Senior Cybersecurity Specialist

Boston, MA
Full Time
IT
Mid Level
Company Overview
Rhythm is a global, commercial-stage biopharmaceutical company committed to transforming the lives of patients and their families living with rare neuroendocrine diseases. We develop medicines for previously untreatable or undertreated diseases and provide meaningful support for healthcare providers and patients and their families. We recognize the courage it takes for patients and their caregivers to begin their journey of advocacy to find the answers they need. Their courage inspires us to challenge convention, ask bold questions and seek answers for them. Every day, we strive for excellence through our willingness to adapt, learn, and our tenacity to overcome barriers, together.

Opportunity Overview
Reporting to the Associate Director, Cybersecurity, Rhythm is seeking an experienced and highly motivated Senior Cybersecurity Specialist to join the Information Technology team. This role will be responsible for supporting cybersecurity initiatives in governance and compliance, risk management, vulnerability management, and incident response. As a senior member of our cybersecurity team, you will leverage risk-based assessments and industry-specific threat intelligence to strengthen Rhythm’s security posture and participate in routine incident response activities. You will also play a pivotal role in enhancing security awareness and education across all business units.

Responsibilities and Duties
  • Identify and escalate cybersecurity risks related to Rhythm’s systems, data, and third-party relationships and drive timely remediation efforts
  • Execute the vulnerability management program, ensuring vulnerabilities are addressed within defined SLAs
  • Serve with others as a first responder during security incidents, performing detailed technical analysis and coordinating response activities
  • Support threat hunting and digital forensics initiatives to uncover threats and assess overall risk exposure
  • Partner with cross-functional teams on projects impacting confidentiality, integrity, or availability of critical assets
  • Review and validate security requirements within third-party contracts, including data protection clauses, breach notification obligations, and compliance with relevant regulations
  • Conduct thorough third-party data security assessments to evaluate controls, risk posture, and alignment with organizational standards
  • Provide and maintain general cybersecurity training and education for all Rhythm employees
  • Maintain clear, accurate, and up-to-date documentation for cybersecurity policies, procedures, and standards. Ensure incident response playbooks, vulnerability management workflows, and system hardening guides are well-documented and easily accessible
  • Monitor adherence to established cybersecurity frameworks and internal policies across all IT operations
     
Qualifications and Skills
  • Minimum 5 years of experience in cybersecurity disciplines such as governance and compliance, risk management, vulnerability management, cloud security, and incident response
  • Hands-on expertise with platforms including Microsoft Defender, CrowdStrike, Azure, and AWS
  • Strong knowledge and application of the CIS Controls and NIST Cybersecurity Framework.
  • Familiarity with regulatory and compliance standards (e.g., NIST, GDPR, ISO, SOC 2).
  • Proven ability to manage the full security incident response lifecycle: detection, analysis, containment, eradication and recovery.
  • Demonstrated success in project management within collaborative environments
  • Excellent communication and interpersonal skills (written and verbal)
  • Relevant certifications (e.g., Security+, GSEC) are a plus

This role requires active participation in security incidents that occur outside normal business hours, including evenings, weekends and holidays.

This role is based out of our corporate office in Boston, Massachusetts. Rhythm operates in a hybrid-work model. Candidates applying must be willing and able to be in the Boston office in coordination with their department and business needs. This role may involve some travel.

The expected salary range for this position is $90,000-$135,000. Actual pay will be determined based on experience, level, qualifications, geographic location, and other job-related factors permitted by law. A discretionary annual bonus may be available based on individual and company performance. This role may be eligible for benefits and other compensation such as restricted stock units.


More about Rhythm
We are a dynamic and growing global team spanning more than a dozen countries. At Rhythm we are dedicated to transforming the lives of patients living with rare neuroendocrine diseases by rapidly advancing care and precision medicines that address the root cause.  Our team is passionate about expanding access to reach more patients and developing novel therapies for other rare neuroendocrine diseases, including congenital hyperinsulinism.


At Rhythm our core values are:
  • We are committed to advancing scientific understanding to improve patients’ lives
  • We are inspired to tackle tough challenges and have the courage to ask bold questions
  • We are eager to learn and adapt
  • We believe collaboration and ownership are foundational for our success
  • We value the unique contribution each individual brings to furthering our mission

Rhythm is an equal employment opportunity employer and does not discriminate against any applicant because of race, creed, color, age, national origin, ancestry, religion, gender, sexual orientation, disability, genetic information, veteran status, military status, application for military service, or any other class protected by state or federal law.

Headquartered in Boston, Rhythm is proud to have been named one of the Top Places to Work in Massachusetts.
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

To comply with government Equal Employment Opportunity and/or Affirmative Action reporting regulations, we are requesting (but NOT requiring) that you enter this personal data. This information will not be used in connection with any employment decisions, and will be used solely as permitted by state and federal law. Your voluntary cooperation would be appreciated. Learn more.

Invitation for Job Applicants to Self-Identify as a U.S. Veteran
  • A “disabled veteran” is one of the following:
    • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
    • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran status



Voluntary Self-Identification of Disability
Voluntary Self-Identification of Disability Form CC-305
OMB Control Number 1250-0005
Expires 04/30/2026
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Please check one of the boxes below:

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

You must enter your name and date
Human Check*