Why Endo?
We want the best and brightest people at Endo to help us achieve our mission to develop and deliver life-enhancing products through focused execution. Our nearly 3,000 global team members understand the important role we play in delivering healthcare and are dedicated to supporting each other as we work to bring the best treatments forward. Our shared values of Integrity & Quality, Innovation, Drive, Collaboration and Empathy guide our team and enable us to deliver upon our vision of helping everyone we serve live their best life.
At Endo, we are building a diverse, equitable and inclusive workplace, and we are looking for talented individuals to join our team.
Reporting to Endo’s CIO and as a member of the IT department, the Chief Information Security Officer (CISO) is the Executive Director responsible for shaping and implementing Endo’s cybersecurity vision & strategy. This role manages the enterprise’s information security program, identifies, and evaluates IT and cybersecurity risks, and ensures the protection of information assets and associated technology. They work with executive management to determine the organization’s acceptable risk levels and implement security practices that meet agreed policies and standards.
The CISO communicates the impact of cybersecurity on the business to senior stakeholders and ensures that information systems are secure and compliant with legal, regulatory, and contractual obligations. The CISO is a thought leader who builds consensus between business and technology and coordinates various drivers and constraints while maintaining objectivity. This role involves overseeing the protection of sensitive data, managing risks, ensuring compliance with regulations, and promoting and continuously enhancing a culture of cyber safety & awareness within the company.
Key responsibilities of a CISO include:
Developing, implementing, and monitoring a strategic, comprehensive enterprise information security and IT risk management program.
Working directly with the business leaders & IT business partners to facilitate risk assessment and risk management processes.
Developing and enhancing an information security management framework.
Understands and interacts with related disciplines, either directly or through committees, to consistently apply policies and standards across all technology projects, systems, and services, including privacy, risk management, compliance, and business continuity management.
Works collaboratively with colleagues to continuously enhance Endo’s security profile and respond to new & emerging threats while balancing risks, business operations, and longer-term strategic goals.
Providing leadership to the enterprise’s information security organization.
Partnering with business stakeholders across the company to raise awareness of risk management concerns.
Develop, mentor, and manage a motivated staff of information security professionals, including hiring, training, development, and performance management.
Key Accountabilities - Responsibilities
Strategic Leadership
- Develops an information security vision, strategy & roadmap that is aligned with organizational priorities and enables and facilitates the organization's business objectives.
- Collaborate with the CIO, executive leadership & IT business partners to align security initiatives with business objectives.
- As a member of the IT Leadership team, actively participate and assist in leading the delivery and evolution of IT’s strategy, which includes a portfolio of imperatives focusing on people, processes, and technology.
- Leads the information security function across the company to ensure consistent and high-quality information security management in support of the business goals.
- Provides regular reporting on the status of the information security program to enterprise risk teams, senior business leaders, and the board of directors as part of a strategic enterprise risk management program, thus supporting business outcomes.
- Determines the information security approach and operating model in consultation with stakeholders.
- Drive adoption and optimization of cyber tool sets for a streamlined team member experience – implement appropriate controls while identifying opportunities for automation across the stack.
- Develops, implements, and monitors a strategic, comprehensive information security program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy, and recovery of information assets owned, controlled, or/and processed by the organization.
- Maintain relationships and connectivity with industry peers, relevant threat intelligence sources, and regulatory agencies to collaborate and stay abreast of cyber events or topics.
Risk Management
- Identify, assess, and prioritize information security risks.
- Implement effective risk management strategies and controls to mitigate potential threats.
- Liaises with external agencies, such as law enforcement and other advisory bodies, as necessary to ensure that the organization maintains a strong security posture and is kept well-abreast of the relevant threats identified by these agencies.
- Develops, socializes, and coordinates approval and implementation of security policies.
- Monitors the external threat environment for emerging threats and advises relevant stakeholders on appropriate courses of action.
Security Audits and Assessments
- Conduct routine security assessments and audits to identify vulnerabilities.
- Implement corrective actions to address identified weaknesses.
- Implement target milestones and metrics to measure performance.
Security Framework and Architecture
- Design, implement, and maintain a robust and scalable information security architecture, including policies, tools, and governance.
- Develops and enhances an up-to-date information security management framework based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
- Facilitates a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitates appropriate resource allocation, increases the maturity of the information security, and reviews it with stakeholders at the executive and board levels.
- Ensure that security measures are integrated into all aspects of the IT infrastructure.
Incident Response
- Manages and contains information security incidents and events to protect corporate IT assets, intellectual property, regulated data, and the company's reputation.
- Develop and maintain an incident response plan to address security incidents promptly and efficiently.
- Lead investigations into security breaches and take appropriate corrective actions.
- Coordinates the development and implementation of incident response plans and procedures to ensure that business-critical services are recovered in the event of a security event; provides direction, support, and in-house consulting in these areas.
Compliance and Governance
- Stay abreast of relevant laws, regulations, and industry standards.
- Ensure compliance with applicable security standards and frameworks.
- Collaborates and liaises with the data privacy officer to ensure that data privacy requirements are met.
- Represents Endo in interactions with government agencies, as needed.
Security Awareness and Training
- Foster a culture of security awareness throughout the organization.
- Directs the creation of a targeted information security awareness training program for all employees, contractors, and approved system users and establishes metrics to measure the effectiveness of this security training program for different audiences.
Vendor Management
- Evaluate and manage relationships with third-party security vendors.
- Assess new and recertify existing Endo vendors and ensure that approved Endo vendors adhere to security standards and contractual obligations.
Collaboration and Communication
- Communicate effectively with internal stakeholders, fostering a collaborative and secure environment.
- Build great partnerships with internal stakeholders and clients.
- Creates the necessary internal networks among the information security team and line-of-business executives, corporate compliance, audit, physical security, legal, and HR management teams to ensure alignment as required.
- Builds and nurtures external networks consisting of industry peers, ecosystem partners, vendors, and other relevant parties to address common trends, findings, incidents, and cybersecurity risks.
Qualifications
Education & Experience
- Demonstrated experience and success in senior leadership roles in risk management, information security, and IT or OT security.
- Bachelor’s degree or advanced degree in Information Security, Business Administration, or a technology-related field.
- 10+ years of experience operating in an Information Security Leadership and/or CISO role.
- Experience with developing, socializing, and executing a security roadmap for the business.
- In-depth knowledge of information security principles and best practices.
- Strong understanding of information security, data privacy laws, regulations, and standards.
- Professional security management certification is strongly desired, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or other similar credentials.
- Pharmaceutical industry experience strongly desired.
Knowledge
- Knowledge of regulations, frameworks, and standards, including NIST, ITIL, GDPR, and ISO.
- Expert knowledge and insight into threat vectors, ransomware risks, and data privacy regulations
- Expert knowledge of industry best practice methodologies
- Expert knowledge of available monitoring and threat-detection tools
- Knowledge of physical security, network and systems infrastructure, and security-related tools such as whitelisting, IDS/IPS, anti-malware, patch management, baselining, SIEM, access control, and firewalls.
Skills & Abilities
- Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate information security and risk-related concepts to technical and non-technical audiences at various hierarchical levels, ranging from board members to technical specialists.
- Experienced and skilled at presenting and public speaking (small and large groups); being able to engage and inspire personnel relating to areas of responsibilities.
- Strategic leader and builder of both vision and bridges and able to energize the appropriate teams in the organization.
- Excellent stakeholder management skills
- Analytical thinking and problem-solving skills, with acute attention to detail, accuracy, and accountability balanced with sound business judgment.
- Project management skills
- Experience in financial/budget management
- A master of influencing entities and decisions in situations where no formal reporting structures exist, but achieving the desirable outcome is vital.
- Expertise in technical infrastructure, network architecture, and data movement
- Expertise in IT infrastructure (on-prem and IaaS), cloud technologies, identity management, data protection techniques
- Prior and currently active experience and membership with Security consortiums/groups
- Expertise in system monitoring and threat detection toolsets and techniques
- Excellent listening, analytical, and communication skills
- Exceptional interpersonal skills
- Innovative thinking and leadership with an ability to lead and motivate cross-functional, interdisciplinary teams
Physical Requirements
- Occasional travel to sites
Commitment to Diversity, Equity, and Inclusion:
At Endo, our diversity unites and empowers us as One Team, and we are committed to cultivating, and valuing, each person’s unique perspective. We actively promote a culture of inclusion that draws strength from our broad spectrums of diversity, including race, ethnicity, religion, gender identity or expression, national origin, color, sexual orientation, disability status, age, and all our other unique characteristics, qualifications, demonstrated skills, achievements, and contributions, backgrounds, experiences, cultures, styles, and talents.
EEO Statement:
At Endo we firmly believe in the principles of equal employment opportunity and strive to create an atmosphere where all employees, regardless of their race, color, creed, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability (including pregnancy), age, or military or veteran status, feel valued, respected, and empowered. Our commitment to EEO extends to every aspect of employment, including recruitment, hiring, training, promotions, compensation, benefits, transfers, terminations, and all other employment practices. We are dedicated to ensuring that all employment decisions are based on qualifications, skills, and merit.