×
Register Here to Apply for Jobs or Post Jobs. X

Assoc Dir, Information Security Governance Risk & Compliance

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: Servier
Full Time position
Listed on 2026-08-04
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 180000 - 240000 USD Yearly USD 180000.00 240000.00 YEAR
Job Description & How to Apply Below

Type of

Contract:

Full-time Employment / Unlimited

Assoc Dir, Information Security Governance Risk & Compliance

About Servier

Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision.

Role Summary

The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the Associate Director, Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk methodology, strategic priorities, and maturity roadmap. The role provides oversight of information security risk management, policy governance, compliance, third-party risk management, control assurance, audit readiness, and risk reporting while directing operational execution through subordinate managers, analysts, contractors, and service providers.

This position partners closely with Global Information Security, IT, Legal, Privacy, Procurement, Quality, Internal Audit, and business stakeholders to ensure risks are identified, assessed, communicated, and managed in alignment with enterprise requirements. The role serves as the primary GRC advisor and enables risk-informed decision making by translating information security risk into business, operational, regulatory, and financial impact. This is a high visibility leadership role with the opportunity to build and scale a modern GRC capability aligned to Servier's global cybersecurity strategy, enterprise risk expectations, regulatory obligations, and business growth.

Primary Responsibilities

Cyber Risk Management and Governance

  • Establish and lead the US information security risk management framework across the affiliate
  • Define risk assessment methodologies, risk taxonomy, scoring models, reporting standards, and escalation criteria
  • Provide oversight and challenge of risk assessments performed by the GRC team
  • Ensure information security risks are clearly defined, consistently assessed, and aligned to Group methodology and enterprise risk expectations
  • Review material risks, treatment recommendations, mitigation strategies, and risk acceptance proposals before escalation
  • Drive risk-based prioritization of remediation activities, investment recommendations, and control improvement initiatives

Local Risk Coordinator and GRC Program Leadership

  • Serve as the senior US GRC leader responsible for coordinating information security risk governance across the affiliate
  • Act as the primary US liaison to Global Information Security for GRC-related risk, compliance, policy and assurance activities
  • Establish governance routines, program cadences, reporting expectations, and execution standards for the US GRC function
  • Ensure alignment between US affiliate execution and Global risk management methodology, policy baselines, and governance expectations
  • Escalate material risks, systemic issues, overdue remediation, and governance concerns through US and Global governance channels

Governance, Policy and Control Assurance

  • Establish governance expectations for information security policies, standards, procedures, control requirements, and exception management
  • Sponsor the local information security policy lifecycle, ensuring alignment with Global baselines, US business requirements, and regulatory obligations
  • Define the control assurance approach used to evaluate control design, implementation, effectiveness, and maturity
  • Oversee control monitoring, compliance validation, gap analysis, and continuous improvement activities
  • Define and monitor KPIs and KRIs measuring policy adoption, control maturity, security posture, remediation progress, and governance effectiveness

Third-Party Risk and Enterprise Risk Integration

  • Establish the strategic direction for third-party information security risk management across the US vendor ecosystem
  • Define governance requirements, risk acceptance criteria, assessment standards, and escalation paths for third-party engagements
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary