Get more replies from employers
Send a job-specific resume in minutes.
Servier, a Boston-based biopharmaceutical company, seeks an Associate Director, Information Security Governance Risk & Compliance to lead the US GRC program. You will shape the governance framework, risk methodology, and maturity roadmap, overseeing risk management, policy governance, third-party risk, control assurance, and audit readiness.
The role partners with Global Information Security, Legal, Privacy, and business stakeholders to translate risk into business and regulatory impact,
Type of Contract: Full-time Employment / Unlimited
About Servier
Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision.
Role Summary
The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the Associate Director, Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk methodology, strategic priorities, and maturity roadmap. The role provides oversight of information security risk management, policy governance, compliance, third-party risk management, control assurance, audit readiness, and risk reporting while directing operational execution through subordinate managers, analysts, contractors, and service providers. This position partners closely with Global Information Security, IT, Legal, Privacy, Procurement, Quality, Internal Audit, and business stakeholders to ensure risks are identified, assessed, communicated, and managed in alignment with enterprise requirements. The role serves as the primary GRC advisor and enables risk-informed decision making by translating information security risk into business, operational, regulatory, and financial impact. This is a high visibility leadership role with the opportunity to build and scale a modern GRC capability aligned to Servier's global cybersecurity strategy, enterprise risk expectations, regulatory obligations, and business growth.
Primary Responsibilities
Cyber Risk Management and Governance
Local Risk Coordinator and GRC Program Leadership
Governance, Policy and Control Assurance
Third-Party Risk and Enterprise Risk Integration