Sr. IT Compliance Analyst
Listed on 2026-07-27
-
IT/Tech
Cybersecurity, IT Business Analyst
Liquidia is deeply passionate and committed to the discovery, engineering, and development required to bring novel therapies to patients who need them most, and to the healthcare providers who care for them. Our current drive is toward improving the treatment of pulmonary hypertension (PH). We will continue to combine our proprietary, innovative PRINT® Technology with new and established medications, offering the potential for both better precision and improved clinical outcomes.
Our team members include some of the industry’s top scientists, clinicians, business strategists, engineers, and pharmaceutical executives. We work together to help people lead longer, healthier, and happier lives.
The Sr. IT Compliance Analyst is the senior individual contributor responsible for the operational execution of Liquidia's IT compliance program in a commercial-stage public pharmaceutical environment subject to SOX, GxP, and 21 CFR Part 11 regulations. The role serves as the primary IT bridge to the Quality function on compliance and computerized system validation matters, plans and conducts internal IT audits, manages supplier and third-party IT risk assessments, oversees the IT Infrastructure Qualification program for GxP-supporting infrastructure, serves as the primary IT liaison for external audit engagements, drives corrective action closure, and leads the maturation of the IT cybersecurity framework on a multi-year roadmap.
The role contributes to the broader IT cybersecurity program through coordination on policy lifecycle, AI governance documentation, and risk register maintenance. This position establishes operational separation of duty between IT compliance oversight and IT security and infrastructure execution.
Job responsibilities
- Steward the lifecycle of IT policies, standards, and standard operating procedures, including version control, periodic review, and stakeholder approval workflows.
- Maintain the IT risk register, governance trackers, and recurring control evidence, including quarterly review cadences.
- Maintain AI governance documentation, including tool authorization records and monitoring artifacts.
- Administer SOX IT General Controls (ITGC) documentation, evidence collection, and control performance tracking.
- Coordinate ITGC walkthroughs, testing, and evidence requests with internal and external auditors, ensuring timely delivery of requested artifacts.
- Track IT audit findings and corrective actions through verified closure with control owners.
- Maintain 21 CFR Part 11 documentation for IT-managed systems and coordinate with Quality on validation boundaries.
- Support infrastructure qualification activities for GxP-supporting infrastructure using established IT qualification templates, in coordination with Quality and the Computer System Validation function.
- Participate in change control and periodic review activities for validated and qualified IT systems to assess compliance impact.
- Maintain cybersecurity framework alignment documentation and support gap analysis and remediation tracking.
- Conduct third-party IT risk assessments in coordination with Procurement and Legal.
- Support security awareness training compliance reporting and incident response documentation.
- Perform other duties as assigned.
Job requirements
Education and Experience:
- Minimum of 8 years of progressive experience in IT compliance, IT audit, or governance, risk, and compliance (GRC) functions with a Bachelor's degree, or a minimum of 6 years with a Master's degree, in Information Technology, Business, Accounting, or a related discipline.
- Demonstrated experience in the pharmaceutical, biotechnology, or life sciences industry preferred.
- Working knowledge of IT-relevant Good Practice (GxP) regulations, including United States (FDA) requirements and 21 CFR Part 11.
- Working knowledge of GAMP 5 methodology and IT infrastructure qualification practices.
- Demonstrated experience supporting external audits and managing corrective action life cycles.
Knowledge, Skills and Abilities:
- Strong working knowledge of SOX IT General Controls, including access management, change management, and operational controls in support of financial reporting.
- Familiar…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).