Assoc Dir, Information Security Governance Risk & Compliance
Listed on 2026-08-05
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Assoc Dir, Information Security Governance Risk & Compliance
Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision.
Role Summary
The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the Associate Director, Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk methodology, strategic priorities, and maturity roadmap. The role provides oversight of information security risk management, policy governance, compliance, third-party risk management, control assurance, audit readiness, and risk reporting while directing operational execution through subordinate managers, analysts, contractors, and service providers.
This position partners closely with Global Information Security, IT, Legal, Privacy, Procurement, Quality, Internal Audit, and business stakeholders to ensure risks are identified, assessed, communicated, and managed in alignment with enterprise requirements. The role serves as the primary GRC advisor and enables risk-informed decision making by translating information security risk into business, operational, regulatory, and financial impact. This is a high visibility leadership role with the opportunity to build and scale a modern GRC capability aligned to Servier's global cybersecurity strategy, enterprise risk expectations, regulatory obligations, and business growth.
Primary Responsibilities
Cyber Risk Management and Governance
Establish and lead the US information security risk management framework across the affiliate
Define risk assessment methodologies, risk taxonomy, scoring models, reporting standards, and escalation criteria
Provide oversight and challenge of risk assessments performed by the GRC team
Ensure information security risks are clearly defined, consistently assessed, and aligned to Group methodology and enterprise risk expectations
Review material risks, treatment recommendations, mitigation strategies, and risk acceptance proposals before escalation
Drive risk-based prioritization of remediation activities, investment recommendations, and control improvement initiatives
Local Risk Coordinator and GRC Program Leadership
Serve as the senior US GRC leader responsible for coordinating information security risk governance across the affiliate
Act as the primary US liaison to Global Information Security for GRC-related risk, compliance, policy, and assurance activities
Establish governance routines, program cadences, reporting expectations, and execution standards for the US GRC function
Ensure alignment between US affiliate execution and Global risk management methodology, policy baselines, and governance expectations
Escalate material risks, systemic issues, overdue remediation, and governance concerns through US and Global governance channels
Governance, Policy and Control Assurance
Establish governance expectations for information security policies, standards, procedures, control requirements, and exception management
Sponsor the local information security policy lifecycle, ensuring alignment with Global baselines, US business requirements, and regulatory obligations
Define the control assurance approach used to evaluate control design, implementation, effectiveness, and maturity
Oversee control monitoring, compliance validation, gap analysis, and continuous improvement activities
Define and monitor KPIs and KRIs measuring policy adoption, control maturity, security posture, remediation progress, and governance effectiveness
Third-Party Risk and Enterprise Risk Integration
Establish the strategic direction for third-party information security risk management across the US vendor ecosystem
Define governance requirements, risk acceptance criteria, assessment standards, and escalation paths for third-party engagements
Partner with Procurement, Legal, Privacy, IT, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).