GRC Leader - Information Security & Compliance

Servier Pharmaceuticals

Boston (MA)

Hybrid

USD 179,000 - 212,000

Full time

8 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Servier in the U.S. seeks an Associate Director, Information Security Governance, Risk and Compliance to lead the US GRC function, establishing risk management framework, policy governance, and third-party risk across the US affiliate.

You will partner with Global Information Security, IT, Legal, Privacy, and Procurement to translate risk into business impact and drive remediation. The role combines leadership with strategic program development and executive reporting.

Qualifications

  • Minimum 8+ years of experience in information security GRC, IT risk management, cybersecurity, compliance, audit, security operations, or related disciplines
  • Minimum of 3+ years in a leadership role with program ownership, people leadership, or management of managers
  • Bachelor’s degree preferred in Cybersecurity, Information Technology, Information Systems, Business, Risk Management, or a related field
  • Deep expertise in information security risk frameworks and governance models, including NIST CSF 2.0, ISO 27001, PCI, SOX, FAIR, or similar methodologies
  • Experience leading policy governance, third-party risk management, compliance oversight, audit readiness, control assurance, and remediation governance programs
  • Strong executive communication skills with the ability to influence senior stakeholders in a global, matrixed organization

Responsibilities

  • Establish and lead the US information security risk management framework across the affiliate
  • Define risk assessment methodologies, risk taxonomy, scoring models, reporting standards, and escalation criteria
  • Provide oversight and challenge of risk assessments performed by the GRC team
  • Ensure information security risks are clearly defined, consistently assessed, and aligned to Group methodology and enterprise risk expectations
  • Review material risks, treatment recommendations, mitigation strategies, and risk acceptance proposals before escalation
  • Drive risk-based prioritization of remediation activities, investment recommendations, and control improvement initiatives
  • Serve as the senior US GRC leader responsible for coordinating information security risk governance across the affiliate
  • Act as the primary US liaison to Global Information Security for GRC-related risk, compliance, policy, and assurance activities
  • Establish governance routines, program cadences, reporting expectations, and execution standards for the US GRC function
  • Ensure alignment between US affiliate execution and Global risk management methodology, policy baselines, and governance expectations
  • Escalate material risks, systemic issues, overdue remediation, and governance concerns through US and Global governance channels
  • Establish governance expectations for information security policies, standards, procedures, control requirements, and exception management
  • Sponsor the local information security policy lifecycle, ensuring alignment with Global baselines, US business requirements, and regulatory obligations
  • Define the control assurance approach used to evaluate control design, implementation, effectiveness, and maturity
  • Oversee control monitoring, compliance validation, gap analysis, and continuous improvement activities
  • Define and monitor KPIs and KRIs measuring policy adoption, control maturity, security posture, remediation progress, and governance effectiveness
  • Establish the strategic direction for third-party information security risk management across the US vendor ecosystem
  • Define governance requirements, risk acceptance criteria, assessment standards, and escalation paths for third-party engagements
  • Partner with Procurement, Legal, Privacy, IT, and business stakeholders to ensure vendor security risks are appropriately assessed and managed
  • Oversee integration of third-party security risk into enterprise risk management, procurement processes, contractual reviews, and business decision making
  • Drive cross-domain alignment across Information Security, IT, Legal, Privacy, Procurement, Quality, and business functions
  • Oversee information security audit readiness across internal audits, external audits, regulatory engagements, and assurance activities
  • Establish governance over evidence collection, control validation, audit response, remediation tracking, and management reporting
  • Ensure audit findings, compliance gaps, and control deficiencies are translated into clear risk treatment plans with defined owners, timelines, and measurable outcomes
  • Partner with Internal Audit, Quality, Legal, Privacy, and Global Information Security to support assurance activities and regulatory expectations
  • Act as a trusted advisor on information security governance, risk, compliance, and assurance matters
  • Translate complex information security risks into business, operational, regulatory, financial, and reputational impact
  • Deliver executive-level reporting on information security risk posture, governance maturity, compliance status, control effectiveness, and remediation progress
  • Support governance committees, leadership forums, business reviews, and strategic planning discussions with clear risk-based recommendations
  • Represent US GRC priorities in Global information security and enterprise risk forums, influencing alignment where appropriate
  • Lead and develop the US Information Security Governance Risk and Compliance function
  • Manage GRC managers, analysts, contractors, consultants, managed service providers, and supporting resources
  • Define the GRC organizational structure, operating procedures, quality standards, workforce strategy, and capability development roadmap
  • Build scalable and repeatable GRC processes aligned to information security maturity objectives and organizational growth
  • Identify opportunities to improve efficiency through automation, process standardization, documentation quality, tooling, and operating model maturity

Skills

Information security GRC
Leadership
Executive communication
Regulatory frameworks

Education

Bachelor’s degree (cybersecurity/IT/business)

Tools

NIST CSF 2.0
ISO 27001
PCI
SOX
FAIR

Job description

Servier in the U.S. seeks an Associate Director, Information Security Governance, Risk and Compliance to lead the US GRC function, establishing risk management framework, policy governance, and third-party risk across the US affiliate.

You will partner with Global Information Security, IT, Legal, Privacy, and Procurement to translate risk into business impact and drive remediation. The role combines leadership with strategic program development and executive reporting.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InfoSec GRC Leader: Governance, Risk & Compliance
InfoSec GRC Leader: Governance, Risk & Compliance

Servier • Boston (MA)

On-site
USD 180,000 - 240,000
Assoc Dir, Information Security Governance Risk & Compliance
Assoc Dir, Information Security Governance Risk & Compliance

Servier • Boston (MA)

On-site
USD 180,000 - 240,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC & InfoSec Director: Strategy, Risk & Compliance
GRC & InfoSec Director: Strategy, Risk & Compliance

Surescripts, LLC • Minneapolis (MN)

Hybrid
USD 209,000 - 255,000
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
Senior GRC Director: Security Governance & Risk Lead
Senior GRC Director: Security Governance & Risk Lead

Health Care Service Corp. • Richardson (TX)

On-site
USD 133,000 - 248,000
Health benefits
401(k) plan
Pension plan
+8
GRC Lead: Security Risk & Compliance
GRC Lead: Security Risk & Compliance

MSIG USA • Warren Township (IA)

On-site
USD 120,000 - 180,000
Director, GRC & Information Security — Hybrid Leader
Director, GRC & Information Security — Hybrid Leader

Surescripts • Minneapolis (MN)

Hybrid
USD 209,000 - 255,000
Comprehensive healthcare
Infertility coverage
Paid time off
+4
Information Security GRC Leader
Information Security GRC Leader

Steptoe LLP • Washington

Hybrid
USD 148,000 - 161,000
Medical, Dental, Vision
401K Plan
Profit-Sharing
+2
Global InfoSec GRC Manager — Lead Compliance & Risk
Global InfoSec GRC Manager — Lead Compliance & Risk

Ivalua • New York (NY)

Hybrid
USD 112,000 - 208,000
Competitive salary
Healthcare benefits
Hybrid working model
+2