The Executive Director, IT Governance and Compliance, is the senior leader responsible for establishing and operating the governance, regulatory compliance, and portfolio management practices that support the company’s consolidated IT and digital functions. Reporting to the Chief Information Officer, the role partners closely with business leaders and executives across the enterprise, the IT Leadership team (Infrastructure, AI/Data and Analytics, Security, and Applications) and the Enterprise Project Management team to ensure that IT decisions, investments, and controls are consistent, transparent, and aligned to enterprise priorities.
This role oversees a technology organization supporting 8 distinct business units and divisions, with an overall operating budget of $35MM+ and up to $5MM in annual capital spend. The function includes approximately 15 FTEs (6 directs) and supports a portfolio of 150 applications and platforms across the enterprise.
IT Governance & Policy Leadership
- Establish and lead IT governance framework, including decision rights, policy standards, and operating cadences across the consolidated digital organization.
- Define and maintain IT policies, standards, and procedures spanning Infrastructure, AI/Data and Analytics, and Business Analysis/Enterprise Applications functions.
- Lead governance forums (e.g., architecture review, change advisory, demand intake, project prioritization) to ensure consistent decision-making across teams.
- Partner with executive leadership and support the CIO in launching and operating the Technology Governance Council to align IT governance practices with enterprise risk appetite and organizational objectives.
- Own the IT policy lifecycle, ensuring policies remain current, communicated, and adopted across the organization.
Regulatory Compliance & Quality Systems
- Ensure IT and computerized systems practices comply with applicable FDA and other industry regulations, including 21 CFR Parts 11 (electronic records and signatures), 210/211 (Pharmaceutical Manufacturing), the 600-series biologics regulations, 820 (medical device), and other relevant industry regulatory requirement for establishment computer systems.
- Own the GxP computerized systems inventory, risk classification methodology, and qualification/validation program, incorporating current Computer Software Assurance (CSA) guidance.
- Establish and enforce change control, configuration management, and release validation discipline for regulated platforms, including parameter level changes affecting testing, labeling, and product release.
- Partner with Quality Assurance and Regulatory Affairs to maintain SOPs governing system validation, change control, and periodic review.
- Serve as the primary IT point of contact for FDA inspections, internal audits, and regulatory inquiries related to computerized systems.
- Own IT compliance with HIPAA and HITECH privacy and security requirements for protected health information, in partnership with the Privacy Officer and Information Security, including completion and sustainment of outstanding breach remediation commitments.
- Own the enterprise IT portfolio management process, including demand intake, prioritization, capacity planning, and investment tracking across all digital teams.
- Establish a standard project and product intake framework that balances Infrastructure, Data/AI, and Business Applications priorities.
- Provide executive-level portfolio reporting, including status, risk, spend, and value realization, to senior leadership.
- Own enterprise IT risk assessment practices, including identification, scoring, remediation tracking, and reporting, in coordination with Information Security and Internal Audit.
- Ensure IT readiness for internal, external, and regulatory audits, including timely evidence gathering and issue remediation.
- Own IT general controls for the annual financial statement audit, including access management, change management, and IT operations controls, and serve as the primary IT liaison to Internal Audit and the external auditors.
- Own the IT components of enterprise business continuity and disaster recovery planning for critical systems, including ERP, laboratory information systems, and service desk operations.
- Establish governance practices for evaluating, onboarding, and managing key technology vendors and software contracts.
- Support vendor risk assessments, including data security, business continuity, and regulatory considerations.
- Manage the enterprise technology contract, license, and billing lifecycles, including software asset management and the renewal calendar, in coordination with Finance and Supply Chain.
Cross-Functional & Strategic Leadership
- Support the CIO by defining and taking on “Office of the CIO” duties.
- Define and report monthly on key performance metrics for the enterprise technology organization.
- Partner with the leaders of Infrastructure, AI/Data and Analytics, and Business Analysis/Enterprise Applications to ensure governance practices support a unified digital organization.
Event Management
- Manage the functional lead and their team of direct reports in ensuring successful remote events.
- Build, lead, and develop a team responsible for IT governance, compliance, project management, and portfolio management functions.
- Establish clear roles, workflows, and career development paths for governance, relationship management and PMO staff.
- Manage performance, coaching, and professional development for direct reports.
- Foster collaboration between the new function and delivery teams across the consolidated digital organization.
Education
Bachelor’s degree in information technology, Computer Science, or a related STEM field.
Experience
- 15+ years of progressive IT experience, including significant experience in IT governance, compliance, risk management, business process engineering, and/or portfolio/PMO leadership.
- 7+ years of experience in healthcare, life sciences, pharmaceuticals, or other FDA-regulated environments.
- Demonstrated experience with FDA computerized systems requirements, including 21 CFR Part 11, validation/qualification practices, Data Integrity, and Computer Software Assurance (CSA) principles.
- Experience establishing or leading enterprise IT governance frameworks, policies, and standards.
- Experience managing IT portfolios, including demand intake, prioritization, and investment reporting.
- Experience leading audit readiness activities and managing regulatory inspection support for IT/computerized systems.
- Strong track record partnering with Infrastructure, Data/Analytics, and Applications teams to drive consistent governance practices.
- Demonstrated ability to communicate governance, risk, and compliance matters to executive leadership.
- Working knowledge of the regulatory frameworks governing biologics, or clinical laboratory operations, including 21 CFR 600 series, or similar clinical, blood or biological regulated industries.
Knowledge, Skills & Abilities
- IT governance frameworks, operating models, and policy management.
- FDA regulatory requirements applicable to computerized systems in regulated healthcare or biologics manufacturing, including 21 CFR Part 11, data integrity and ALCOA+ principles, and Computer Software Assurance.
- IT portfolio management, project/product intake, and PMO practices.
- Enterprise risk management, audit readiness, and controls frameworks.
- Vendor and contract management practices, including software licensing and framework agreements.
- Business continuity and disaster recovery planning principles.
- HIPAA and HITECH privacy and security requirements applicable to protected health information.
- Data governance and AI governance practices, including data classification, records retention, and responsible AI use.
- Establish and lead governance frameworks across a multi-disciplinary technology organization.
- Translate regulatory requirements into practical, actionable IT controls and processes.
- Manage complex portfolios spanning infrastructure, data/AI, and business applications.
- Communicate effectively with executives, regulators, auditors, and technical staff.
- Balance compliance obligations with delivery speed and business needs.
- Build and scale governance, compliance, and portfolio functions supporting enterprise growth.
- Influence and collaborate effectively across organizational boundaries and leadership teams.