Capricor Therapeutics

Biotech

SecurityAnalyst

$120–140k San Diego, California, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid+ candidates.

The Brief

“Security Analyst at Capricor Therapeutics. Skills: Cybersecurity operations, Regulatory compliance, SOX ITGC controls, Vulnerability management. Monitor security alerts. Respond to security alerts”

Industry & Context.

Biotech
Problems you'll solve

Root cause analysis; Troubleshooting

What They're Looking For.

Must Have

3 years cybersecurity experience, 2 years regulated environment experience, 1 year SOX ITGC controls experience, Demonstrated policy development experience

Nice to Have

CrowdStrike Falcon experience, Rapid7 InsightVM experience, 21 CFR Part 11 experience, NIST CSF experience, NIST 800-53 experience, CIS Controls experience, FDA inspection support experience, SOC 2 attestation experience, Basic scripting experience, PowerShell experience, Python experience, Bash experience, IAM platforms experience, Cloud security experience

What You'll Do.

Monitor security alerts

Respond to security alerts

Triage security alerts

Investigate security incidents

Execute incident response procedures

Maintain incident documentation

Administer CrowdStrike Falcon

Manage Abnormal Security

Perform vulnerability assessments

Oversee KnowBe4 training

Coordinate SIEM log analysis

Support SOX ITGC control execution

Perform User Access Reviews

Manage logical access controls

Manage change management controls

Manage logging controls

Prepare SOX documentation

Coordinate control execution

Coordinate control remediation

Draft security policies

Review security policies

Maintain security policies

Ensure policy approval

Support internal audits

Support external audits

Prepare audit evidence

Coordinate remediation activities

Maintain assessor relationships

Conduct vulnerability scans

Prioritize remediation

Coordinate remediation

Track remediation evidence

Administer security training

Deliver targeted training

Conduct phishing campaigns

Analyze phishing results

Track training metrics

Develop security playbooks

Contribute to security metrics

Identify control gaps

Identify detection gaps

Identify governance gaps

Recommend security improvements

Implement security improvements

How You'll Work.

Team & Collaboration

Coordinate with Finance; Coordinate with IT; Coordinate with QA; Coordinate with Compliance

Full Job Description

## Description Capricor Therapeutics (NASDAQ: CAPR) is a biotechnology company dedicated to advancing transformative cell and exosome-based therapies for rare diseases. At the forefront of our innovation is Deramiocel (CAP-1002), our lead cell therapy in late-stage development for Duchenne muscular dystrophy. We are also harnessing our proprietary StealthX™ exosome platform to unlock new possibilities in targeted delivery and vaccinology. Every program reflects our commitment to pushing the boundaries of science and delivering life-changing treatments to patients and families who need them most. We are seeking a detail-oriented Security Analyst to protect our cybersecurity operations within our regulated biotech/pharmaceutical environment. This role combines hands-on security operations with compliance governance, focusing on protecting GMP systems, regulated data, and financially relevant systems in scope for SOX compliance. This is a unique opportunity to work at the intersection of threat operations and regulatory compliance, ensuring adherence to GMP, SOX IT General Controls (ITGCs), and industry security frameworks while actively defending against evolving cyber threats. ## Responsibilities Monitor and Respond to Security Threats Monitor, triage, and respond to security alerts across endpoint, email, and SIEM platforms Investigate security incidents impacting: GMP systems and regulated environments SOX in-scope systems (financial applications, identity systems, etc. Execute incident response procedures aligned with validated and auditable processes Maintain detailed, audit-ready documentation of all incidents and remediation actions Manage Security Technology Stack Administer and implement CrowdStrike Falcon for endpoint detection and response (EDR) Manage Abnormal Security for phishing, business email compromise (BEC), and account takeover threats Perform vulnerability assessments using Rapid7 InsightVM Oversee KnowBe4 security awareness training and phishing

Free ATS check

Applying for this Security Analyst role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Lever

  • Lever uses a streamlined one-page form — apply in under 5 minutes.
  • LinkedIn import works well; review parsed data before submitting.
  • The cover letter field is optional but visible to reviewers — use it to differentiate.
  • Referral codes from employees can significantly boost visibility of your application.

ANONYMOUS · UNFILTERED

What do employees actually say about Capricor Therapeutics?

Real rants from real employees. Read before you apply.

Read Company Rants →