2 open positions available
Lead integrated commercial insights and market research to inform strategic decisions in pharma/biotech. | 8+ years in commercial analytics or consulting within pharma/biotech with strong market research and data analysis skills. | About Us Kardigan is a heart health company working to make cardiovascular disease preventable, curable and no longer the leading cause of death in the world. It is Kardigan's mission to develop multiple targeted treatments in parallel that bring people with cardiovascular diseases to the cures they deserve. Led by Tassos Gianakakos, Jay Edelberg, M.D., Ph.D., and Bob McDowell, Ph.D., Kardigan's co-founders have reunited after leading MyoKardia to discover and develop mavacamten, the first cardiac myosin inhibitor, resulting in an acquisition by Bristol Myers Squibb in 2020. We have a cutting-edge discovery and translational research platform, a pipeline of late-stage candidates, and an industry-leading team that is driven to improve the lives of patients. At Kardigan, we are motivated by our values which guide how we work, interact, and achieve our goals. Driven by patients and their families, we are deeply committed to improving the lives of patients and prioritizing their needs above all else. We believe in being authentic-leading with truth to bring out the best in others by creating an environment where every person knows they will be fully accepted. With an eagerness to learn, we encourage the highest levels of curiosity and are open to changing our minds. We are committed to winning as a team with urgency, excellence, and intention, and support each other no matter what role we play or where we sit. Lastly, we strive to enable the impossible because patients are counting on us. We are not afraid to take risks to unlock innovation and advance scientific discoveries. These values are the foundation of our work, empowering us to make a real difference, every day. Position Title: Associate Director, Insights & Analytics Department: Commercial Reports To: Senior Director, Insights & Analytics Location: South San Francisco, CA (preferred) or Princeton, NJ - On-site 4 days per week (Mon to Thurs) Job Overview The Associate Director, Insights & Analytics is responsible for generating integrated commercial insights that inform program strategy, portfolio planning, and product development decisions. This individual will lead primary market research and secondary analytics activities to support strategic and operational decision-making across the organization. Working closely with Commercial, Strategy, Clinical Development, Medical Affairs, Regulatory Affairs, Program Management, and Business Development teams, the Associate Director will synthesize information from diverse data sources, stakeholder research, and market intelligence to identify opportunities, assess risks, and deliver actionable recommendations. The ideal candidate combines strong analytical capabilities, business acumen, and pharmaceutical industry expertise with the ability to communicate complex findings clearly and influence cross-functional decision making. The role reports to the Senior Director, Insights and Analytics who is located in South San Francisco, CA. This is an exciting opportunity to join a high-growth organization and have a direct impact on the future of innovation in the cardiovascular space Essential Duties and Responsibilities • Partner with commercial leadership to identify key business questions, Lead stakeholder engagement to identify business priorities and align market research and analytics initiatives with strategic objectives • Lead the design and execution of qualitative and quantitative primary market research with physicians, patients, caregivers, and payers • Analyze claims, EHR/EMR, specialty pharmacy, epidemiology, and market data • Support the develop of patient-based forecasts and commercial opportunity assessments • Integrate primary research, secondary analytics, and competitive intelligence into cohesive actionable insights • Deliver concise and impactful presentations, facilitate cross-functional alignment around key insights and strategic recommendations • Support lifecycle planning, launch readiness, and portfolio strategy initiatives • Manage external market research and analytics vendors, including study design, execution, quality control, and budget management • Develop and evolve analytics best practices, identify and evaluate data sources, vendor options, and methodologies and technologies to meet business needs Qualifications and Preferred Skills • Bachelor's degree is required; preferably in quantitative, scientific, or business discipline; advanced degree (MBA, MS, PhD) strongly preferred. • 8+ years of progressive experience in commercial analytics, insights, strategy, or consulting within pharma/biotech; prior consulting experience preferred. • Strong experience in designing and conducting both qualitative and quantitative market research with HCPs, patients, and payers, and translating research findings into actionable recommendations • Strong experience conducting and/or evaluating secondary data sources, including claims, EHR/EMR, specialty pharmacy, prescriber-level, and real-world data. • An entrepreneurial and innovative spirit, with an ability to develop creative solutions to complex problems. • Ability to effectively collaborate in and across multiple functions, and with internal and external stakeholders of various backgrounds and skill sets. • Strong verbal and written communication skills, with the ability to convey complex concepts to diverse audiences • Extensive healthcare industry knowledge (i.e., managed care, patient, provider, pharma company, pharma / biotech technology, and disease area trends) • Strong project and process management skills including the ability to manage multiple projects, set priorities and meet deadlines • Strong critical thinking and structured, problem-solving skills • Demonstrated ability to lead cross-functional initiatives and influence stakeholders at multiple organizational levels Exact Compensation may vary based on skills, experience and location. Pay range $174,000-$268,000 USD
Manage and strengthen information security, privacy, and IT compliance programs including risk management and audit coordination. | Bachelor's degree with 7+ years in IT security, risk management, or compliance, including SOX ITGCs, GxP, vendor assessments, and IAM expertise. | About Us Kardigan is a heart health company working to make cardiovascular disease preventable, curable and no longer the leading cause of death in the world. It is Kardigan’s mission to develop multiple targeted treatments in parallel that bring people with cardiovascular diseases to the cures they deserve. Led by Tassos Gianakakos, Jay Edelberg, M.D., Ph.D., and Bob McDowell, Ph.D., Kardigan’s co-founders have reunited after leading MyoKardia to discover and develop mavacamten, the first cardiac myosin inhibitor, resulting in an acquisition by Bristol Myers Squibb in 2020. We have a cutting-edge discovery and translational research platform, a pipeline of late-stage candidates, and an industry-leading team that is driven to improve the lives of patients. At Kardigan, we are motivated by our values which guide how we work, interact, and achieve our goals. Driven by patients and their families, we are deeply committed to improving the lives of patients and prioritizing their needs above all else. We believe in being authentic—leading with truth to bring out the best in others by creating an environment where every person knows they will be fully accepted. With an eagerness to learn, we encourage the highest levels of curiosity and are open to changing our minds. We are committed to winning as a team with urgency, excellence, and intention, and support each other no matter what role we play or where we sit. Lastly, we strive to enable the impossible because patients are counting on us. We are not afraid to take risks to unlock innovation and advance scientific discoveries. These values are the foundation of our work, empowering us to make a real difference, every day. Position Title: Senior Manager, IT Cybersecurity & Compliance Department: Information Technology Reports To: Senior Director, IT Infrastructure Location: South San Francisco, CA (preferred) or Princeton, NJ – On-site 4 days per week (Mon to Thurs) Job Overview We are seeking a Senior Manager, IT Cybersecurity and Compliance to manage and strengthen our information security, privacy, and IT compliance programs. Reporting to the Senior Director, IT Infrastructure, this role manages the day-to-day security risk management process, runs security awareness and training, and helps ensure compliance with applicable regulations and internal policies (including SOX, GDPR, and GxP). The Senior Manager serves as a primary IT point of contact for audits and assessments, maintains IT security policies and standards, oversees vulnerability management and vendor security reviews, and prepares evidence and attestations for IT General Controls (ITGCs) and related governance processes. Key Responsibilities Security governance and program leadership: Help define and execute the IT security and compliance roadmap and operating processes; maintain metrics, reporting, and continuous improvement activities. Security policies and standards: Maintain and obtain approvals for IT security policies, standards, and procedures (e.g., vulnerability management, patching, configuration baselines, identity and access management, encryption, logging/monitoring, secure remote access, incident response, and third-party risk management), and recommend updates as needed. Vendor and third-party security assessments: Conduct security due diligence and ongoing monitoring for vendors (SaaS, cloud, MSPs, consultants, and critical suppliers), including risk tiering, questionnaires, evidence review (e.g., SOC 1/2, ISO 27001), remediation tracking, and security addendum requirements in partnership with Legal and Procurement. Security awareness and training: Run user security training and awareness programs (onboarding, annual training, targeted campaigns, phishing simulations, role-based training), and measure effectiveness through reporting and follow-up actions. SOX compliance (ITGC): Support and maintain IT General Controls in scope for SOX (access controls, change management, computer operations, system development where applicable). Provide timely evidence, coordinate walkthroughs, respond to auditor requests, and execute remediation and management action plans. Privacy and regulatory compliance: Partner with Privacy/Legal to support GDPR and other applicable privacy requirements, including security controls, data protection impact inputs, and vendor processing/security reviews. GxP/regulated environment compliance: Help ensure IT controls and practices support GxP expectations (e.g., validated systems, data integrity/ALCOA+ principles, audit trails, controlled access, change control, backup/restore, and incident handling) in partnership with Quality. Identity, access, and permissions governance: Operate access governance processes (role design, least privilege, segregation of duties, periodic access reviews). Provide ITGC-related attestations for appropriate roles and permissions, including evidence of approvals and review completion. Risk management: Maintain the IT security risk register; perform periodic risk assessments, threat modeling (as appropriate), and control gap analyses; escalate risks and recommendations to leadership. Vulnerability management: Manage the vulnerability management program including scanning, prioritization, remediation SLAs, exception handling, and reporting; partner with Infrastructure, Application owners, and vendors to drive timely remediation. Incident response and investigations: Coordinate IT security incident response activities, including triage, containment, forensics coordination, communications support, and post-incident reviews; maintain tabletop exercises and runbooks. Audit and assessment management: Serve as a primary IT contact for internal/external audits and customer security assessments; coordinate evidence collection across IT teams; ensure findings are documented, tracked, and resolved. Security architecture and project reviews: Review new systems, integrations, and changes for security and compliance requirements; provide secure-by-design guidance for cloud, endpoints, networks, and applications. Data protection: Support data classification, retention/security control alignment, encryption and key management practices (in partnership with platform teams), and secure data handling requirements. Business continuity and disaster recovery: Support IT aspects of BCP/DR planning, testing, and documentation; ensure controls align with audit/regulatory expectations. Collaboration and stakeholder management: Partner with Finance, Quality, Legal/Privacy, HR, Procurement, and business leaders to operationalize controls and meet compliance objectives; communicate security requirements in practical, business-aligned terms. Required Qualifications Bachelor’s degree in Information Security, Information Systems, Computer Science, or equivalent practical experience. 7+ years of progressive experience in IT, information security, risk management, and/or IT compliance, including experience leading projects, programs, or small teams. Demonstrated experience supporting SOX IT General Controls, including evidence collection, walkthroughs, and remediation of findings. Working knowledge of GDPR security requirements and privacy-supporting controls. Experience operating in regulated environments and supporting GxP expectations (e.g., pharma/biotech, medical devices, clinical, manufacturing, or quality-regulated systems). Hands-on experience with third-party/vendor security assessments, including SOC report review and risk-based remediation tracking. Experience designing and delivering security awareness and training programs for end users and administrators. Strong understanding of core security domains: IAM, endpoint security, network security, cloud security, vulnerability management, logging/monitoring, and incident response. Excellent written communication skills, including ability to draft clear policies, standards, and procedures. Preferred Qualifications Relevant certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or similar. Experience with security and compliance frameworks such as NIST CSF, NIST 800-53, ISO 27001, SOC 2, and/or COBIT. Experience with cloud platforms (e.g., AWS, Azure, GCP) and SaaS security controls. Experience with GRC tooling (risk registers, control libraries, evidence management, vendor risk platforms). Experience supporting customer security questionnaires and audits. Experience building and scaling security programs in high-growth organizations. Key Competencies Ability to translate regulatory and security requirements into practical, scalable processes. Strong project/program management and prioritization skills; comfortable operating with ambiguity. Strong communication skills and the ability to present risk, tradeoffs, and remediation plans to leadership and stakeholders. High integrity and sound judgment when handling sensitive information. Collaborative approach with the ability to influence without authority across IT and business stakeholders. Detail-oriented approach to controls, evidence, and documentation while maintaining a risk-based mindset. Exact Compensation may vary based on skills, experience and location. Pay range $164,000—$200,000 USD
Create tailored applications specifically for Kardigan with our AI-powered resume builder
Get Started for Free