GSK
biopharma
Analyst–CyberDesignAssurance&ProductManagement(DA&PM)
“Analyst – Cyber Design Assurance & Product Management (DA&PM) at GSK. Skills: Cyber Design Assurance, Product Management, Cloud Security, Infrastructure Security, Application Security, Security Engineering, Governance, Zero Trust. Support the integration of secure design principles into product, platform, infrastructure, and cloud environments during planning, design, and implementation phases.. Support security design reviews, technical assessments, control validations, threat modelling activit”
What You'll Achieve.
Help ensure secure-by-design implementation across enterprise technologies.; Support secure delivery, operational alignment, and continuous improvement of cybersecurity controls and practices.; Support delivery of secure and scalable enterprise solutions.
Industry & Context.
analytical, troubleshooting, and problem-solving capabilities.
What They're Looking For.
Must Have
Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field., 2–5 years of experience in cybersecurity, cloud security, infrastructure security, application security, or security engineering functions., Working knowledge of cloud platforms such as Microsoft Azure and Google Cloud Platform (GCP), including security controls, identity and access management, networking, monitoring, and cloud-native security principles., Familiarity with cybersecurity concepts including IAM, network security, endpoint security, application security, vulnerability management, and data protection principles., Understanding of security standards and frameworks (e. g. , NIST CSF, CIS Benchmarks, OWASP, MITRE ATT&CK, Zero Trust)., Experience supporting security assessments, governance activities, engineering functions, or operational security processes.
Nice to Have
Familiarity with DevSecOps practices and integrating security into CI/CD pipelines., Exposure to security technologies across the stack (e. g. , CNAPP, CSPM, SIEM/SOAR, EDR/XDR, PAM/PIM, SAST/DAST, API Security, Data Classification/Labeling)., Basic scripting or automation knowledge (e. g. , PowerShell, Python, Bash) is beneficial., analytical, troubleshooting, and problem-solving capabilities., Good communication and stakeholder collaboration skills., Ability to work in a fast-paced, federated environment supporting secure delivery and operational alignment., Interest in modern cybersecurity practices aligned to Zero Trust, secure-by-design, cloud-native security, and enterprise transformation initiatives.
What You'll Do.
Support the integration of secure design principles into product
and cloud environments during planning
and implementation phases.
Support security design reviews
technical assessments
threat modelling activities
and architecture assurance exercises across enterprise technologies and platforms.
Contribute to governance activities including control assessments
and lifecycle assurance across security and technology platforms.
and reviewing cybersecurity tools across cloud
and data protection domains.
Work with engineering
and cyber defence teams to support secure implementation
and operational alignment.
Support identification of security risks
and exposure scenarios across enterprise systems
Assist in preparing dashboards
and reporting related to security controls
and governance activities.
Help maintain security guidance
reusable assessment templates
design assurance checklists
and secure-by-default implementation standards.
Contribute to initiatives related to Zero Trust
and enterprise security transformation programs.
Collaborate with product owners
and vendors to support delivery of secure and scalable enterprise solutions.
How You'll Work.
Team & Collaboration
Works closely with architecture, engineering, cloud, infrastructure, identity, and product teams.; Collaborate with product owners, architecture teams, engineering teams, operations teams, and vendors.
Communication Scope
Good communication and stakeholder collaboration skills.
Applying for this Analyst – Cyber Design Assurance & Product Management (DA&PM) role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about GSK?
Real rants from real employees. Read before you apply.