Director of Cyber Security Governance, Risk, and
hace 6 meses
Are you ready to be part of the future of healthcare? Can you think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you
Transform billions of patients’ lives through technology, data, and innovative ways of working. You’re disruptive, decisive, and transformative. Someone excited to use technology to improve patients’ health. We’re building a new health tech business - Evinova, a fully-owned subsidiary of AstraZeneca Group.
Evinova delivers market-leading digital health solutions that are science-based, evidence-led, and human experience-driven. Thoughtful risks and quick decisions come together to accelerate innovation across the life sciences sector. Be part of a diverse team that pushes the boundaries of science by digitally empowering a deeper understanding of the patients we’re helping. Launch pioneering digital solutions that improve the patients’ experience and deliver better health outcomes. Together, we have the opportunity to combine deep scientific expertise with digital and artificial intelligence to serve the wider healthcare community and create new standards across the sector.
**Key responsibilities include**:
- Develop and optimize the Evinova cyber security governance framework to ensure continued alignment with leading practices, regulatory obligations, and corporate insurability (e.g., NIST CSF, ISO 27001, EU / UK GDPR, HIPAA / HITRUST, SOC 2 Trust Services Criteria, etc.).
- Maintain cyber security policies, procedures, and standards to establish clear and actionable guidelines for cyber security controls, data protection, and incident response protocols. Additionally, maintain the cyber security Risk Register and Risk Exception handling process.
- Partner with the Quality and Compliance Team to ensure the effectiveness of engineering security practices, aligned with relevant standards, and fully documented in policies/procedures. Tracks and develops remediation strategies to ensure continued compliance with relevant regulations and audit requirements.
- Lead the identification, assessment, and mitigation of cyber security risks across Evinova and our digital products. Additionally, providing advisory-based perspectives to the CTO leadership team on best practices and appropriate technology solutions to align residual risk to the organizational risk appetite.
- Collaborate with internal collaborators to assess and manage cyber security risks associated with third-party vendors and service providers, ensuring contractual obligations and security controls are effectively implemented. Partner with Legal / Data Privacy to support Privacy Impact Assessments.
- Define and implement the Evinova Cyber Security and Awareness education program. Collaborates across all business functions and contractors to evangelize security best practices and ensure compliance with all Evinova information security policy requirements.
- Develop insightful and data-driven dashboard(s) articulating Evinova’s current cyber risk posture through the measurement of relevant Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and cyber trends (e.g., incidents, emerging risks, external interest areas).
- Drive continuous improvement initiatives to enhance the effectiveness and efficiency of the cyber security GRC program, leveraging feedback, metrics, and lessons learned. Actively collaborate with Evinova and AstraZeneca Group leadership to align and share best practices for cyber security, business continuity, and other related policies and procedures.
**Minimum Qualifications**:
- Bachelor's degree in Technology, Computer Science, Business Administration, or a related field.
- 8+ years of combined experience in Cyber GRC relevant domains such as Information Security Compliance, IT Risk Management, Third-Party Risk Management, and Information Assurance (preferably in a cloud-native organization).
- Prior experience providing GRC-related capabilities at a SaaS/cloud service provider.
- Experience in implementing, operating, and assessing GRC programs aligned to the NIST CSF and ISO 27001 frameworks.
- Hands-on experience with audit readiness, response, and remediation activities in support of external SOC2, and penetration testing-related engagements. Additionally, experience maintaining cyber-centric Risk Registers and Corrective Action Plans / Plans of Actions and Milestones (POA&Ms).
- Well-versed in Business Continuity and Disaster Recovery planning and performing third-party risk management due diligence reviews of technology service providers and external entities with persistent access to internal systems / sensitive data.
- Experience articulating the ISMS and supporting processes in the context of responding to third-party risk management questionnaires, and other external entities performing cyber security due diligence-focused inquiries (e.g.
-
Director of Cyber Security Operations
hace 5 meses
Barcelona, España AstraZeneca A tiempo completo**Location: Barcelona** Are you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to seek longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data and...
-
Cyber Security Director
hace 1 mes
Barcelona, Barcelona, España Gartner Careers A tiempo completoJob SummaryAs a Director of Cybersecurity and Risk Management at Gartner, you will be responsible for providing actionable advice to clients in resolving their mission-critical priorities by organizing and providing analysis on a variety of security issues that change on a daily basis.You will define our client's mission-critical priorities as: What should...
-
Cyber Security Risk Manager
hace 5 meses
Barcelona, España Launch Global A tiempo completo**Cyber Security Risk Manager - Contract 6 Months (with potential to extend to 2 years) - Barcelona** **Why this role might be of interest** The role has come about because the company, a highly successful and rapidly expanding international pharmaceutical business, is putting in place a brand new internal team to manage cyber security threats. Because of...
-
Cyber Security Risk Manager
hace 6 meses
Barcelona, España Launch Global A tiempo completo**Cyber Security Risk Manager - Contract 6 Months (with potential to extend to 2 years) - Barcelona** **Why this role might be of interest** The role has come about because the company, a highly successful and rapidly expanding international pharmaceutical business, is putting in place a brand new internal team to manage cyber security threats. Because of...
-
Cyber Security Governance Director
hace 1 semana
Barcelona, Barcelona, España Galderma A tiempo completoAbout the RoleWe are seeking an experienced Cyber Security Governance Manager to join our team at Galderma. In this role, you will be responsible for leading our Cyber Security Governance Team and implementing IT infrastructure and systems administration plans.Key ResponsibilitiesLead the Galderma Cyber Security Governance Team in implementing IT security...
-
Security Governance
hace 4 meses
Barcelona, España Dentsu A tiempo completoThe purpose of this role is to contribute to the ongoing development of client focused security initiatives, standards and compliance strategy.Provide information security support and advisory services to our Brands, for managing clients' security requirements, agreements and assessment programmes.The Security Governance Risk Analyst will be responsible for...
-
Cyber Security Director
hace 3 semanas
Barcelona, Barcelona, España Empresa reconocida A tiempo completoAbout the RoleWe are seeking a highly skilled Cyber Security Director to lead our information security program and ensure the confidentiality, integrity, and availability of our company's information assets. As a key member of our leadership team, you will be responsible for overseeing the development and implementation of our information security strategy,...
-
Security Governance
hace 4 meses
Barcelona, España Dentsu A tiempo completoThe purpose of this role is to contribute to the ongoing development of client focused security initiatives, standards and compliance strategy. Provide information security support and advisory services to our Brands, for managing clients' security requirements, agreements and assessment programmes. The Security Governance & Risk Analyst will be responsible...
-
Security Governance
hace 2 meses
Barcelona, España Dentsu A tiempo completoThe purpose of this role is to contribute to the ongoing development of client focused security initiatives, standards and compliance strategy.Provide information security support and advisory services to our Brands, for managing clients' security requirements, agreements and assessment programmes.The Security Governance & Risk Analyst will be responsible...
-
Senior Director Of Cyber Security
hace 4 semanas
Barcelona, España Astrazeneca A tiempo completoAre you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you!Transform billions of patients' lives through technology, data, and pioneering ways of...
-
Senior Director of Cyber Security
hace 6 meses
Barcelona, España AstraZeneca A tiempo completoAre you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data, and pioneering ways of...
-
Senior Director of Cyber Security
hace 4 semanas
Barcelona, España AstraZeneca A tiempo completoAre you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data, and pioneering ways of...
-
Senior Director Of Cyber Security
hace 5 meses
Barcelona, España Astrazeneca A tiempo completo.Are you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you!Transform billions of patients' lives through technology, data, and pioneering ways of...
-
Director of Cyber Security Architecture
hace 6 meses
Barcelona, España AstraZeneca A tiempo completoAre you ready to be part of the future of healthcare? Can you think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data, and innovative ways of working....
-
Security Governance
hace 6 meses
Barcelona, España Dentsu Aegis Network A tiempo completoThe purpose of this role is to contribute to the ongoing development of client focused security initiatives, standards and compliance strategy. Provide information security support and advisory services to our Brands, for managing clients’ security requirements, agreements and assessment programmes. The Security Governance & Risk Analyst will be...
-
Cyber Security Specialist
hace 1 semana
Barcelona, Barcelona, España Cyber Crime A tiempo completoAbout the Role: We are seeking a highly skilled Cyber Security Specialist to join our team in Barcelona. As a Cyber Security Specialist, you will work within our global Directory Services team providing technical expertise in both on-premises Active Directory and Cloud Services (Entra ID & AWS MSAD). This role is hands-on within an operational team providing...
-
Cyber Security Governance Lead
hace 4 semanas
Barcelona, Barcelona, España Galderma A tiempo completoAbout the RoleThis position is responsible for managing the Galderma Cyber Security Governance Team, overseeing the implementation of IT infrastructure and systems administration, and ensuring adherence to company policies and guidelines.Key Responsibilities:Lead the Cyber Security Governance Team in implementing security policies and proceduresDevelop and...
-
Manager, Information Security
hace 1 mes
Barcelona, España Clarivate Analytics A tiempo completo.Manager, Information Security - Governance, Risk, and ComplianceClarivate is searching for a Manager, Information Security – Governance, Risk, and Compliance to join our team. In this role you will be a part of the Governance, Risk and Compliance (GRC) function of the Information Security team at Clarivate, a dynamic team that works across the company at...
-
Governance, Risk And Compliance Consultant
hace 5 días
Barcelona, España Rockwell Automation A tiempo completoGovernance, Risk And Compliance ConsultantRockwell Automation – Barcelona, BarcelonaRockwell Automation is a global technology leader focused on helping the world's manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing...
-
Governance, Risk And Compliance Consultant
hace 6 días
Barcelona, España Rockwell Automation A tiempo completoGovernance, Risk And Compliance Consultant Rockwell Automation – Barcelona, BarcelonaRockwell Automation is a global technology leader focused on helping the world's manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing...