> Markdown version of [/jobs/ext/2270113-director-information-security-governance-risk-compliance](https://www.wearedevelopers.com/jobs/ext/2270113-director-information-security-governance-risk-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Information Security Governance Risk Compliance - **Company:** Viatris Inc. - **Location:** Canonsburg, PA, United States - **Experience:** Expert - **Salary:** $112,000.0 - $236,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, IT Management, Key Management, Software Vulnerability Management, GXP - **Published:** August 27, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88152073/1 ## About the Role * Minimum of a Bachelor's degree with a focus in MIS ,IT or Engineering or equivalent is required. Masters degree in MIS, IT, Engineering or related is preferred. Related experience and/or education may be considered. * Minimum of eight years of IT or Cybersecurity experience is required. * Knowledge of cybersecurity and privacy principles, frameworks, and regulatory requirements applicable to global pharmaceutical organizations. * Knowledge of enterprise risk management methodologies, governance structures, and compliance assessment techniques. * Knowledge of audit practices, internal controls, and regulatory compliance requirements including SOX, HIPAA, GDPR, and GxP expectations. * Knowledge of third-party risk management concepts and vendor governance processes. * Knowledge of incident management, vulnerability management, and security operations governance. * Knowledge of security architecture concepts, cloud technologies, and data protection methodologies. ## Description The primary purpose of the Director, Governance, Risk & Compliance (GRC) is to provide strategic leadership and enterprise oversight for the GRC program supporting the organization's cybersecurity, privacy, quality, and regulatory obligations. The Director is responsible for establishing and maturing enterprise-wide cybersecurity governance processes, risk management frameworks, compliance monitoring activities, third-party risk management, and audit readiness programs. This role partners with executive leadership, legal, privacy, quality, manufacturing, and global technology teams to ensure cybersecurity risks are identified, communicated, and managed in alignment with business objectives and regulatory requirements applicable to the pharmaceutical industry including GxP, HIPAA, SOX, GDPR, and FDA expectations. The Director leads cross-functional initiatives, develops strategic roadmaps, directs remediation priorities, and ensures effective communication of cyber risk posture to executive leadership and governance committees., * Develop and maintain enterprise cybersecurity governance, risk, and compliance strategies aligned with organizational objectives and regulatory requirements. * Direct enterprise risk assessments, compliance reviews, and control maturity evaluations across business and technology environments. * Lead development and implementation of cybersecurity policies, standards, procedures, and governance frameworks. * Provide strategic oversight for audit readiness activities supporting internal audits, regulatory inspections, and third-party assessments. * Review and communicate enterprise cyber risk posture, key risk indicators, and remediation priorities to executive leadership and governance committees. * Oversee third-party cybersecurity risk management processes including supplier risk evaluations and contractual security requirements. * Coordinate enterprise-wide remediation strategies for vulnerabilities, audit findings, and risk treatment plans. * Guide strategic planning and budgeting activities for cybersecurity governance and compliance initiatives. * Collaborate with legal, privacy, quality, manufacturing, and IT leadership to align cybersecurity governance with enterprise risk management objectives. * Support development of business continuity and operational resilience strategies for critical business processes. * Partner with architecture and engineering teams to ensure security controls and compliance requirements are integrated into technology solutions. * Promote cybersecurity awareness and risk-informed decision making across business functions and leadership teams. * Support organizational initiatives involving mergers, acquisitions, and digital transformation by evaluating cybersecurity and compliance risks. ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)