Neurocrine Biosciences
Posted 1d ago

Senior Systems Engineer, IT Infrastructure & Cloud Solutions

Neurocrine Biosciences
San Diego, California, United States
$103k-$141k/yrOnsiteFull Time
Responsibilities
  • remediating vulnerabilities
  • automating patching
  • maintaining SOPs
Requirements
  • Bachelor's degree and 4+ years
  • Master's degree and 2+ years, or 8+ years of relevant experience. Requires Linux/Windows administration
  • Security patching
  • Vulnerability remediation
  • Automation
  • Cloud infrastructure, and compliance experience
Technical tools mentioned
AWSAzureAWS Systems Manager (SSM) Patch ManagerWSUSSCCMIntuneAnsibleSatelliteLandscapePythonBashPowerShellServiceNowCisco Catalyst Center

Job description

Who We Are:

Neurocrine Biosciences is a leading biopharmaceutical company with a simple purpose: to relieve suffering for people with great needs. We are dedicated to discovering, developing and commercializing life-changing treatments for patients with under-addressed neurological, psychiatric, endocrine and immunological disorders. The company's diverse portfolio includes FDA-approved treatments for tardive dyskinesia, chorea associated with Huntington's disease, classic congenital adrenal hyperplasia, hyperphagia in Prader-Willi syndrome, endometriosis* and uterine fibroids*, as well as a robust pipeline including multiple compounds in mid- to late-phase clinical development across our core therapeutic areas. For more than three decades, we have applied our unique insight into neuroscience and the interconnections between brain and body systems to treat complex conditions. We relentlessly pursue medicines to ease the burden of debilitating diseases and disorders, because you deserve brave science. For more information, visit neurocrine.com, and follow the company on LinkedInX, Facebook and YouTube. (*in collaboration with AbbVie)



About the Role:

This is a hands-on, automation-driven senior systems security engineering role responsible for planning, implementing, and driving enterprise technology infrastructure security posture and regulatory compliance readiness across Linux, Windows, cloud, on-prem, and hybrid environments. The engineer serves as a senior technical resource for enterprise infrastructure vulnerability management, overseeing the process from initial alert through remediation and closure verification. The role also develops and improves patch automation using scripting, configuration management, and orchestration, while continuously evaluating tools and processes to adapt to changes in the infrastructure and threat landscape. The engineer applies deep systems engineering and enterprise systems administration expertise to plan and execute security patches, and translates Cybersecurity policy requirements into implemented, auditable controls, establishing KPIs to measure and report progress against security risk remediation goals. The engineer also establishes and maintains Standard Operating Procedures (SOPs) and change management controls to ensure infrastructure security changes are consistently documented and traceable. This provides objective evidence for security and access control audits while maintaining continuous organizational audit readiness. This role serves as a key technical resource and liaison between Cybersecurity, IT business partners, Internal Audit, and Compliance/Quality functions, ensuring that security requirements are operationalized consistently and remediation work is tracked to closure with measurable outcomes.

_

Your Contributions (include, but are not limited to):

Security Automation and Vulnerability Management at Scale

  • Lead complex infrastructure vulnerability remediation efforts and continuously improve the tools and automation used to detect, remediate, and verify security findings across Linux, Windows, cloud, network, and hybrid infrastructure

  • Plan and implement security patches across enterprise Linux and Windows server environments, including patch testing, sequencing, rollback planning, and post patch validation

  • Lead and coordinate the enterprise vulnerability remediation program across cloud (AWS/Azure), on prem, and hybrid infrastructure, prioritizing based on risk severity, exploitability, and business impact

  • Design and implement a scalable patch management framework across AWS, Azure, and hybrid infrastructure including Linux and Windows servers, network devices, and platform services, reducing reliance on manual, one-off remediation efforts

  • Apply enterprise systems administration expertise (OS hardening, configuration management, service dependencies) to assess patch impact and minimize disruption to production systems

  • Partner with Cybersecurity to translate vulnerability scan findings and audit action items into clear, actionable remediation plans with committed timelines and owners

  • Extend vulnerability management support to the application layer, partnering with Business teams and application owners to identify, prioritize, and drive remediation of application vulnerabilities alongside infrastructure remediation efforts

  • Administer and enhance the organization’s automation platforms, including AWS Systems Manager (SSM) Patch Manager, and integrate them with other automation and orchestration tools to scale vulnerability detection, patching, remediation tracking, and closure verification across AWS, Azure, and hybrid environments

  • Develop and maintain KPIs and reporting mechanisms (e.g., patch compliance rate, mean time to remediate, aging of open findings, risk trend over time) to measure and communicate progress of security risk remediation efforts to leadership and governance forums

  • Coordinate remediation activities across Technology Infrastructure, Network Engineering, Cloud Engineering, and Scientific Systems teams to ensure consistent execution and minimal disruption to operations

  • Continuously identify opportunities to shift from reactive, one-off patching toward standardized, repeatable, and automated remediation processes

Change Management, SOPs, and Audit Readiness

  • Establish and maintain security vulnerability management SOPs, work instructions, and documentation standards for infrastructure security changes to ensure consistent, compliant execution across all systems

  • Implement, maintain and monitor controls designed to ensure infrastructure security changes (network, cloud, compute, storage, identity, and security configuration) are documented, approved, and traceable end to end

  • Build and maintain a long-term remediation evidence repository (change records, approvals, exceptions, risk acceptance artifacts, testing/validation artifacts, access reviews) that supports objective evidence for internal and external audits

  • Partner with Quality/Compliance and Cybersecurity to ensure change management and access control processes meet applicable regulatory requirements (e.g., GxP, SOX, data integrity) and industry frameworks

  • Lead or support periodic access reviews, control self-assessments, and audit response activities, ensuring evidence is complete, current, and readily retrievable

  • Identify and close gaps between current operational practices and documented SOPs; drive continuous improvement of change and compliance processes as environments evolve

  • Serve as a key point of contact during internal and external audits related to security and access controls, coordinating evidence gathering and responses across infrastructure teams

Cross-Functional Collaboration and Governance

  • Serve as a senior technical liaison among Cybersecurity, Enterprise Technology Infrastructure, and IT business partners to translate security and compliance requirements into practical technical controls while supporting clear ownership, accountability, and operational execution

  • Provide technical input on cybersecurity policies and controls, assessing whether requirements are proportionate to business risk, technically sustainable at scale, and balanced against user experience and operational efficiency. Recommend practical, risk-based alternatives where controls introduce unnecessary friction or complexity

  • Participate in architecture and change advisory reviews to ensure security and compliance requirements are addressed early in design rather than retrofitted after implementation

  • Support the definition of RACI models and outcome-based security requirements so that policy ownership (Cyber) and implementation ownership (Infrastructure) remain clear

  • Contribute to the enterprise system security control baseline, including closing or formally risk accepting legacy assessment action items

  • Mentor and provide guidance to engineers on secure configuration standards, patching best practices, and documentation discipline

  • Other duties as assigned

Requirements:

  • Bachelor’s degree in computer science, Information Technology, Systems Engineering, or a related technical field and 4+ years of relevant systems engineering or systems administration experience, OR

  • Master's degree in computer science/engineering or a related technical field and 2+ years of experience as listed above, OR

  • 8+ years of a relevant combination of technical education, certifications, training and systems engineering experience

  •  Relevant experience should include enterprise Linux and/or Windows server environments and security patching, vulnerability remediation, automation, or IT compliance. Demonstrated hands-on experience administering and patching enterprise systems and developing automation for patch deployment or remediation (scripting or configuration management tooling) is required

  • Relevant certifications such as CISSP, CISM, CompTIA Security+, RHCE, Microsoft Certified: Windows Server, or ITIL Foundation are preferred but not required

  • Hands-on technical expertise planning and implementing security patches in both Linux and Windows enterprise server environments, including patch testing, staging, deployment sequencing, and rollback procedures

  • Demonstrated experience working as a Systems Engineer or Systems Administrator, with strong working knowledge of enterprise system administration: OS configuration, hardening, service and dependency management, and performance/stability considerations during patch cycles

  •  Strong understanding of the vulnerability management lifecycle: identification, prioritization, remediation, and verification across AWS, Azure, and hybrid infrastructure

  • Working knowledge of application-layer vulnerability management sufficient to partner effectively with Business teams and application owners on remediation prioritization and timelines, complementing infrastructure-focused remediation work

  • Experience with cloud and hybrid patch/automation tooling particularly AWS Systems Manager (SSM) Patch Manager and Azure equivalents alongside Windows (e.g., WSUS, SCCM/Intune) and Linux (e.g., package management, Ansible, Satellite/Landscape or equivalent) tooling and network devices

  • Demonstrated experience administering and continuously improving automation platforms such as AWS Systems Manager (SSM) Patch Manager integrated with other automation and orchestration tools (scripting in Python/Bash/PowerShell, configuration management tools) to scale vulnerability management, patching, and remediation across AWS, Azure, and hybrid server fleets

  • Working knowledge of change management frameworks (ITIL or similar) and experience operating within ITSM platforms such as ServiceNow

  • Familiarity with regulatory and compliance frameworks relevant to a regulated environment (e.g., GxP, SOX, data integrity requirements, 21 CFR Part 11 concepts) and their translation into technical and procedural controls

  • Experience developing SOPs, work instructions, and audit-ready documentation for technology operations

  • Understanding of identity and access management principles, access certification processes, and least privilege concepts

  • Familiarity with cloud and network security tooling (e.g., Cisco Catalyst Center, vulnerability scanners, cloud security posture management tools)

  • Ability to define measurable KPIs and turn remediation data into clear progress reporting for technical and leadership audiences

  • Experience supporting or leading audit response activities, including evidence collection and remediation tracking

  • Strong organizational and documentation discipline, with attention to detail and consistency

  • Strong written communication skills for SOPs, audit evidence, and leadership reporting

  • Ability to work cross functionally across Cybersecurity, Infrastructure, Network, Cloud, and Compliance/Quality teams

  • Analytical and problem-solving skills to prioritize remediation work based on risk and business impact

  • Comfortable operating in a fast paced, growing, regulated environment with evolving priorities

  • Project management skills to track multi team remediation and documentation efforts to closure

#LI-CL1

Neurocrine Biosciences is an EEO/Disability/Vets employer.

We are committed to building a workplace of belonging, respect, and empowerment, and we recognize there are a variety of ways to meet our requirements. We are looking for the best candidate for the job and encourage you to apply even if your experience or qualifications don’t line up to exactly what we have outlined in the job description.

_

The annual base salary we reasonably expect to pay is $103,300.00-$141,000.00. Individual pay decisions depend on various factors, such as primary work location, complexity and responsibility of role, job duties/requirements, and relevant experience and skills. In addition, this position offers an annual bonus with a target of 20% of the earned base salary and eligibility to participate in our equity based long term incentive program. Benefits offered include a retirement savings plan (with company match), paid vacation, holiday and personal days, paid caregiver/parental and medical leave, and health benefits to include medical, prescription drug, dental and vision coverage in accordance with the terms and conditions of the applicable plans.

About Neurocrine Biosciences

Develops treatments for neurological, psychiatric, endocrine, and immunological disorders.

Year founded
1992
Employees
2000
Organization type
Public
Latest investment
Raised $250.00M Post-IPO Equity (2015) — led by J.P. Morgan Securities LLC, Deutsche Bank Securities Inc., Jefferies LLC, Barclays Capital Inc.
Subsidiaries
Headquarters
US

Similar jobs

Systems Engineer roles near San Diego, California
19h
Save
Mark Applied
Hide
System Engineer
San Diego, California, United States
$81k-$142k/yr HybridFull Time
General Atomics Electromagnetic Systems (GA-EMS)
General Atomics Electromagnetic Systems (GA-EMS): Private U.S. defense technology division developing electromagnetic, power, space, and nuclear systems for government and commercial customers.
Bachelor's, master's, or PhD in engineering or related technical discipline, with 4+ years' experience for bachelor's or 2+ for master's. Requires SysML, systems engineering, integration/testing, and ability to obtain Secret or Top Secret clearance.
SysML, Cameo, DOORS, Confluence, Microsoft Teams, JIRA, MagicDraw
1d
Save
Mark Applied
Hide
Senior Systems Engineer, Algorithm Development
Hawthorne or El Segundo or Los Angeles or Washington or San Francisco or San Diego or Seattle or London or United States
$140k-$280k/yr OnsiteFull Time
CHAOS Industries
CHAOS Industries: Redefining modern defense with a multi-product portfolio.
Bachelor’s degree or equivalent experience, deep radar and signal-processing expertise, RF systems engineering experience, algorithm development and data analysis skills, and proficiency with Python or MATLAB.
Python, MATLAB, C++, FPGAs, DSPs
1d
Save
Mark Applied
Hide
Systems Engineer III (RAS)
San Diego, California, United States
$180k-$200k/yr OnsiteFull Time
Precise Systems
Precise Systems: Private U.S. defense contractor providing engineering, digital, lifecycle, and program-support services to government and military customers.
10+ YOEBachelor's degree or equivalent experience, 10+ years of related systems engineering experience, active TS/SCI clearance, U.S. citizenship, architecture and integration expertise, and strong technical communication skills.
Department of Defense Architecture Framework (DoDAF), RMF, ICS, SCADA
1d
Save
Mark Applied
Hide
Senior Systems Engineer IV
Carlsbad, California, United States
$133k-$175k/yr OnsiteFull Time
Frontgrade Technologies
Frontgrade Technologies: Provides mission-critical electronics for space and defense applications.
8+ YOEBachelor’s degree in electrical or systems engineering and 8+ years in aerospace, defense, or high-reliability electronics; equivalent experience may substitute. Requires systems engineering and requirements-management experience.
IBM DOORS, Jama, MIL-STD
2d
Save
Mark Applied
Hide
Staff Systems Engineer - Triton (Rancho Bernardo CA)
San Diego or Rancho Bernardo
$177k-$266k/yr OnsiteFull Time
Northrop Grumman
Northrop GrummanNYSE: NOC: Global aerospace and defense technology.
12+ YOE2+ MgmtBachelor's in STEM plus 12 years, master's plus 10 years, or PhD plus 8 years of relevant experience; 5 years technical execution, 2 years technical leadership, requirements and lab integration experience, and active Secret clearance required.
SIGINT, Comms, Radar, EO/IR, SYS IV 3960
2d
Save
Mark Applied
Hide
Staff Systems Engineer - Triton (Rancho Bernardo CA)
Rancho Bernardo or San Diego
$177k-$266k/yr HybridFull Time
Northrop Grumman
Northrop GrummanNYSE: NOC: Global aerospace and defense technology.
8+ YOE2+ MgmtRequires a STEM bachelor's degree with 12 years, master's with 10 years, or PhD with 8 years of relevant experience; 5 years technical execution, 2 years technical leadership, requirements and lab integration experience, and active Secret clearance.
SYSIII, SYS IV 3960, SIGINT, Comms, Radar, EO/IR, NAVAIR
2d
Save
Mark Applied
Hide
MBSE Systems Engineer
San Diego, California, United States
OnsiteFull Time
SAIC
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
9+ YOERequires a STEM bachelor's with 9+ years, master's with 7+ years, or PhD with 4 years; TS/SCI clearance; MBSE, SysML, UPDM, BPMN, UAF, CAMEO, Team Work Cloud, GitLab, AFSIM, and complex systems modeling experience.
Model-Based Systems Engineering (MBSE), SysML, UPDM, BPMN, UAF, CAMEO Enterprise Architect, Team Work Cloud, GitLab, AFSIM, Scaled Agile Framework Environment (SAFe)
3d
Save
Mark Applied
Hide
Sr. Systems Engineer
San Diego, California, United States
OnsiteFull Time
Innovatus Technology Consulting
Innovatus Technology Consulting: Delivers IT infrastructure and cybersecurity services to federal defense agencies.
10+ YOERequires active U.S. Secret clearance, bachelor's degree or equivalent, 10+ years of systems engineering experience, and 6–7 years focused on Microsoft 365 and Azure; advanced PowerShell and enterprise cloud expertise required.
Microsoft 365, Exchange Online, Microsoft SharePoint Online, Microsoft Teams, Microsoft OneDrive, Microsoft Intune, Microsoft Entra ID, Azure Active Directory, Microsoft Defender for Office 365, Microsoft Azure, Azure Virtual Machines, VNets, NSGs, VPN, ExpressRoute, Azure Storage, Azure Virtual Desktop, Azure Monitor, Log Analytics, Azure AD Connect, Cloud Sync, Microsoft Active Directory, PowerShell, Microsoft Graph, Azure CLI, Bicep, ARM templates, Infrastructure-as-Code, Group Policy, DNS, Terraform, Microsoft Defender, DISA STIGs, FedRAMP, NIST, DoD, CMMC