or disclose any Confidential Information; (b) keep all Confidential Information confidential at all times; and (c) not copy, reproduce or modify any Confidential Information.
  2. Definition of “Confidential Information.” For purposes of this Agreement, “Confidential Information” shall mean any and all information and materials provided to me by the Company, including without limitation, inventions, trade secrets, software code, product development and marketing strategies, ideas, processes, formulas, know-how, unpublished financial information, business plans, contractual relationships with third parties and operating strategies; memoranda, notes, records, drawings, manuals, disks, or other documents and media; and all embodiments, copies, extracts, and summaries thereof; provided, however, that “Confidential Information” shall not include information that: (a) is generally known or available to the public, or (b) is furnished to me by a third party who obtained such information using lawful means and without any restrictions on disclosure.
  3. Third Party Information. I agree that during the course of communications with the Company pursuant to this Agreement or in connection with my application and interviews for employment with the Company, I will not make any unauthorized use or disclosure to the Company of any confidential or proprietary information or trade secrets of any other person or entity to whom I have an obligation of confidentiality with respect to such information, including any current or former employer.  I further agree not to provide to the Company any materials or documents of any third party that are not generally available to the public.
  4. Remedies for Breach. I acknowledge that in the event of any breach of this Agreement, the Company will not have an adequate remedy in money or damages, and therefore the Company shall be entitled to obtain temporary, preliminary and/or permanent injunctive relief to redress any such breach, from any court of competent jurisdiction, and that the Company’s right to obtain such relief shall not limit its right to obtain other available remedies.
  5. General. The interpretation and enforcement of this Agreement shall be governed by the laws of the State of California.  This Agreement constitutes the entire agreement between the parties concerning the subject matters hereof; it supersedes any and all prior agreements or representations, written or oral, with respect to its subject matters; and it cannot be modified except in a written agreement signed by the Company.

Select...