Director, Information Security Governance Risk Compliance

1100 Mylan Pharmaceuticals Inc.

Northern (KY)

Hybrid

USD 112,000 - 236,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Inclusive environment

Job summary

Viatris, based in the United States, seeks a Director of Governance, Risk & Compliance (GRC) to lead enterprise cybersecurity governance, risk management and regulatory obligations across the organization.

The role partners with executive leadership, legal, privacy, quality, manufacturing and IT to ensure risks are identified, communicated, and managed in alignment with FDA expectations and global regulations.

Qualifications

  • Bachelor’s degree in MIS/IT/Engineering or equivalent.
  • 8+ years in IT or cybersecurity.
  • Knowledge of SOX, HIPAA, GDPR, GxP.
  • Experience with risk management methodologies and governance.

Responsibilities

  • Develop and maintain cybersecurity governance, risk, and compliance strategies.
  • Lead risk assessments, compliance reviews, and control maturity evaluations.
  • Oversee policy development, standards, and governance frameworks.
  • Ensure audit readiness for internal audits, regulatory inspections, and third-party assessments.
  • Coordinate remediation strategies for vulnerabilities and findings.
  • Team with legal, privacy, quality, manufacturing, and IT leadership on governance.

Skills

GRC leadership
Cybersecurity governance
Risk management
Regulatory compliance
Audit readiness
Vendor governance
第三方风险管理

Education

Bachelor's in MIS/IT/Engineering
Master's preferred

Job description

About Mylan Inc. Viatris

Mylan Inc. Viatris is a global healthcare company uniquely positioned to bridge the traditional divide between generics and brands, combining the best of both to more holistically address healthcare needs globally. With a mission to empower people worldwide to live healthier at every stage of life, we provide access at scale, currently supplying high-quality medicines to approximately 1 billion patients around the world annually and touching all of life's moments, from birth to the end of life, acute conditions to chronic diseases. We have been included on number of award lists that demonstrate the impact we are making. Every day, we rise to the challenge to make a difference and here’s how the Director, Information Security Governance Risk Compliance role will make an impact:

Position Overview

The primary purpose of the Director, Governance, Risk & Compliance (GRC) is to provide strategic leadership and enterprise oversight for the GRC program supporting the organization’s cybersecurity, privacy, quality, and regulatory obligations. The Director is responsible for establishing and maturing enterprise-wide cybersecurity governance processes, risk management frameworks, compliance monitoring activities, third-party risk management, and audit readiness programs. This role partners with executive leadership, legal, privacy, quality, manufacturing, and global technology teams to ensure cybersecurity risks are identified, communicated, and managed in alignment with business objectives and regulatory requirements applicable to the pharmaceutical industry including GxP, HIPAA, SOX, GDPR, and FDA expectations. The Director leads cross-functional initiatives, develops strategic roadmaps, directs remediation priorities, and ensures effective communication of cyber risk posture to executive leadership and governance committees. Key responsibilities for this role include:

Key Responsibilities
  • Develop and maintain enterprise cybersecurity governance, risk, and compliance strategies aligned with organizational objectives and regulatory requirements.
  • Direct enterprise risk assessments, compliance reviews, and control maturity evaluations across business and technology environments.
  • Lead development and implementation of cybersecurity policies, standards, procedures, and governance frameworks.
  • Provide strategic oversight for audit readiness activities supporting internal audits, regulatory inspections, and third-party assessments.
  • Review and communicate enterprise cyber risk posture, key risk indicators, and remediation priorities to executive leadership and governance committees.
  • Oversee third-party cybersecurity risk management processes including supplier risk evaluations and contractual security requirements.
  • Coordinate enterprise-wide remediation strategies for vulnerabilities, audit findings, and risk treatment plans.
  • Guide strategic planning and budgeting activities for cybersecurity governance and compliance initiatives.
  • Collaborate with legal, privacy, quality, manufacturing, and IT leadership to align cybersecurity governance with enterprise risk management objectives.
  • Support development of business continuity and operational resilience strategies for critical business processes.
  • Partner with architecture and engineering teams to ensure security controls and compliance requirements are integrated into technology solutions.
  • Promote cybersecurity awareness and risk-informed decision making across business functions and leadership teams.
  • Support organizational initiatives involving mergers, acquisitions, and digital transformation by evaluating cybersecurity and compliance risks.
Minimum Qualifications
  • Minimum of a Bachelor’s degree with a focus in MIS ,IT or Engineering or equivalent is required. Masters degree in MIS, IT, Engineering or related is preferred. Related experience and/or education may be considered.
  • Minimum of eight years of IT or Cybersecurity experience is required.
  • Knowledge of cybersecurity and privacy principles, frameworks, and regulatory requirements applicable to global pharmaceutical organizations.
  • Knowledge of enterprise risk management methodologies, governance structures, and compliance assessment techniques.
  • Knowledge of audit practices, internal controls, and regulatory compliance requirements including SOX, HIPAA, GDPR, and GxP expectations.
  • Knowledge of third-party risk management concepts and vendor governance processes.
  • Knowledge of incident management, vulnerability management, and security operations governance.
  • Knowledge of security architecture concepts, cloud technologies, and data protection methodologies.
Compensation & Benefits
  • Exact compensation may vary based on skills, experience, and location.
  • The salary range for this position is $112,000.00 - $236,000.00 USD.
  • At Viatris, we offer competitive salaries, benefits and an inclusive environment where you can use your experiences, perspectives and skills to help make an impact on the lives of others.
Equal Opportunity Employer

Viatris is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, gender expression, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

Company Background

Viatris is a global healthcare company formed in 2020 through the combination of Mylan and Upjohn, a legacy division of Pfizer. By integrating the strengths of these two companies, including our global workforce, we aim to deliver increased access to affordable, quality medicines for patients worldwide, regardless of geography or circumstance. We believe in healthcare as it should be – empowering people worldwide to live healthier at every stage of life. Because of our unwavering belief that better access leads to better health, we leverage our best-in-class manufacturing and scientific expertise and proven commercial capabilities to bring quality medicines to patients when and where they need them.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Information Security Governance Risk Compliance
Director, Information Security Governance Risk Compliance

Viatris • United States

On-site
USD 112,000 - 236,000
Analyst – Governance, Risk, & Information Protection
Analyst – Governance, Risk, & Information Protection

1100 Mylan Pharmaceuticals Inc. • Northern (KY)

On-site
USD 39,000 - 88,000
Senior Internal Audit Analyst
Senior Internal Audit Analyst

1100 Mylan Pharmaceuticals Inc. • Canonsburg

Hybrid
USD 90,000 - 120,000
Manager, EH&S
Manager, EH&S

1100 Mylan Pharmaceuticals Inc. • St. Albans (WV)

On-site
USD 78,000 - 152,000
Administrative Assistant
Administrative Assistant

1100 Mylan Pharmaceuticals Inc. • Washington

On-site
USD 37,000 - 73,000
Supervisor, Pharmaceutical Coating – 2nd Shift
Supervisor, Pharmaceutical Coating – 2nd Shift

1100 Mylan Pharmaceuticals Inc. • St. Albans (WV)

On-site
USD 55,000 - 105,000
Technical Assistant, PV Operations
Technical Assistant, PV Operations

1100 Mylan Pharmaceuticals Inc. • Morgantown (WV)

On-site
USD 37,000 - 73,000
Senior Manager, Core Labeling Strategy
Senior Manager, Core Labeling Strategy

1100 Mylan Pharmaceuticals Inc. • Washington

On-site
USD 95,000 - 193,000
Competitive salary
Benefits
Inclusive environment
Director Core Labeling Strategy
Director Core Labeling Strategy

1100 Mylan Pharmaceuticals Inc. • Washington

On-site
USD 112,000 - 236,000
Manager Advertising and Promotion US Regional
Manager Advertising and Promotion US Regional

1100 Mylan Pharmaceuticals Inc. • Washington, Northern (KY)

Hybrid
USD 78,000 - 152,000