Director of Cyber Security Governance, Risk, and

hace 1 semana


Barcelona, España AstraZeneca A tiempo completo

Are you ready to be part of the future of healthcare? Can you think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you

Transform billions of patients’ lives through technology, data, and innovative ways of working. You’re disruptive, decisive, and transformative. Someone excited to use technology to improve patients’ health. We’re building a new health tech business - Evinova, a fully-owned subsidiary of AstraZeneca Group.

Evinova delivers market-leading digital health solutions that are science-based, evidence-led, and human experience-driven. Thoughtful risks and quick decisions come together to accelerate innovation across the life sciences sector. Be part of a diverse team that pushes the boundaries of science by digitally empowering a deeper understanding of the patients we’re helping. Launch pioneering digital solutions that improve the patients’ experience and deliver better health outcomes. Together, we have the opportunity to combine deep scientific expertise with digital and artificial intelligence to serve the wider healthcare community and create new standards across the sector.

**Key responsibilities include**:

- Develop and optimize the Evinova cyber security governance framework to ensure continued alignment with leading practices, regulatory obligations, and corporate insurability (e.g., NIST CSF, ISO 27001, EU / UK GDPR, HIPAA / HITRUST, SOC 2 Trust Services Criteria, etc.).
- Maintain cyber security policies, procedures, and standards to establish clear and actionable guidelines for cyber security controls, data protection, and incident response protocols. Additionally, maintain the cyber security Risk Register and Risk Exception handling process.
- Partner with the Quality and Compliance Team to ensure the effectiveness of engineering security practices, aligned with relevant standards, and fully documented in policies/procedures. Tracks and develops remediation strategies to ensure continued compliance with relevant regulations and audit requirements.
- Lead the identification, assessment, and mitigation of cyber security risks across Evinova and our digital products. Additionally, providing advisory-based perspectives to the CTO leadership team on best practices and appropriate technology solutions to align residual risk to the organizational risk appetite.
- Collaborate with internal collaborators to assess and manage cyber security risks associated with third-party vendors and service providers, ensuring contractual obligations and security controls are effectively implemented. Partner with Legal / Data Privacy to support Privacy Impact Assessments.
- Define and implement the Evinova Cyber Security and Awareness education program. Collaborates across all business functions and contractors to evangelize security best practices and ensure compliance with all Evinova information security policy requirements.
- Develop insightful and data-driven dashboard(s) articulating Evinova’s current cyber risk posture through the measurement of relevant Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and cyber trends (e.g., incidents, emerging risks, external interest areas).
- Drive continuous improvement initiatives to enhance the effectiveness and efficiency of the cyber security GRC program, leveraging feedback, metrics, and lessons learned. Actively collaborate with Evinova and AstraZeneca Group leadership to align and share best practices for cyber security, business continuity, and other related policies and procedures.

**Minimum Qualifications**:

- Bachelor's degree in Technology, Computer Science, Business Administration, or a related field.
- 8+ years of combined experience in Cyber GRC relevant domains such as Information Security Compliance, IT Risk Management, Third-Party Risk Management, and Information Assurance (preferably in a cloud-native organization).
- Prior experience providing GRC-related capabilities at a SaaS/cloud service provider.
- Experience in implementing, operating, and assessing GRC programs aligned to the NIST CSF and ISO 27001 frameworks.
- Hands-on experience with audit readiness, response, and remediation activities in support of external SOC2, and penetration testing-related engagements. Additionally, experience maintaining cyber-centric Risk Registers and Corrective Action Plans / Plans of Actions and Milestones (POA&Ms).
- Well-versed in Business Continuity and Disaster Recovery planning and performing third-party risk management due diligence reviews of technology service providers and external entities with persistent access to internal systems / sensitive data.
- Experience articulating the ISMS and supporting processes in the context of responding to third-party risk management questionnaires, and other external entities performing cyber security due diligence-focused inquiries (e.g.



  • Barcelona, España NDT Global A tiempo completo

    A leading diagnostics solutions provider based in Barcelona is seeking a Cyber Security Specialist to enhance its governance, risk management, and compliance programs. The ideal candidate should have a Bachelor's degree in Cyber Security or related fields, along with a minimum of 5 years of experience in cybersecurity functions. The role involves...


  • Barcelona, España NDT Global A tiempo completo

    A leading diagnostics solutions provider based in Barcelona is seeking a Cyber Security Specialist to enhance its governance, risk management, and compliance programs. The ideal candidate should have a Bachelor's degree in Cyber Security or related fields, along with a minimum of 5 years of experience in cybersecurity functions. The role involves...


  • Barcelona, España Technip Energies A tiempo completo

    A global technology and engineering company is seeking a Head of Cyber Security Program Governance in Barcelona. The role involves managing a comprehensive cybersecurity program, overseeing policy governance, and leading a team of experts. Candidates must have over 10 years of experience in information security and a preferred degree in Cyber Security or...


  • Barcelona, España Technip Energies A tiempo completo

    Be part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting‑edge solutions to solve real‑world energy problems. About us Technip Energies is a global technology and engineering powerhouse. With leadership positions in LNG, hydrogen, ethylene, sustainable chemistry, and CO2 management, we are...


  • Barcelona, España Technip Energies A tiempo completo

    Be part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting-edge solutions to solve real-world energy problems. About us: Technip Energies is a global technology and engineering powerhouse. With leadership positions in LNG, hydrogen, ethylene, sustainable chemistry, and CO2 management, we are...


  • Barcelona, España AstraZeneca A tiempo completo

    Are you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data, and pioneering ways of...


  • Barcelona, España AstraZeneca A tiempo completo

    Are you ready to be part of the future of healthcare? Can you think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data, and innovative ways of working....

  • Security Governance

    hace 4 días


    Barcelona, España Dentsu Aegis Network A tiempo completo

    The purpose of this role is to contribute to the ongoing development of client focused security initiatives, standards and compliance strategy. Provide information security support and advisory services to our Brands, for managing clients’ security requirements, agreements and assessment programmes. The Security Governance & Risk Analyst will be...


  • Barcelona, España NDT Global A tiempo completo

    About NDT GlobalNDT Global is the leading provider of inline diagnostic solutions, advanced data insights, and integrity management services that safeguard energy‑sector infrastructure. The company is recognized for its expertise in both ultrasonic inspection technologies — such as Pulse Echo, Pitch‑and‑Catch, Phased Array, and Acoustic Resonance...

  • Cyber Security Specialist

    hace 2 semanas


    Barcelona, España NDT Global A tiempo completo

    About NDT Global NDT Global is the leading provider of inline diagnostic solutions, advanced data insights, and integrity management services that safeguard energy-sector infrastructure. The company is recognized for its expertise in both ultrasonic inspection technologies — such as Pulse Echo, Pitch-and-Catch, Phased Array, and Acoustic Resonance (ART...