> Markdown version of [/jobs/ext/2636440-associate-director-it-compliance](https://www.wearedevelopers.com/jobs/ext/2636440-associate-director-it-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Director IT Compliance - **Company:** Novotech Inc. - **Location:** United States - **Salary:** $160,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Audit Trail, Software as a Service, Software Documentation, Cyber Security, Data Integrity, Document Management Systems, Information Technology Audit, IT Management, Cloud Services, Microsoft SharePoint, System Testing, Smartsheet, Information Security Management System, IT General Controls (ITGC), Computerised Systems, Information Technology, RSA Archer Platform, GXP, Servicenow - **Published:** August 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6918d502bb9eeef1 ## About the Role * Bachelor's Degree in Information Technology, Computer Science, Information Security, Quality, Life Sciences, Regulatory Compliance, or a related discipline. * Significant experience in IT compliance, technology risk, governance, information security, quality systems or regulated technology environments. * Experience working in a regulated industry such as clinical research, pharmaceutical, biotechnology, medical device, healthcare or life sciences. * Demonstrated experience supporting vendor, sponsor, client, regulatory or certification audits. * Practical knowledge of ISO/IEC 27001, preferably ISO/IEC 27001:2022. * Experience maintaining ISMS records, control evidence, risk registers, audit records, policies, procedures or compliance documentation. * Understanding of GxP computerised system compliance and risk-based validation principles. * Familiarity with regulatory frameworks and expectations such as 21 CFR Part 11, EU Annex 11, GAMP 5, data integrity principles, GDPR or other privacy/security obligations. * Experience working with SaaS, cloud-hosted systems, vendor qualification, supplier audits or third-party risk assessments.Experience engaging with cross-functional stakeholders across IT, QA, Legal, Privacy, Information Security and business operations. Preferred * ISO/IEC 27001 Lead Implementer, Lead Auditor, Internal Auditor or equivalent certification. * CISA, CRISC, CISM, CISSP, CGEIT or other relevant governance, risk, audit or information security certification. * GxP, CSV, CSA, GAMP 5 or life sciences validation training. * Privacy or data protection certification such as CIPP/E, CIPM or equivalent. * Experience in a Contract Research Organisation, clinical trial technology environment, pharmaceutical sponsor environment or regulated SaaS ecosystem. * Experience with ServiceNow, SharePoint, Smartsheet, Microsoft 365, GRC platforms, audit management tools or document management systems.Experience with emerging AI technologies as related to the GxP system validation and functions. ## Description The Associate Director, IT Compliance is responsible for organising, leading and continuously improving Novotech's IT Compliance function across a global CRO environment. The role provides leadership for IT governance, compliance assurance, audit readiness, vendor and sponsor audit responses, ISMS governance, ISO/IEC 27001:2022 certification activities, and regulatory compliance guidance for GxP computerised systems. This role acts as a key interface between IT, Information Security, Quality Assurance, Legal, Privacy, Business Operations, system owners, sponsors, vendors and external auditors. The successful candidate will ensure that Novotech's IT practices, systems, documentation and control evidence remain inspection-ready and aligned with applicable regulatory, contractual, quality and information security requirements. The role requires a pragmatic compliance leader who can interpret regulatory obligations, translate them into practical IT controls and documentation, and guide business and technology teams through audit, certification, risk management and continuous improvement activities. Responsibilities Leadership of the IT Compliance Function * Lead, organise and manage the global IT Compliance function, ensuring clear priorities, operating cadence, responsibilities, documentation standards and service expectations.Act as the primary IT Compliance lead for technology governance, IT control assurance, IT audit readiness and regulatory support. Vendor, Sponsor and Regulatory Audit Management * Manage and coordinate IT responses to vendor, sponsor, client and regulatory audits involving IT systems, IT practices, information security controls and data privacy controls.Manage and coordinate vendor, sponsor, client and regulatory reviews in relation to emerging AI and Machine Learning capabilities, as well as participate in strategy discussions related to AI ISMS Governance and ISO/IEC 27001:2022 Certification * Manage and maintain Information Security Management System records, registers, evidence repositories and governance documentation.Support the ongoing operation, monitoring and continual improvement of Novotech's ISMS. GxP and Computerised System Compliance Guidance * Provide guidance to IT, Quality Assurance, system owners and business process owners on regulatory compliance expectations for GxP computerised systems.Support interpretation and practical application of relevant regulatory and industry expectations, including GxP, computerised system validation, data integrity, 21 CFR Part 11, EU Annex 11 and GAMP 5-aligned risk-based validation principles. Governance, Risk and Control Assurance * Lead or support technology risk assessments for new and existing systems, vendors, services and IT processes.Identify control gaps, compliance risks and documentation deficiencies, and work with accountable owners to define appropriate remediation or risk treatment plans. Vendor and Third-Party Compliance Oversight * Support supplier and vendor compliance assessments for technology vendors, cloud service providers, SaaS platforms and GxP-relevant suppliers.Review supplier control evidence such as ISO certifications, SOC reports, validation documentation, security questionnaires, privacy documentation and contractual compliance requirements. Documentation, Training and Business Guidance * Own or contribute to IT Compliance policies, SOPs, work instructions, templates, guidance materials and evidence packs.Translate complex regulatory, security and quality requirements into practical, business-friendly guidance. Key Deliverables * Effective operation of the global IT Compliance function. * Timely, accurate and defensible IT responses to vendor, sponsor, client and regulatory audits. * Maintained and audit-ready ISMS records, evidence, registers and governance artefacts. * Successful support for ISO/IEC 27001:2022 certification, surveillance and recertification activities. * Clear compliance guidance for GxP systems, SaaS platforms, cloud services and technology projects. * Improved audit evidence reuse, response consistency and inspection readiness. * Well-maintained IT Compliance SOPs, work instructions, templates and control documentation.Measurable tracking of IT compliance risks, findings, corrective actions and continual improvement initiatives. ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)