
Director, Information Security Governance, Risk, Compliance
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in United States.
β’ Design and uphold enterprise cybersecurity governance, risk, and compliance strategies that align with organizational goals and regulatory standards.
β’ Oversee enterprise risk assessments, compliance evaluations, and control maturity analyses across business and technology sectors.
β’ Spearhead the creation and execution of cybersecurity policies, standards, procedures, and governance frameworks.
β’ Provide strategic guidance for audit readiness activities that support internal audits, regulatory reviews, and assessments by third parties.
β’ Assess and convey the enterprise's cyber risk posture, key risk indicators, and remediation priorities to executive leadership and governance committees.
β’ Manage third-party cybersecurity risk management processes, which include supplier risk assessments and contractual security stipulations.
β’ Coordinate organization-wide remediation strategies for vulnerabilities, audit findings, and risk treatment plans.
β’ Direct strategic planning and budgeting processes for cybersecurity governance and compliance initiatives.
β’ Collaborate with legal, privacy, quality, manufacturing, and IT leadership to ensure cybersecurity governance is consistent with enterprise risk management goals.
β’ Assist in developing business continuity and operational resilience strategies for essential business functions.
β’ Work alongside architecture and engineering teams to guarantee that security controls and compliance requirements are incorporated into technology solutions.
β’ Foster cybersecurity awareness and promote risk-informed decision-making across business units and leadership teams.
β’ Support organizational efforts related to mergers, acquisitions, and digital transformation by assessing cybersecurity and compliance risks.
β’ A minimum of a Bachelorβs degree in MIS, IT, Engineering, or a related field is required.
β’ Equivalent experience and/or education may be taken into account.
β’ At least eight years of experience in IT or Cybersecurity is necessary.
β’ Familiarity with cybersecurity and privacy principles, frameworks, and regulatory requirements relevant to global pharmaceutical companies.
β’ Understanding of enterprise risk management methodologies, governance structures, and compliance assessment techniques.
β’ Knowledge of audit practices, internal controls, and regulatory compliance requirements including SOX, HIPAA, GDPR, and GxP standards.
β’ Awareness of third-party risk management concepts and vendor governance processes.
β’ Proficiency in incident management, vulnerability management, and security operations governance.
β’ Understanding of security architecture concepts, cloud technologies, and data protection strategies.
β’ Competitive salaries
β’ Comprehensive benefits
β’ An inclusive work environment
β’ Commitment to equal opportunity employment
Terac
DSV - Global Transport and Logistics
Kin Insurance
Summit Therapeutics, Inc.
Get handpicked remote jobs straight to your inbox weekly.