Stand out for this role — generate a tailored resume and cover letter in about a minute.
Sobi is seeking a Director of Information Security Governance & Compliance to ensure a robust information security framework. This role involves leading governance activities, driving audits, and overseeing continuous improvement initiatives within a collaborative, hybrid workspace.
The ideal candidate has significant experience in information security governance in regulated environments and possesses strong analytical skills. This position offers competitive compensation and a focus on work/life balance, enabling impactful contributions to ultra-rare disease patients.
As the Director of Information Security Governance & Compliance, you will play a key leadership role in ensuring that Sobi's information security framework is robust, effective and fit for a highly regulated environment. You will lead governance and compliance activities across Sobi and our external partners, drive audits and control reviews, maintain a strong and up-to-date ISMS, and oversee CAPA and continuous improvement initiatives. In this role, you will work closely with the CISO, Quality and key stakeholders across the business to make sure our policies, processes and responsibilities are clear, aligned and continuously improving.
You will join our Global Information Security team, report to the CISO, and be based at our Stockholm HQ or Global Hub in Basel. This is a hybrid role with the opportunity to work in an international setting where your expertise will have visible impact across the organisation.
About you
You are a confident and pragmatic information security leader who enjoys combining governance, compliance and continuous improvement in a way that creates real business value. You are comfortable navigating a complex, regulated environment and know how to translate frameworks and requirements into practical ways of working. Just as importantly, you build trust across functions and communicate with clarity—whether you are partnering with senior stakeholders, supporting audits, or driving follow‑up actions with the wider organisation. You bring a structured and proactive mindset, a strong sense of ownership, and a genuine interest in building a security culture that is both effective and sustainable.