Capricor Therapeutics
Biotech
SecurityAnalyst
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Security Analyst at Capricor Therapeutics. Skills: Cybersecurity operations, Regulatory compliance, SOX ITGC controls, Vulnerability management. Monitor security alerts. Respond to security alerts”
Industry & Context.
Root cause analysis; Troubleshooting
What They're Looking For.
Must Have
3 years cybersecurity experience, 2 years regulated environment experience, 1 year SOX ITGC controls experience, Demonstrated policy development experience
Nice to Have
CrowdStrike Falcon experience, Rapid7 InsightVM experience, 21 CFR Part 11 experience, NIST CSF experience, NIST 800-53 experience, CIS Controls experience, FDA inspection support experience, SOC 2 attestation experience, Basic scripting experience, PowerShell experience, Python experience, Bash experience, IAM platforms experience, Cloud security experience
What You'll Do.
Monitor security alerts
Respond to security alerts
Triage security alerts
Investigate security incidents
Execute incident response procedures
Maintain incident documentation
Administer CrowdStrike Falcon
Manage Abnormal Security
Perform vulnerability assessments
Oversee KnowBe4 training
Coordinate SIEM log analysis
Support SOX ITGC control execution
Perform User Access Reviews
Manage logical access controls
Manage change management controls
Manage logging controls
Prepare SOX documentation
Coordinate control execution
Coordinate control remediation
Draft security policies
Review security policies
Maintain security policies
Ensure policy approval
Support internal audits
Support external audits
Prepare audit evidence
Coordinate remediation activities
Maintain assessor relationships
Conduct vulnerability scans
Prioritize remediation
Coordinate remediation
Track remediation evidence
Administer security training
Deliver targeted training
Conduct phishing campaigns
Analyze phishing results
Track training metrics
Develop security playbooks
Contribute to security metrics
Identify control gaps
Identify detection gaps
Identify governance gaps
Recommend security improvements
Implement security improvements
How You'll Work.
Team & Collaboration
Coordinate with Finance; Coordinate with IT; Coordinate with QA; Coordinate with Compliance
Full Job Description
## Description Capricor Therapeutics (NASDAQ: CAPR) is a biotechnology company dedicated to advancing transformative cell and exosome-based therapies for rare diseases. At the forefront of our innovation is Deramiocel (CAP-1002), our lead cell therapy in late-stage development for Duchenne muscular dystrophy. We are also harnessing our proprietary StealthX™ exosome platform to unlock new possibilities in targeted delivery and vaccinology. Every program reflects our commitment to pushing the boundaries of science and delivering life-changing treatments to patients and families who need them most. We are seeking a detail-oriented Security Analyst to protect our cybersecurity operations within our regulated biotech/pharmaceutical environment. This role combines hands-on security operations with compliance governance, focusing on protecting GMP systems, regulated data, and financially relevant systems in scope for SOX compliance. This is a unique opportunity to work at the intersection of threat operations and regulatory compliance, ensuring adherence to GMP, SOX IT General Controls (ITGCs), and industry security frameworks while actively defending against evolving cyber threats. ## Responsibilities Monitor and Respond to Security Threats Monitor, triage, and respond to security alerts across endpoint, email, and SIEM platforms Investigate security incidents impacting: GMP systems and regulated environments SOX in-scope systems (financial applications, identity systems, etc. Execute incident response procedures aligned with validated and auditable processes Maintain detailed, audit-ready documentation of all incidents and remediation actions Manage Security Technology Stack Administer and implement CrowdStrike Falcon for endpoint detection and response (EDR) Manage Abnormal Security for phishing, business email compromise (BEC), and account takeover threats Perform vulnerability assessments using Rapid7 InsightVM Oversee KnowBe4 security awareness training and phishing
Applying for this Security Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Lever
- Lever uses a streamlined one-page form — apply in under 5 minutes.
- LinkedIn import works well; review parsed data before submitting.
- The cover letter field is optional but visible to reviewers — use it to differentiate.
- Referral codes from employees can significantly boost visibility of your application.
ANONYMOUS · UNFILTERED
What do employees actually say about Capricor Therapeutics?
Real rants from real employees. Read before you apply.