Rose BioSolutions offers career opportunities at the forefront of advanced therapy manufacturing. Join a world-class team shaping innovative, scalable solutions that support programs from early development through commercial launch.

About Rose BioSolutions
With decades of expertise, including plasmid DNA manufacturing since 1992, we provide seamless program continuity from early research through commercial supply across the US and EU, eliminating handoffs that delay progress.
At Rose BioSolutions, innovation, infrastructure, and expertise come together to accelerate advanced therapies from concept to commercialization.

The role · Open position
At Rose BioSolutions, our capabilities span foundational research with human immune cells and stem cells to the complete advanced therapy manufacturing continuum. We are an established operation with a world-class team of experts, and we apply our R.O.S.E standard to every program and relationship: Reliable, Outcome driven, Scalable, and Excellent!
This role directly owns cybersecurity for the infrastructure organization, in addition to core infrastructure architecture and operations. As a newly independent company standing up its own IT function post carve-out, we do not yet have an MSP in place: this role will lead the evaluation, selection, and onboarding of our managed services partner(s), which may include a combined MSP/MSSP model or separate providers, then own ongoing SLA management and performance oversight.
This is a hands-on leadership role. The successful candidate will balance strategic architecture and security ownership with direct oversight of vendor selection, vendor delivery, incident response, and infrastructure roadmap execution in a fast-moving, newly standalone life sciences company. We are specifically looking for someone with prior carve-out or divestiture experience: someone who has designed and built a future-state IT infrastructure environment from a legacy or transitional foundation, not just operated within an already-established one. This person will also need to be comfortable leading a lean team while simultaneously running a major vendor selection process, and communicating infrastructure and security posture clearly to the CIO and executive leadership, including in a private equity-backed governance context.
Reports to: CIO
Direct reports: 2–5, including on-site support resources across Rose Bio's four locations (Rockville, MD; Memphis, TN; Northridge, CA; Keele, UK)
Travel: Regular travel expected across Rose Bio's four sites in the US and UK; frequency to be defined based on carve-out and MSP/MSSP transition milestones
Lead the RFP, evaluation, and selection process for Rose Bio's first managed service provider(s), evaluating whether a combined MSP/MSSP model or separate specialized providers best fits the security and operational needs, defining scope, SLAs, and success metrics from the ground up
Own the MSP (and MSSP, if part of the same or a related contract) relationship end to end post-selection: onboarding, ticket escalations, quarterly business reviews, and ongoing contract and performance management against defined KPIs
Hold the MSP accountable for network, server, storage, help desk, and monitoring service delivery, and the MSSP (whether the same vendor or separate) accountable for security monitoring and response service levels
Clarify and manage the model for on-site support resources at each of the four locations, whether Rose Bio employees, MSP-provided resources, or a mix, as part of the vendor selection and org design process
Manage additional infrastructure vendors as needed
Own cybersecurity strategy, policy, standards, and risk posture for Rose Bio, whether execution is performed in-house or by an MSSP
Architect the security program and determine what is executed internally versus by an MSSP, similar to the MSP model: the Director owns the design and outcomes, the vendor executes against defined scope and SLAs
If an MSSP is engaged (standalone or combined with the MSP), own that relationship end to end: scope, SLAs, quarterly performance reviews, and accountability for security monitoring and response service levels
Own incident response decision-making and post-incident review, including working knowledge of SIEM tooling and alerting, even where an MSSP performs detection and triage
Own perimeter security posture, including firewall architecture and configuration, in coordination with the network team and any MSP/MSSP partner
Own identity and access governance, including provisioning, deprovisioning, periodic access reviews, and least-privilege standards
Own data privacy considerations across jurisdictions, including GDPR exposure at the Keele, UK site alongside applicable US requirements
Coordinate with OT security partners to ensure appropriate segmentation and monitoring of manufacturing-adjacent systems
Accountable to the CIO for the organization's overall security posture, regardless of which team or vendor performs day to day execution
Own the overall infrastructure architecture strategy across network, server, storage, virtualization, and cloud, ensuring designs support scalability, security, and resilience
Set architectural standards and roadmap for a newly standalone company building its technology environment largely from scratch post carve-out
Make build vs. buy and on-prem vs. cloud architecture decisions in partnership with IT and business leadership
Ensure infrastructure design supports uptime, data integrity, and validation requirements typical of a GxP environment
Own lifecycle management for network infrastructure (LAN/WAN, firewalls, segmentation), server environments, and storage systems across all sites
Bring hands-on knowledge of firewall architecture, rule management, and perimeter design to guide both internal decisions and vendor oversight
Cloud and SaaS
Lead infrastructure strategy across Azure and/or AWS, including cost management, security posture, and architecture decisions
Oversee governance of the SaaS portfolio, including Office 365 and other business-critical SaaS platforms
Manage Active Directory (or Azure AD/Entra ID) and identity infrastructure
Ensure a reliable, well-supported end user computing environment across corporate and site locations
Oversee help desk performance delivered through the MSP, including SLA adherence and end user satisfaction
Virtualization and Data Center
Own virtualization strategy and platform management (e.g., VMware, Hyper-V)
Manage any remaining on prem data center footprint and its transition roadmap, where applicable
Ensure comprehensive monitoring coverage across infrastructure, with defined alerting and escalation paths
Own disaster recovery and business continuity planning for infrastructure systems, including defined recovery time objectives (RTO) and recovery point objectives (RPO), regular testing, and documentation
Own backup strategy and validation to ensure recoverability meets defined objectives
Maintain infrastructure documentation and runbooks to support audit readiness
Own or oversee change management and ITSM processes, including ticketing, change control, and configuration management (CMDB), whether managed in-house or through the MSP
Understand and support the intersection of IT and OT within a CDMO manufacturing environment, including networked lab and manufacturing systems
Coordinate with OT facility partners to ensure appropriate segmentation and monitoring of manufacturing-adjacent systems
Understand computer system validation (CSV) and 21 CFR Part 11 considerations as they relate to infrastructure supporting GxP systems, partnering with Quality on validation-specific requirements
Support any SOC 2 or similar compliance framework work needed to meet client attestation requirements
Evaluate and pilot AI tools and use cases that improve infrastructure operations, monitoring, and help desk efficiency
Stay current on AI-driven infrastructure and security tooling relevant to the environment
10+ years of progressive infrastructure leadership experience, including experience selecting and managing MSPs (not just inheriting an existing relationship)
Experience in a life sciences, CDMO, pharma, or other regulated manufacturing environment strongly preferred
Demonstrated expertise in infrastructure architecture across network, server, storage, virtualization, and cloud (Azure and/or AWS)
Strong working knowledge of Office 365, Active Directory/Entra ID, and enterprise SaaS management
Direct ownership experience of a cybersecurity program, including endpoint, identity, and vulnerability management, not just partnership with a separate security function
Hands on experience with incident management and SIEM tooling, and strong knowledge of perimeter security and firewall architecture
Experience with disaster recovery and backup planning, including defining and meeting RTO/RPO targets
Experience owning IT service management processes (change management, ticketing, CMDB)
Prior experience in a carve-out, divestiture, or newly independent company, with a track record of designing and building future-state infrastructure rather than only maintaining an existing environment
Experience managing budget for infrastructure and vendor spend
Comfort operating in a private equity-backed, board-visible environment, with strong written and verbal communication skills for CIO and executive-level reporting
Exposure to OT environments and IT/OT convergence in a manufacturing or lab setting a plus
Familiarity with GxP, computer system validation, or 21 CFR Part 11 a plus
Familiarity with SOC 2 or similar compliance frameworks a plus
Experience with multi-jurisdiction data privacy considerations (e.g., GDPR) a plus given the UK site
Bachelor's degree in a related field or equivalent experience; relevant certifications (e.g., Azure/AWS, security) a plus
MSP/MSSP performance consistently meets or exceeds SLA targets, with proactive escalation management
Infrastructure supports business growth and audit readiness without unplanned downtime
Cybersecurity posture across IT and OT environments is continuously improving and measurable
Disaster recovery and backup objectives (RTO/RPO) are defined, tested, and met
End users and site operations experience reliable, well supported technology
CIO and executive leadership have clear, timely visibility into infrastructure and security posture
The pay range for this position is $185,000-225,000 per year. Please note that salaries vary within the range based on factors including, but not limited to, experience, skills, education, certifications, and location.
Impact: Every process we design is a step toward a cure. You’ll be making a real impact on the health of people in your community and across the globe.
Expertise: Work alongside a world-class team of scientists and operational leaders in a "no-ego" environment.
Stability & Growth: We offer the security of an established operation with the career growth opportunities of a rapidly expanding organization.
Competitive base salary with performance-based bonus opportunities.
Comprehensive health, dental, and vision insurance.
401(k) with company contribution.
Generous PTO and professional development support.
Rose BioSolutions is an equal opportunity employer committed to a diverse and inclusive workforce.
Apply
A few questions and your resume. We'll take it from there.