Assoc Dir, Information Security Governance Risk & Compliance

Servier

Boston (MA)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Servier, a Boston-based biopharmaceutical company, seeks an Associate Director, Information Security Governance Risk & Compliance to lead the US GRC program. You will shape the governance framework, risk methodology, and maturity roadmap, overseeing risk management, policy governance, third-party risk, control assurance, and audit readiness.

The role partners with Global Information Security, Legal, Privacy, and business stakeholders to translate risk into business and regulatory impact,

Qualifications

  • Leadership experience directing GRC programs in a US affiliate.
  • Background in governance, risk and compliance for information security.
  • Ability to translate risk into business, regulatory and financial implications.

Responsibilities

  • Establish and lead the US information security risk management framework across the affiliate.
  • Define risk assessment methodologies, risk taxonomy, scoring models and reporting standards.
  • Provide oversight of risk assessments and ensure alignment with enterprise risk expectations.
  • Drive risk-based remediation prioritization and control improvement initiatives.
  • Coordinate governance routines, cadences and reporting for the US GRC function.
  • Partner with Global Information Security, Legal, Privacy, Procurement and Internal Audit.

Skills

GRC leadership
Information security risk management
Policy governance
Third-party risk management
Stakeholder communications

Job description

Type of Contract: Full-time Employment / Unlimited

Assoc Dir, Information Security Governance Risk & Compliance

About Servier

Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision.

Role Summary

The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the Associate Director, Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk methodology, strategic priorities, and maturity roadmap. The role provides oversight of information security risk management, policy governance, compliance, third-party risk management, control assurance, audit readiness, and risk reporting while directing operational execution through subordinate managers, analysts, contractors, and service providers. This position partners closely with Global Information Security, IT, Legal, Privacy, Procurement, Quality, Internal Audit, and business stakeholders to ensure risks are identified, assessed, communicated, and managed in alignment with enterprise requirements. The role serves as the primary GRC advisor and enables risk-informed decision making by translating information security risk into business, operational, regulatory, and financial impact. This is a high visibility leadership role with the opportunity to build and scale a modern GRC capability aligned to Servier's global cybersecurity strategy, enterprise risk expectations, regulatory obligations, and business growth.

Primary Responsibilities

Cyber Risk Management and Governance

  • Establish and lead the US information security risk management framework across the affiliate
  • Define risk assessment methodologies, risk taxonomy, scoring models, reporting standards, and escalation criteria
  • Provide oversight and challenge of risk assessments performed by the GRC team
  • Ensure information security risks are clearly defined, consistently assessed, and aligned to Group methodology and enterprise risk expectations
  • Review material risks, treatment recommendations, mitigation strategies, and risk acceptance proposals before escalation
  • Drive risk-based prioritization of remediation activities, investment recommendations, and control improvement initiatives

Local Risk Coordinator and GRC Program Leadership

  • Serve as the senior US GRC leader responsible for coordinating information security risk governance across the affiliate
  • Act as the primary US liaison to Global Information Security for GRC-related risk, compliance, policy and assurance activities
  • Establish governance routines, program cadences, reporting expectations, and execution standards for the US GRC function
  • Ensure alignment between US affiliate execution and Global risk management methodology, policy baselines, and governance expectations
  • Escalate material risks, systemic issues, overdue remediation, and governance concerns through US and Global governance channels

Governance, Policy and Control Assurance

  • Establish governance expectations for information security policies, standards, procedures, control requirements, and exception management
  • Sponsor the local information security policy lifecycle, ensuring alignment with Global baselines, US business requirements, and regulatory obligations
  • Define the control assurance approach used to evaluate control design, implementation, effectiveness, and maturity
  • Oversee control monitoring, compliance validation, gap analysis, and continuous improvement activities
  • Define and monitor KPIs and KRIs measuring policy adoption, control maturity, security posture, remediation progress, and governance effectiveness

Third-Party Risk and Enterprise Risk Integration

  • Establish the strategic direction for third-party information security risk management across the US vendor ecosystem
  • Define governance requirements, risk acceptance criteria, assessment standards, and escalation paths for third-party engagements
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assoc Dir, Information Security Governance Risk & Compliance
Assoc Dir, Information Security Governance Risk & Compliance

Servier Pharmaceuticals • Boston (MA)

Hybrid
USD 179,000 - 212,000
Assoc Dir, Information Security Governance Risk & Compliance (Boston, MA, US)
Assoc Dir, Information Security Governance Risk & Compliance (Boston, MA, US)

Biopharma Careers • Boston (MA)

Hybrid
USD 179,000 - 212,000
InfoSec GRC Leader: Governance, Risk & Compliance
InfoSec GRC Leader: Governance, Risk & Compliance

Servier • Boston (MA)

On-site
USD 180,000 - 240,000
US GRC & Information Security Strategy Lead
US GRC & Information Security Strategy Lead

Biopharma Careers • Boston (MA)

Hybrid
USD 179,000 - 212,000
GRC Strategy Lead, Information Security & Compliance
GRC Strategy Lead, Information Security & Compliance

Servier Pharmaceuticals • Boston (MA)

Hybrid
USD 179,000 - 212,000
Senior Manager, Privacy
Senior Manager, Privacy

Servier Pharmaceuticals • United States

On-site
USD 160,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior Manager, Privacy (remote, US)
Senior Manager, Privacy (remote, US)

Biopharma Careers • United States

Hybrid
USD 160,000 - 180,000
Senior Manager, Privacy
Senior Manager, Privacy

Servier Inc • Boston (MA)

Hybrid
USD 160,000 - 180,000
401(k)
Unlimited sick time
Flexible time off
Assoc Dir, Internal Communications and Employee Engagement
Assoc Dir, Internal Communications and Employee Engagement

Servier Pharmaceuticals • Boston (MA)

Hybrid
USD 160,000 - 190,000
Assoc Dir, Internal Communications and Employee Engagement
Assoc Dir, Internal Communications and Employee Engagement

Servier • Boston (MA)

Hybrid
USD 160,000 - 190,000
Benefits package
Incentive programs