Director, Data & AI Risk Management

AstraZeneca
Madrid, Spain
2 days ago
Apply on astrazeneca.eightfold.ai
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security Data Security Information Technology GXP

Job description

Here, the answers aren’t always available. So, you’ll need to bring a fearless, self-starter mindset to navigate uncharted territories. You’ll harness your ceaseless energy to discover and make the necessary connections with colleagues to shape the future and achieve maximum impact., We’re building a connected, end-to-end Enterprise AI engine - uniting data foundations, AI technology, process reinvention, and business-facing AI to accelerate results across the whole value chain. Success depends on being exceptional connectors: you’ll actively leverage existing capabilities, celebrate and promote reuse, export breakthrough ideas across geographies and functions, and obsess over scaling impact rather than building in isolation. If you thrive in high-collaboration environments where your role is to turn complex, cross-functional problems into reusable, enterprise-wide capabilities - and where the measure of success is adoption and scale, not just innovation - you’ll have the platform (and sponsorship) to make it real.

The Director, Data & AI Risk Management, leads and delivers enterprise risk management activities that help AstraZeneca identify, assess, govern, report, and reduce Data & AI risk.

The role provides practical risk advisory, consulting, governance, and risk appetite support across regulatory compliance, data protection, AI governance, and related risk domains.

Reporting to the Senior Director, Data & AI Risk Management, the Director partners across Data & AI Trust and Assurance and with business and enabling functions to translate complex risk and regulatory expectations into clear decisions, proportionate mitigations, and measurable improvements in risk posture.

The role also leads cross-functional projects and supports enterprise governance forums and Enterprise Risk Management reporting, enabling responsible and confident use of Data & AI at scale.

Typical Accountabilities

  • Provide trusted risk advisory, consulting, and risk appetite support across Data & AI risks, helping stakeholders make timely, proportionate, and well-informed decisions.

  • Provide governance and business analysis support across regulatory compliance, data protection, AI governance, and other Data & AI risk areas, translating complex requirements into clear risk positions, decisions, and actions.

  • Lead and/or project manage priority initiatives across Data & AI Trust and Assurance, irrespective of team boundaries, including Standards and Controls rollout and regulatory compliance programmes covering requirements such as the US Data Security Program, EU AI Act, European Health Data Space, and other emerging obligations.

  • Improve visibility of Data & AI risk posture by developing clear narratives, indicators, dashboards, and insights on material exposures, trends, mitigations, residual risk, and progress against appetite.

  • Engage business and functional stakeholders to build relationships and understand risk exposure, challenge the adequacy of mitigations, agree pragmatic remediation, and help drive residual risk and overall risk posture down.

  • Lead selected aspects of Data & AI risk aggregation, analysis, and reporting for Enterprise Risk Management, senior leadership, and governance bodies.

  • Facilitate risk assessments, workshops, and decision forums for complex or novel Data & AI use cases, balancing enablement, compliance, and protection of patients, the company, and its information and intellectual property.

  • Synthesize complex issues into concise, executive-ready narratives; anticipate stakeholder concerns; navigate ambiguity; and influence decisions in high-stakes forums.

  • Partner with Regulatory Intelligence, Legal, Compliance, Privacy, Cyber Risk, Enterprise Risk Management, Data Offices, and risk teams in R&D, Operations, Commercial, Enabling Units, and other business functions to align risk approaches and accountabilities.

  • Work across Data & AI Trust and Assurance teams to accomplish shared goals, resolve cross-cutting issues, and deliver integrated outcomes across policy, standards and controls, assurance, monitoring, risk, and regulatory readiness.

  • Identify opportunities to simplify and continuously improve Data & AI risk management processes, governance, reporting, and stakeholder experience while preserving effective oversight.

  • Promote a culture of responsible, compliant, and value-focused use of Data & AI, demonstrating AstraZeneca values in all interactions., Your wellbeing means a lot to us, and we’re here to support you through all of life’s ups and downs. That’s why we offer an unpaid leave policy, annual leave, reduced-hours timetables and a host of benefits, including a retirement plan, long service award, and health and travel insurance.

Requirements

Ready to make an impact in your career? If you’re passionate, growth-orientated and a true team player, we’ll help you succeed. Here are some of the skills and capabilities we look for., Seize ownership and excel with autonomy to enjoy the constant rush of ground-breaking discovery. Your ability to anticipate sudden shifts and adapt swiftly will prove critical as you make your mark in an environment that rewards initiative and resilience., Essential

  • Bachelor’s degree in business administration, Risk Management, Information/Data Science, Informatics, Computer Science, Economics, Law, or a related discipline, or equivalent relevant experience.

  • Significant experience in risk management, assurance, governance, regulatory compliance, or second-line oversight within a complex, global organisation.

  • Demonstrated experience assessing and managing data, technology, digital, and/or AI risks and translating complex issues into pragmatic business decisions.

  • Strong project leadership and project management capability, including delivery through cross-functional and matrixed teams, such as Regulatory Compliance, areas of organisational risk, AI governance, or related disciplines.

  • Experience providing risk advisory or consulting support, including risk appetite, mitigation, escalation, and risk acceptance discussions.

  • Working knowledge of relevant Data & AI regulatory and compliance requirements, such as the US Data Security Program, EU AI Act, European Health Data Space, GDPR, GxP, NIS2, or comparable frameworks.

  • Experience with governance forums, executive reporting, risk indicators, dashboards, or Enterprise Risk Management processes.

  • Strong business analysis, facilitation, and problem-solving skills, with the ability to structure ambiguity and establish clear ownership and actions. This includes working across domains such as regulatory compliance, data protection, AI governance, or related disciplines to translate requirements into clear risk positions, decisions, accountabilities, and actions.

  • Demonstrated experience developing risk reporting to support senior management decision-making.

  • Proven ability to build partnerships across Legal, Compliance, Privacy, Cyber Security, Enterprise Risk Management, Data Offices, technology, and business functions.

  • Excellent written and verbal communication, with the credibility to influence senior stakeholders and present concise, decision-oriented recommendations.

  • Strong collaboration, negotiation, and change leadership skills, with a practical, proportionate, and enablement-focused mindset.

Desirable

  • Master’s degree or advanced qualification in Business Administration, Risk Management, Information/Data Science, Informatics, Computer Science, Economics, Law, or a related discipline.

  • Experience in life sciences, healthcare, or another highly regulated industry.

  • Practical knowledge of ISO/IEC 42001, the NIST AI Risk Management Framework, or recognised enterprise risk and control frameworks.

  • Data, AI, privacy, compliance, audit, governance, or risk management education and professional certifications.

  • Experience implementing or assessing standards and controls and linking regulatory obligations, risks, controls, assurance, and reporting.

  • Knowledge of key pharmaceutical business processes across R&D, Operations, Commercial, and Enabling Units.

About the company

Why choose AstraZeneca Spain?

AstraZeneca Spain is a rising force in our global business. With headquarters in Madrid and our global hub in Barcelona, we’ve become an important international centre of excellence in the fight against critical disease. Boasting vibrant universities and business schools, the Barcelona ecosystem is a place where scientists can thrive. We attract a diverse workforce from across the globe, shining a beacon for innovation in a country that’s committed to clinical development.

We invite you to bring your talents to Barcelona where our respiratory medicine R&D and Global Marketing centre offers opportunities in R&D, IT, Commercial and HR. Or join us in Madrid and shape our growth in our BUs (Respiratory, Oncology & CVRM ), and a range of Corporate functions. Additionally, you can find sales roles throughout the country. Together, we’re contributing to a world-leading pipeline of therapeutics and delivering life-changing medicines to patients.

Who do we look for?

Calling all tech innovators, ownership takers, challenge seekers and proactive collaborators. At AstraZeneca Spain, breakthroughs born in the lab become transformative medicine for the world’s most complex diseases. Alongside technical expertise, colleagues have the resilience, energy and collaborative mindset to change lanes, work with different teams and start projects from scratch.

Here, diverse minds and bold disruptors can meaningfully impact the future of healthcare using cutting-edge technology. Whether you join us in Madrid or Barcelona, you can make a tangible impact within a global biopharmaceutical company that invests in your future. Join a talented global team that’s powering AstraZeneca to better serve patients every day., At AstraZeneca we’re dedicated to being a Great Place to Work. Where you are empowered to push the boundaries of science and unleash your entrepreneurial spirit. There’s no better place to make a difference to medicine, patients and society. An inclusive culture that champions diversity and collaboration, and always committed to lifelong learning, growth and development. We’re on an exciting journey to pioneer the future of healthcare.

When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That’s why we work, on average, a minimum of three days per week from the office. But that doesn’t mean we’re not flexible. We balance the expectation of being in the office while respecting individual flexibility., AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements., There are many things I enjoy when working at AstraZeneca, mainly the Speak up culture, the great colleagues that are in my teams, the great products that AstraZeneca provides to our patients and the challenging conversations I have around our medicines. Sales Representative Oslo, Norway

There are many things I enjoy when working at AstraZeneca, mainly the Speak up culture, the great colleagues that are in my teams, the great products that AstraZeneca provides to our patients and the challenging conversations I have around our medicines. See Thomas’s Story

Christine Recchio

Working at AstraZeneca has impacted my life in such a positive way. I now have an improved work-life balance through creating my own schedule and time management, I feel a balance that I didn’t have before. Sales Representative California, United States

Working at AstraZeneca has impacted my life in such a positive way. I now have an improved work-life balance through creating my own schedule and time management, I feel a balance that I didn’t have before. See Larry’s Story

Stephanie Ling

There are a lot of reasons why I enjoy working in AstraZeneca, my colleagues being one of them. My team members and the managers have provided a great deal of guidance in helping me to be more confident in my daily work. Sales Representative Petaling Jaya, Malaysia

There are a lot of reasons why I enjoy working in AstraZeneca, my colleagues being one of them. My team members and the managers have provided a great deal of guidance in helping me to be more confident in my daily work. See Stephanie’s Story

What we offer

We’re driven by our shared values of serving people, society and the planet. Our people make this possible, which is why we prioritise diversity, inclusivity, balance and sustainability. Discover what a career at AstraZeneca could mean for you., Diversity and inclusion are embedded in everything we do, and our different views, experiences and strengths enrich our culture. There’s no salary gap at AstraZeneca, and the number of female employees has increased by four per cent over the last three years. We’ve also made all positions fully accessible.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on astrazeneca.eightfold.ai
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

3:13 min

Core components of the internal Optimize ecosystem

Dominik Schneider Dominik Schneider · World Congress 2025

6:17 min

Understanding AI risk tiers and compliance obligations

Jaap Kersten Jaap Kersten +1 · World Congress 2024

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all