Technical Lead - Threat Mitigations
lilly · US, Remote · United States · Remote
Posted Oct 9, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us.
Overview – Advisor - Cyber Programs, Mitigations, and Compliance
The Cyber Threat Mitigations Team is looking for an experienced service-area lead with strong background in threat surface management and the technical control solutions that support it (ex. vulnerability scanning and prioritization platforms, EDR, SIEM).
This role is designed for someone who excels at working with cross-functional teams to drive down security risk across Lilly's technology estate, and who will build durable connections with adjacent cybersecurity teams to ensure emerging threats translate into prioritized, actionable mitigation work.
As a Threat Mitigations Advisor, you will partner with internal cyber teams, platform and application owners, and business stakeholders to reduce the impact of identified vulnerabilities and threats. You will drive burndowns of targeted risks across the organization and support application teams in executing their cyber mitigation plans.
You will also serve as a technical anchor for the threat surface management squad, raising the capability of the analysts around you.
Key Responsibilities:
Threat Mitigation & Burndown Execution
Assist in the intake of vulnerability, exposure, and threat intelligence data from across the cyber organization and translate it into scoped, executable burndown campaigns with clear owners, targets, and timelines.
Develop solutions that accelerate burndown execution, including automation of triage, deduplication, ownership identification, and notification.
Drive burndowns to closure — tracking progress against targets, unblocking remediation owners, and escalating stalled or high-severity work.
Capture root cause, technical recommendations, and lessons learned, and package them for the teams that can act on them to drive durable process improvement.
Threat Mitigation Plan Validation & Support
Assist platform, application, and infrastructure teams in interpreting mitigation requirements and completing their security plans, removing friction rather than simply tracking overdue items.
Serve as a technical resource for the ‘how’
Confirm implementation of threat mitigation requirements in our GRC tool — validating that required controls are in place, evidence is attached, and records are accurate before closure.
Threat Surface Management…