Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Assoc Dir, Information Security Governance Risk & Compliance

$179k - $212k

Les Laboratoires Servier

About Servier Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision. Role SummaryThe Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the Associate Director, Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk methodology, strategic priorities, and maturity roadmap. The role provides oversight of information security risk management, policy governance, compliance, third-party risk management, control assurance, audit readiness, and risk reporting while directing operational execution through subordinate managers, analysts, contractors, and service providers. This position partners closely with Global Information Security, IT, Legal, Privacy, Procurement, Quality, Internal Audit, and business stakeholders to ensure risks are identified, assessed, communicated, and managed in alignment with enterprise requirements. The role serves as the primary GRC advisor and enables risk-informed decision making by translating information security risk into business, operational, regulatory, and financial impact. This is a high visibility leadership role with the opportunity to build and scale a modern GRC capability aligned to Servier’s global cybersecurity strategy, enterprise risk expectations, regulatory obligations, and business growth.Primary ResponsibilitiesCyber Risk Management and GovernanceEstablish and lead the US information security risk management framework across the affiliateDefine risk assessment methodologies, risk taxonomy, scoring models, reporting standards, and escalation criteriaProvide oversight and challenge of risk assessments performed by the GRC teamEnsure information security risks are clearly defined, consistently assessed, and aligned to Group methodology and enterprise risk expectationsReview material risks, treatment recommendations, mitigation strategies, and risk acceptance proposals before escalationDrive risk-based prioritization of remediation activities, investment recommendations, and control improvement initiativesLocal Risk Coordinator and GRC Program LeadershipServe as the senior US GRC leader responsible for coordinating information security risk governance across the affiliateAct as the primary US liaison to Global Information Security for GRC-related risk, compliance, policy, and assurance activitiesEstablish governance routines, program cadences, reporting expectations, and execution standards for the US GRC functionEnsure alignment between US affiliate execution and Global risk management methodology, policy baselines, and governance expectationsEscalate material risks, systemic issues, overdue remediation, and governance concerns through US and Global governance channelsGovernance, Policy and Control AssuranceEstablish governance expectations for information security policies, standards, procedures, control requirements, and exception managementSponsor the local information security policy lifecycle, ensuring alignment with Global baselines, US business requirements, and regulatory obligationsDefine the control assurance approach used to evaluate control design, implementation, effectiveness, and maturityOversee control monitoring, compliance validation, gap analysis, and continuous improvement activitiesDefine and monitor KPIs and KRIs measuring policy adoption, control maturity, security posture, remediation progress, and governance effectivenessThird-Party Risk and Enterprise Risk IntegrationEstablish the strategic direction for third-party information security risk management across the US vendor ecosystemDefine governance requirements, risk acceptance criteria, assessment standards, and escalation paths for third-party engagementsPartner with Procurement, Legal, Privacy, IT, and business stakeholders to ensure vendor security risks are appropriately assessed and managedOversee integration of third-party security risk into enterprise risk management, procurement processes, contractual reviews, and business decision makingDrive cross-domain alignment across Information Security, IT, Legal, Privacy, Procurement, Quality, and business functionsAudit, Compliance and Assurance OversightOversee information security audit readiness across internal audits, external audits, regulatory engagements, and assurance activitiesEstablish governance over evidence collection, control validation, audit response, remediation tracking, and management reportingEnsure audit findings, compliance gaps, and control deficiencies are translated into clear risk treatment plans with defined owners, timelines, and measurable outcomesPartner with Internal Audit, Quality, Legal, Privacy, and Global Information Security to support assurance activities and regulatory expectationsExecutive Engagement and Cross-Functional InfluenceAct as a trusted advisor on information security governance, risk, compliance, and assurance mattersTranslate complex information security risks into business, operational, regulatory, financial, and reputational impactDeliver executive-level reporting on information security risk posture, governance maturity, compliance status, control effectiveness, and remediation progressSupport governance committees, leadership forums, business reviews, and strategic planning discussions with clear risk-based recommendationsRepresent US GRC priorities in Global information security and enterprise risk forums, influencing alignment where appropriateOrganizational Leadership and Capability BuildingLead and develop the US Information Security Governance Risk and Compliance functionManage GRC managers, analysts, contractors, consultants, managed service providers, and supporting resourcesDefine the GRC organizational structure, operating procedures, quality standards, workforce strategy, and capability development roadmapBuild scalable and repeatable GRC processes aligned to information security maturity objectives and organizational growthIdentify opportunities to improve efficiency through automation, process standardization, documentation quality, tooling, and operating model maturityEducation and Required SkillsMinimum of 8+ years of experience in information security GRC, IT risk management, cybersecurity, compliance, audit, security operations, or related disciplinesMinimum of 3+ years in a leadership role with responsibility for program ownership, people leadership, functional leadership, or management of managersBachelor’s degree preferred in Cybersecurity, Information Technology, Information Systems, Business, Risk Management, or a related fieldDeep expertise in information security risk frameworks and governance models, including NIST CSF 2.0, ISO 27001, PCI, SOX, FAIR, or similar methodologiesExperience leading policy governance, third-party risk management, compliance oversight, audit readiness, control assurance, and remediation governance programsStrong executive communication skills with the ability to influence senior stakeholders in a global, matrixed organizationRelevant certifications such as CISSP, CISM, CRISC, CISA, CGRC, FAIR, or equivalent preferredTravel and LocationOnsite in Boston preferred 1-2 days hybrid; Remote considered with occasional travel to BostonEstimated travel required: 5-10%Servier’s CommitmentServier is committed to modeling diversity, equity, and inclusion within the industry. We are dedicated to fostering an environment that maintains equitable treatment for all and we welcome applicants who are passionate, committed, and innovative individuals. We encourage candidates to apply to our open roles as we are always willing to consider experiences and skills beyond what is listed in the job description.All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.Salary RangeThe salary range for this role is $179,000-$212,000. An employee’s pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs. We may ultimately pay more or less than the posted range, and the range may be modified in the future. Employees in this position are also eligible for Short-Term and Long-Term incentive programs. Servier also offers a competitive and comprehensive benefits package that includes benefits such as medical, dental, vision, flexible time off (Servier provides unlimited sick time and flex time, and does not accrue time off), 401(k), life and disability insurance, recognition programs among other great benefits (all benefits are subject to eligibility requirements). For more information on our benefits, please visit this link.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Assoc Dir, Information Security Governance Risk & Compliance in Boston, MA vacancy
  • $225k - $337.5k

     ...transformation leader with deep expertise in automation, governance, and large-scale client onboarding, delivering...  ..., AIS platforms, GL/Oracle Financials, Corporate Information Security automation, Basel Risk & Compliance, and the Cloud Technology Stack—bringing strategic... 
    Suggested
    Full time
    Temporary work
    Work at office
    Flexible hours

    State Street Bank

    Quincy, MA
    4 days ago
  • $70k - $80k

     ...(CA), you will play a pivotal role securing our clients’ infrastructure, data and...  ...senior security leader, like a Chief Information Security Officer (CISO). We fill...  ...provide cybersecurity leadership in Governance, Risk, and Compliance (GRC) directly to our clients. You will... 
    Suggested
    Full time
    Work at office

    Fractional CISO

    Newton, MA
    2 days ago
  • $230k - $283k

     ...is actively recruiting for a Chief Risk Officer / Information Security Officer / Director of Internal Audit...  ...subordinates, the internal audit, compliance, and risk management activities of...  ...mitigation activities. Ensures that the governance, risk, compliance, and control... 
    Suggested
    Work at office

    Socket.dev

    Cambridge, MA
    1 day ago
  • $239.18k - $263.1k

     ...Director, Governance, Risk & Compliance – Fresenius Medical Care Lexington, Massachusetts (Remote) As Director of Governance, Risk & Compliance, you will manage Information Security Governance, Risk, and Compliance programs across global business units. You will... 
    Suggested
    Temporary work
    Remote work
    Work from home

    Fresenius Medical Care

    Lexington, MA
    5 days ago
  •  ...Risk Consulting - Risk Technology - Sap Grc & Security - Senior Consultant Location: New York Other locations...  ...rapid growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP...  ...degree in computer science, information systems, information security... 
    Suggested
    Shift work

    EY

    Boston, MA
    3 days ago
  • $110k - $315k

     ...OverviewThe position reports to the Chief Information Security Officer and leads the enterprise-wide technology risk and governance program. This role establishes the risk framework...  ...across Technology, Cyber Security, Compliance, Legal, and business, the role translates... 
    Full time
    Local area

    Arrowstreet Capital

    Boston, MA
    4 days ago
  • $130k - $170k

     ...mission to unlock human performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity...  ...assessments, exceptions management, SDLC reviews and security compliance process ownership. The role will partner closely... 
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    2 days ago
  • $147.4k

    Posting Description INFORMATION SECURITY MANAGER, The Massachusetts Green High Performance Computing Center (MGHPCC), to serve as the...  ...senior, hands-on role spans security architecture, risk management, compliance, and policy for a nationally recognized academic research... 
    Full time
    Visa sponsorship

    Massachusetts Institute of Technology

    Cambridge, MA
    5 days ago
  • $170k - $282.5k

     ...entity management and subsidiary governance to lead our Global Legal Entity Governance...  ...law and regulation, governance, compliance, finance, strategy, technology, risk management, and process...  ...judgment, and drive effective risk-informed decisions; Executive presence and... 
    Full time
    Temporary work
    Work at office
    Flexible hours

    State Street Bank

    Boston, MA
    3 days ago
  • $100k - $140k

     ...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology...  ...management,SDLC reviews and security compliance process ownership. The role...  ...and remediationBachelor’s degree in Information Security, Computer Science, Business... 
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    2 days ago
  •  ...evaluating frameworks and identifying risks. Enhance workflows and reporting...  ...investment decisions.Lead assessments of governance, compliance, and technology practices within...  ...accurate records and ensure adherence to information security standards.Monitor industry... 

    Green Key Resources

    Boston, MA
    4 days ago
  •  ...KAYAK, part of Booking Holdings, is seeking an Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team. This early‑career role develops skills in risk assessments, policy management, and control monitoring while modernizing GRC practices. The position... 
    Work at office
    3 days per week

    KAYAK

    Cambridge, MA
    2 days ago
  • $130k - $160k

     ...everything possible.The Senior Cybersecurity Risk Analyst is responsible for executing...  ...position is part of the Corporate Information Security and will be located as Remote. In this...  ..., vendor security, or related governance work.It would be a plus if you also possess... 
    Full time
    Remote work
    Work from home
    Flexible hours

    Danaher Corporation

    Boston, MA
    1 day ago
  • $155k - $195k

     ...lifestyle.WHOOP is seeking a Security Architect to help...  ...function within the Information Security organization....  ...establishing standards, governance, reusable design...  ...identify architectural risks, validate security controls...  ...regulatory and compliance requirements—including... 
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    2 days ago
  • $105.4k - $207.8k

     ...strengthen resilience, support compliance, and protect critical data....  ...that advance data governance, information protection, and regulatory...  ...Purview and adjacent Microsoft security and compliance technologies...  ...security posture and reduce risk. A successful candidate would... 
    Local area
    Visa sponsorship

    Deloitte

    Boston, MA
    4 days ago
  • $300k - $412.5k

     ...a senior operational leader.Risk, Regulatory & Control ExcellenceOwn...  ...risk, regulatory compliance, and control execution across...  ...Establish and maintain strong governance, issue management, and escalation...  ..., age, disability, genetic information, sex, sexual orientation,... 
    Full time
    Temporary work
    Local area
    Flexible hours

    State Street Bank

    Boston, MA
    3 days ago
  • $120k - $202.5k

     ...is seeking a Tech Operations Governance Lead to head oversight of...  ...excellence, resilience, and strong risk governance.The Lead will...  ...with Technology, Risk, Compliance, Operations, and business leadership...  ..., age, disability, genetic information, sex, sexual orientation,... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Boston, MA
    3 days ago
  • $156k - $234k

     ...exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure...  ...in developing and refining information security policies, standards and...  ...broader CISO vision amongst other governance, risk and compliance efforts. The STAR team is highly... 

    Klaviyo

    Boston, MA
    4 days ago
  • $118.3k - $207.4k

    Third‑Party IT Risk Manager is responsible for leading and modernizing...  ...’s risk appetite, security standards, and regulatory expectations...  ...with enterprise cyber risk governance.• Modernize TPITRM by...  ...degree in computer science, information security, management information... 
    Full time
    Contract work
    Work at office
    Shift work

    Wolters Kluwer

    Boston, MA
    4 days ago
  • $175k - $225k

     ...The Director, Investment Risk will establish a centralized investment risk function...  ...risk measurement, analytics, governance, reporting, and oversight across the firm...  ...professionals, Product Management, Legal & Compliance, Information Technology, and senior leadership to... 
    Work at office
    Local area
    Remote work
    1 day per week

    Gwkinvest

    Boston, MA
    3 days ago
  •  ...Job Description Job Description About Us Qualio is evolving into a category leader in Life Sciences GRC (Governance, Risk, and Compliance), and we need an exceptional product marketing leader to architect our market position and drive our evolution from QMS provider... 
    Contract work
    Temporary work
    Remote work
    Home office
    Flexible hours

    Qualio

    Boston, MA
    12 days ago
  • $171.1k - $236k

     ...to enterprise priorities and governance. Acts as a senior program leader...  ..., dependencies, timelines, risk mitigation). Ensure outcomes...  ...stakeholders, to drive alignment, inform decision-making, and ensure...  ...AI governance, risk, and compliance frameworks. Operationalize responsible... 
    Full time
    Part time
    Work at office

    Threadneedle group

    Boston, MA
    5 days ago
  •  ...WHOOP, based in Boston, MA, seeks a Governance, Risk, and Compliance Analyst II to lead day-to-day GRC operations for AI and risk management in a...  ...-growing environment. This role collaborates with Legal, Security, Product, and other teams to advance compliance objectives... 

    WHOOP

    Boston, MA
    4 days ago
  • $120k - $202.5k

     ...establish world-class operational governance, resilience, and...  ...improvement across cyber security data, analytics, and AI platforms...  ..., Security Operations, Risk, Audit, and Compliance teams to improve...  ...govern quality management and information security management practices... 
    Full time
    Temporary work
    Work at office
    Local area
    Flexible hours
    Shift work
    2 days per week

    State Street Bank

    Boston, MA
    4 days ago
  • $120k - $202.5k

     ...organization in Global Cyber Security (GCS). This role will lead...  ...the language of controls, risk, and compliance, let's talk. Financial services...  ...-level reporting and governance.What we valueThese skills will...  ...in Computer Science, Information Security, Engineering, Business... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Boston, MA
    1 day ago
  • $120k - $202.5k

     ...Management’s (IM) Business & Technology Risk and Resilience (BTRR) team is first line...  ...years of experience in operational risk, compliance or audit with a focus on risk assessment...  ...and resolve conflicts; ability to make informed, risk optimized decisions under time pressureDemonstrated... 
    Full time
    Temporary work
    Remote work
    Flexible hours

    State Street Bank

    Boston, MA
    3 days ago
  • A leading technology recruitment agency is seeking an AI Risk & Compliance Analyst to perform compliance reviews and risk assessments of AI...  ...leadership. This role offers the opportunity to shape AI governance practices and monitor evolving regulations, making a tangible... 

    Optomi

    Boston, MA
    2 days ago
  •  ...Cybersecurity Analyst to support security operations, risk management, governance initiatives, and security program...  ...documentation. Support governance, risk, and compliance initiatives across the...  ...of experience in cybersecurity, information security, risk management, or related... 

    Madison-Davis, LLC

    Boston, MA
    5 days ago
  •  ...About the Role The Company is seeking a General Counsel & Chief Legal Officer to serve as its primary advisor on governance, risk management, compliance, and legal affairs. This senior executive role is pivotal in providing strategic legal leadership, overseeing... 

    Confidential

    Boston, MA
    4 days ago
  •  ...Analytics Travelers Enterprise Catastrophe Risk Management is seeking a Senior Manager to...  ...team. This team provides enterprise governance, analytical insight, and decision support...  ...multivariate analyses) to develop views of risk and inform pricing decisions. In this role, you will... 
    Local area

    Travelers

    Boston, MA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Assoc Dir, Information Security Governance Risk & Compliance. Be the first to apply!