Senior Director- Global Cyber Compliance
$157.5k - $231kEli Lilly
At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism. We give our best effort to our work, and we put people first. We're looking for people who are determined to make life better for people around the world.
Lilly is seeking a Senior Director of Global Cyber Compliance to lead the transformation of our compliance function into a high-performing, AI-enabled, risk-responsive program that measurably reduces regulatory risk across Lilly's global technology environment. You will lead the strategy and execution across a complex, multi-framework regulatory landscape-including FDA 21 CFR Part 11, GxP, NIS2, ISO 27001, SOC 2, HIPAA, CCPA, PIPL/CSL/DSL, and emerging AI governance requirements-while ensuring every compliance decision is anchored to Lilly's threat-based cyber program. You will bring the technical credibility to challenge the status quo, the platform acumen to automate compliance at scale through LogicGate Risk Cloud and AI-augmented workflows, the operational leadership to build and develop a global compliance team. Four converging forces demand compliance leadership in global pharma:- Regulatory acceleration - NIS2, FDA cybersecurity guidance for digital health and manufacturing, the CCPA Cybersecurity Audit Rule, the DoJ Data Rule, Chinese regulations (PIPL/CSL/DSL), and emerging AI governance mandates are creating a multi-jurisdictional compliance surface that legacy, manual processes cannot scale to address.
- Threat landscape maturity - Pharma IP, clinical trial data, OT/manufacturing systems, and drug supply chains are high-value adversary targets. Compliance not anchored to threats creates false assurance and misallocates resources.
- AI and automation imperative - Manual evidence collection, spreadsheet-based control tracking, and static policy inventories are operationally unsustainable. The next-generation compliance function requires AI-augmented workflows, automated control testing, and intelligent risk quantification delivered through a modern GRC platform.
- Global scale and complexity - Lilly's operating footprint spans EU, US, and APAC regulatory regimes simultaneously. A single-jurisdiction compliance approach is insufficient; this role requires an strong leader who can orchestrate compliance across manufacturing, research, and commercial technology environments at global scale.
- Define and lead the global cyber compliance program, establishing a clear approach that transitions the function from reactionary audits and inspections toward continuous, risk-responsive, program-aligned assurance.
- Set the vision and drive execution for AI, automation and GRC platform capabilities to accelerate compliance delivery, reduce manual overhead, and improve compliance outcomes.
- Own and evolve Lilly's multi-framework compliance program spanning FDA 21 CFR Part 11, GxP, ISO 27001, SOC 2, NIS2, HIPAA, CCPA, PIPL/CSL/DSL, and emerging AI/ML governance requirements across global manufacturing, research, and commercial technology environments.
- Develop scope definitions for security controls and regulatory requirements that reduce task-driven overhead through technical innovation including AI and automation.
- Maintain a current-state, executive-ready view of how Lilly's cyber control environment satisfies each applicable regulatory framework, clearly mapping satisfied obligations and characterizing gaps with relevant regulatory risk analysis.
- Drive effort to create and sustain inspection-ready documentation, evidence packages, and response protocols enabling confident engagement with authorities, ISO auditors, and other regulators globally with minimal lead time.
- Develop deep working knowledge of how relevant regulatory bodies operate-their inspection methodologies, documentation expectations, finding classification frameworks, and how cyber evidence is evaluated, so preparation is proactive rather than reactive.
- Translate regulatory gap analysis into prioritized, risk-ranked remediation roadmaps that leadership can act on, with clear articulation of residual risk where full remediation is not immediately feasible.
- Serve as Lilly's primary internal and external subject-matter authority on cyber regulatory interpretation, informing program teams, platform owners, and business leaders on how new initiatives or technology changes affect compliance posture.
- Serve as the service owner for the LogicGate Risk Cloud compliance module, driving object hierarchy design, workflow automation, integration architecture, and adoption.
- Champion and deliver AI-augmented compliance capabilities including policy intelligence, automated evidence collection, and natural language advisory tooling that enables teams to self-serve compliance guidance at speed.
- Define the target state for compliance automation: continuous control testing, automated regulatory change monitoring, and real-time risk dashboards replacing manual audit cycles.
- Design and implement lightweight, scalable compliance processes that eliminate bottlenecks and drive operational efficiency across security and compliance functions.
- Build data pipelines that consolidate compliance, security, and operational metrics from diverse sources into actionable, executive-ready reporting.
- Develop predictive analytics capabilities that forecast compliance risk, resource requirements, and audit readiness posture.
- Implement data governance frameworks ensuring compliance data quality, consistency, and accessibility across global security operations.
- Apply knowledge of Lilly's cyber control environment and established frameworks to validate that control design satisfies applicable regulatory requirements.
- Own and mature exception management processes, documenting control intensity adjustments based on validated compensating controls, risk context, and business justification.
- Collaborate with Cyber service areas including Programs, Platforms, Operations, and M&A Cyber Integration to embed compliance into security operations rather than treating it as a parallel track.
- Define and own outcome-based regulatory effectiveness, operational efficiency, and program maturity, replacing activity metrics with measures that demonstrate business value.
- Communicate compliance posture, regulatory trends, and program effectiveness to executive cyber leadership in clear, concise language.
- Represent Lilly Cybersecurity's compliance function in cross-functional forums and external regulatory interactions, building trust and credibility with partners across Legal, Quality, Finance, and the business.
- Define team structure, roles, and operating model to support delivery across multiple concurrent regulatory frameworks and geographies.
- Drive cross-functional alignment with Legal, Quality, Privacy, Internal Audit, and Regulatory Affairs-ensuring compliance activities are integrated, non-duplicative, and defensible under regulatory and third-party scrutiny.
- Lead the view - you maintain a clear, current-state map of which regulatory obligations are satisfied by existing controls and where gaps require attention, so leadership is never surprised by an audit finding or regulatory inquiry.
- Lead through transformation - you move the compliance function from reactive and manual to proactive, automated, and data-driven, with measurable gains in efficiency and regulatory quality.
- Establish the team - you hire, develop, and retain compliance talent who grow their regulatory expertise, earn partner trust, and deliver outcomes beyond their individual scope.
- Drive platform adoption - LogicGate Risk Cloud becomes the system of record for compliance, with teams self-serving compliance data and manual processes deprecated.
- Lead with data - you replace activity-based reporting with outcome-based indicators that demonstrate regulatory effectiveness and operational efficiency in business terms.
- Instill trust across the enterprise - Legal, Quality, Audit, and business collaborators see Cyber Compliance as a strategic partner that enables speed, not a gatekeeping function that creates friction.
- Stay ahead globally - NIS2, FDA cyber guidance, AI governance, DoJ Bulk Data Rule, PIPL/CSL/DSL, and other emerging requirements are anticipated and addressed proactively before they become reactive remediation efforts.
- Bachelor's degree in Information Security, Computer Science, Risk Management, Operations Research, or related field
- 12+ years of dynamic experience in cybersecurity compliance, risk management, GRC, or data operations roles within complex, global technology environments.
- Experience designing and operating multi-framework compliance programs that prioritize controls based on risk rather than static regulatory checklists.
- Hands-on experience implementing or operating a modern GRC platform (LogicGate, ServiceNow GRC, Archer) at enterprise scale.
- Experience in highly regulated, multinational environments with demonstrated regulatory engagement, inspection support, and audit management success (FDA, EMA, ISO, NIS2, or equivalent).
- Qualified applicants must be authorized to work in the United States on a full-time basis. Lilly will not provide support for or sponsor work authorization or visas for this role, including but not limited to F-1 CPT, F-1 OPT, F-1 STEM OPT, J-1, H-1B, TN, O-1, E-3, H-1B1, or L-1.
- One or more certifications required or to be obtained within 12 months of hire: CISSP, CISA, CRISC, CISM, or equivalent advanced cybersecurity certification.
- Advanced degree (MBA, MS) in a relevant field preferred.
- Working knowledge of how FDA, EMA, NIS2 competent authorities, and ISO certification bodies conduct cybersecurity-related inspections-including documentation expectations, finding classification, and evidence evaluation criteria
- Demonstrated track record redefining a compliance function from reactive and manual to proactive, AI-augmented, and platform-enabled-with measurable efficiency and quality improvements
- Experience performing structured regulatory gap analysis: mapping existing control environments to regulatory requirements, quantifying residual risk, and communicating findings to executive audiences
- Experience operating in multinational pharma, medtech, or life sciences environments across EU, US, and APAC regulatory regimes concurrently
- Familiarity with GxP computer system validation (CSV), 21 CFR Part 11 electronic records/signatures, and audit trail requirements in pharmaceutical or life sciences technology contexts
- Track record of building and presenting executive-ready compliance risk dashboards and reporting
- Knowledge of cybersecurity frameworks and their application to control design and regulatory mapping
- Experience with M&A cybersecurity due diligence and integrating compliance programs across acquired entities at global scale
- Experience with AI/ML governance frameworks and AI risk management (NIST AI RMF, EU AI Act implications for pharma)
- Shown ability to build, develop, and retain high-performing compliance teams-including coaching members through their first regulatory engagement or audit cycle
- Proficiency with GRC automation, workflow configuration, and compliance-as-code concepts; experience with LogicGate Risk Cloud a strong plus
- Advanced proficiency in data analytics tools (Python, R, SQL, Tableau, Power BI) and experience building automated reporting pipelines
- Understanding of OT/ICS security (NIST 800-82, IEC 62443) in pharmaceutical manufacturing or critical infrastructure contexts
- Experience with workflow automation platforms and data pipeline technologies in a compliance or security operations context
- Familiarity with third-party risk management, vendor security assessment programs, and supply chain compliance considerations
- Familiarity with AI self-service advisory tooling or cybersecurity chatbot capabilities in a compliance context
$157,500 - $231,000 Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly's compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees. #WeAreLilly
$130k - $150k
...Senior Manager, Global Technical Support Smarsh empowers its customers to manage risk and unleash... ...on Smarsh every day to help them spot compliance, legal or reputational risks in 80+... ...geographies. ~ Industry experience with Cyber Security products is beneficial. ~...CyberSeniorLocal area- ...Director / Senior Director, Demand Generation and Integrated Marketing... ...centralized, data-driven Mobile Cyber Defense Automation platform,... ...accelerate delivery, guarantee compliance, and leverage automation to... ..., and mobile businesses globally. Today, Appdome's customers...CyberSenior
$91.32k - $125.56k
...Job Description: In this role, the Global IT Audit Senior Manager - Cyber Security & Data Privacy will oversee complex-level professional IT internal... ...as a thought-partner for the Global IT Audit Associate Director in preparing audit strategy for other technology audit...CyberSenior$120k - $200k
...Canada is seeking a strategic Senior Manager, Organizational... ...Management & Communications (Global Security) thought leader and... ...business leaders, IT operations, compliance, security teams), tailored to... ...compliance, risk management, and/or cyber program management ~5+...CyberSeniorFull timeFlexible hours$232k - $262k
...Director/Senior Director, Global Medical Information & Operations Stoke Therapeutics is seeking an experienced and hands-on Medical Information... ..., workflows, and governance in partnership with Legal, Compliance, Pharmacovigilance, and Clinical Lead development and...SeniorTemporary workRemote work$110k - $135k
A leading global technology firm is seeking a Human Resources Manager based in Honolulu, Hawaii. The successful candidate will have over... ..., and will be responsible for executing HR policies, ensuring compliance with laws, and supporting HR staff. This role offers a salary...Senior$91.7k - $212.5k
...We are seeking an experienced HR Business Partner to join our global gaming organization. This role will serve as a strategic partner... ...compensation adjustment based on the company C&B policy. - Ensure compliance with employment laws and regulations across multiple...SeniorRemote workOverseasRelocation package- ...lights on. We're looking for a senior cybersecurity leader to step... ...for cybersecurity and compliance across APS, with accountability... ...leadership and the Board of Directors, translating risk into the business... .... Deep fluency in cyber risk across IT and OT, with real...CyberSeniorPermanent employmentFor contractorsLocal areaWork from homeHome office
$120.5k - $223.5k
...solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Senior Manager Global Payroll Operations Job Code: 33999 Job... ...of international payroll processes, compliance requirements, and a proven ability to manage...CyberSeniorWork at officeLocal areaRemote workFlexible hours$161.5k - $184.3k
...HR Business Partner- Senior Manager- Global Payments Network Are you interested in joining a team of best-in-class HR consulting leaders... ...including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One...SeniorFull timePart timeCasual workLocal area- ...Senior Principal Human Resources Business Partner (HRBP) Herndon... ...in Information Warfare, Cyber Operations, Operational Security... ...organization. Reporting to the Senior Director of HR, this role partners... ...consistency, efficiency, and compliance across all investigations...CyberSeniorWork at officeRemote work
$84k - $156k
...space, air, land, sea and cyber domains in the... ...Title: Specialist, Trade Compliance Job Code: 35026 Job... ...is an agile global aerospace and defense... ...is actively seeking a Senior Specialist, Trade Technical... ...CCATs) for submission to Directorate of Defense Trade Controls...CyberSeniorWork experience placementWork at officeLocal areaFlexible hours$226.19k - $292.71k
...Senior Director - U.S. Ethics & Compliance Advisor (HIV) At Gilead, we're creating a healthier world for all people. For more than 35 years, we've tackled... ...related to data privacy, information security, cyber laws, industry codes. Support compliance-related incident...CyberSenior$111.2k - $126.9k
...Senior Associate, Product Manager - Global Enterprise Affairs (Data & AI Platforms) Product Management at Capital One is a booming, vibrant craft that... ...disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital...SeniorFull timePart timeLocal area- ...unified payments and financial platform for global businesses. Powered by our unique... ...next. About the team The Regulatory & Compliance team helps Airwallex grow responsibly as... ...environment. What you'll do This is a senior global leadership role responsible for building...SeniorFull timeWorldwide
$139k - $261.15k
...Senior Global Total Rewards Operations & Project Manager We're looking for a strategic and execution-focused Senior Global Total Rewards... ...annual cycles (e.g., compensation planning, benefits cycles, compliance initiatives) Ensure team delivers on seamless day-to-day...SeniorTemporary workLocal areaWorldwide- ...operations, DevSecOps, incident response, and cyber defense—enabling secure collaboration... ...more, visit Mattermost is seeking a Senior Technical Account Manager (TAM) – a customer... ...hybrid, and air‑gapped environments. Ensure compliance alignment with relevant European and...CyberSeniorLocal areaRemote work
$88k - $164k
...solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Senior Specialist, HR Business Partner Job Code: 3... ...for additional career opportunities In compliance with pay transparency requirements, the salary...CyberSeniorLocal areaRelocationFlexible hours$88k - $164k
...technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: HR... ...resolutions. Experience in a manufacturing environment. In compliance with pay transparency requirements, the salary range for this...CyberSeniorLocal areaFlexible hours$135k - $180k
...Rentokil family of companies, the global leader in Pest Control and... ...the planet."OverviewThe Senior Manager, HR Global Services &... ...Partnering closely with the Senior Director, HR Operations &... ...services - moving beyond SLA compliance to measure what actually matters...SeniorFull timePart timeWork at officeLocal areaImmediate start$213.86k - $318.27k
...Senior Director, HR Business Partner Acrisure is a global Fintech leader that combines the best of humans and high tech to... ...including Insurance, Reinsurance, Cyber Services, Mortgage Origination... ...guidance on employee relations, compliance, and risk-related matters, demonstrate...CyberSeniorImmediate startFlexible hours$177k - $308k
At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them,...SeniorFull timeFlexible hours- Tevapharm is seeking a Sr. Director, Associate General Counsel, Transactions, to support Business Development and Alliance Management... ...candidate will also support M&A activities and manage contractual compliance while enhancing internal and external collaboration. The...Senior
- A global cybersecurity firm is seeking a Senior Technical Product Manager to shape the future of their Core Protection Technologies. You will define product... ...that enhance Malwarebytes’ ability to counter modern cyber threats. This role combines security research and...CyberSenior
- ...enterprises’ external attack surface from cyber risks and increases security team... ...ensures that they reach the right team. Global leaders including BlackRock, Infosys, Sompo... ...PositionLocation: US (East coast/TOLA ?)As a Senior Customer Success Manager, you’ll be a go-...CyberSeniorWorldwide
- ...A leading risk management firm is seeking a Senior Manager for their Cyber & Data Resilience Advisory team. This role involves leading global cyber operations and advisory projects, developing comprehensive reports, and fostering client relationships. The ideal candidate...CyberSenior
- ...The Sr. Director, Cybersecurity Architecture is the senior leader responsible for enterprise cybersecurity architecture... ...Cybersecurity professionals in support of a Global Fortune 200 company. Own the... ...detect, respond and recover from Cyber and Cyber related incidents....CyberSeniorWork experience placementRemote work
- ...technology and cybersecurity is seeking a Senior Cyber Security Engineer in North Carolina.... ...evaluate controls, and collaborate on compliance initiatives. The ideal candidate will have... ...projects within a dynamic environment. #J-18808-Ljbffr ManpowerGroup Global, Inc.CyberSenior
- ...Senior Managing Counsel, Privacy & Cybersecurity About the Company... ..., and health data compliance. Industry Medical Devices Type... ...legal response to security and cyber events. Applicants must have... ...and a strong understanding of global data privacy and AI laws. The...CyberSenior
- ...information security program, the full-time Senior Information Security Manager will manage security operations, ensure compliance with global cybersecurity regulations, and lead... ...activities Serve as the operational owner for Cyber Resilience Act readiness, integrating...CyberSeniorFull timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director- Global Cyber Compliance. Be the first to apply!
- associate director regulatory affairs cmc United States
- customs compliance manager United States
- regulatory reporting manager United States
- sox compliance manager United States
- assistant director compliance United States
- regulatory manager United States
- senior regulatory manager United States
- license compliance manager United States
- regulatory product manager United States
- manager regulatory affairs United States

