Director of Cyber Security Governance, Risk, and

hace 2 semanas


Barcelona, España AstraZeneca A tiempo completo

Are you ready to be part of the future of healthcare? Can you think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you

Transform billions of patients’ lives through technology, data, and innovative ways of working. You’re disruptive, decisive, and transformative. Someone excited to use technology to improve patients’ health. We’re building a new health tech business - Evinova, a fully-owned subsidiary of AstraZeneca Group.

Evinova delivers market-leading digital health solutions that are science-based, evidence-led, and human experience-driven. Thoughtful risks and quick decisions come together to accelerate innovation across the life sciences sector. Be part of a diverse team that pushes the boundaries of science by digitally empowering a deeper understanding of the patients we’re helping. Launch pioneering digital solutions that improve the patients’ experience and deliver better health outcomes. Together, we have the opportunity to combine deep scientific expertise with digital and artificial intelligence to serve the wider healthcare community and create new standards across the sector.

**Key responsibilities include**:

- Develop and optimize the Evinova cyber security governance framework to ensure continued alignment with leading practices, regulatory obligations, and corporate insurability (e.g., NIST CSF, ISO 27001, EU / UK GDPR, HIPAA / HITRUST, SOC 2 Trust Services Criteria, etc.).
- Maintain cyber security policies, procedures, and standards to establish clear and actionable guidelines for cyber security controls, data protection, and incident response protocols. Additionally, maintain the cyber security Risk Register and Risk Exception handling process.
- Partner with the Quality and Compliance Team to ensure the effectiveness of engineering security practices, aligned with relevant standards, and fully documented in policies/procedures. Tracks and develops remediation strategies to ensure continued compliance with relevant regulations and audit requirements.
- Lead the identification, assessment, and mitigation of cyber security risks across Evinova and our digital products. Additionally, providing advisory-based perspectives to the CTO leadership team on best practices and appropriate technology solutions to align residual risk to the organizational risk appetite.
- Collaborate with internal collaborators to assess and manage cyber security risks associated with third-party vendors and service providers, ensuring contractual obligations and security controls are effectively implemented. Partner with Legal / Data Privacy to support Privacy Impact Assessments.
- Define and implement the Evinova Cyber Security and Awareness education program. Collaborates across all business functions and contractors to evangelize security best practices and ensure compliance with all Evinova information security policy requirements.
- Develop insightful and data-driven dashboard(s) articulating Evinova’s current cyber risk posture through the measurement of relevant Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and cyber trends (e.g., incidents, emerging risks, external interest areas).
- Drive continuous improvement initiatives to enhance the effectiveness and efficiency of the cyber security GRC program, leveraging feedback, metrics, and lessons learned. Actively collaborate with Evinova and AstraZeneca Group leadership to align and share best practices for cyber security, business continuity, and other related policies and procedures.

**Minimum Qualifications**:

- Bachelor's degree in Technology, Computer Science, Business Administration, or a related field.
- 8+ years of combined experience in Cyber GRC relevant domains such as Information Security Compliance, IT Risk Management, Third-Party Risk Management, and Information Assurance (preferably in a cloud-native organization).
- Prior experience providing GRC-related capabilities at a SaaS/cloud service provider.
- Experience in implementing, operating, and assessing GRC programs aligned to the NIST CSF and ISO 27001 frameworks.
- Hands-on experience with audit readiness, response, and remediation activities in support of external SOC2, and penetration testing-related engagements. Additionally, experience maintaining cyber-centric Risk Registers and Corrective Action Plans / Plans of Actions and Milestones (POA&Ms).
- Well-versed in Business Continuity and Disaster Recovery planning and performing third-party risk management due diligence reviews of technology service providers and external entities with persistent access to internal systems / sensitive data.
- Experience articulating the ISMS and supporting processes in the context of responding to third-party risk management questionnaires, and other external entities performing cyber security due diligence-focused inquiries (e.g.



  • barcelona, España NDT Global A tiempo completo

    A leading diagnostics solutions provider based in Barcelona is seeking a Cyber Security Specialist to enhance its governance, risk management, and compliance programs. The ideal candidate should have a Bachelor's degree in Cyber Security or related fields, along with a minimum of 5 years of experience in cybersecurity functions. The role involves...


  • Barcelona, España Technip Energies A tiempo completo

    A global technology and engineering company is seeking a Head of Cyber Security Program Governance in Barcelona. The role involves managing a comprehensive cybersecurity program, overseeing policy governance, and leading a team of experts. Candidates must have over 10 years of experience in information security and a preferred degree in Cyber Security or...


  • Barcelona, España Launch Global A tiempo completo

    **Cyber Security Risk Manager - Contract 6 Months (with potential to extend to 2 years) - Barcelona** **Why this role might be of interest** The role has come about because the company, a highly successful and rapidly expanding international pharmaceutical business, is putting in place a brand new internal team to manage cyber security threats. Because of...


  • Barcelona, España Launch Global A tiempo completo

    **Cyber Security Risk Manager - Contract 6 Months (with potential to extend to 2 years) - Barcelona** **Why this role might be of interest** The role has come about because the company, a highly successful and rapidly expanding international pharmaceutical business, is putting in place a brand new internal team to manage cyber security threats. Because of...


  • Barcelona, España Technip Energies A tiempo completo

    Be part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting-edge solutions to solve real-world energy problems. About us: Technip Energies is a global technology and engineering powerhouse. With leadership positions in LNG, hydrogen, ethylene, sustainable chemistry, and CO2 management, we are...


  • barcelona, España Technip Energies A tiempo completo

    Be part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting‑edge solutions to solve real‑world energy problems. About us Technip Energies is a global technology and engineering powerhouse. With leadership positions in LNG, hydrogen, ethylene, sustainable chemistry, and CO2 management, we are...


  • Barcelona, España Technip Energies A tiempo completo

    Be part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting‑edge solutions to solve real‑world energy problems.About usTechnip Energies is a global technology and engineering powerhouse. With leadership positions in LNG, hydrogen, ethylene, sustainable chemistry, and CO2 management, we are...


  • Barcelona, España Fluidra Spain A tiempo completo

    Security Governance, Risk, and Compliance Senior Analyst Fluidra, a Spanish multinational listed group, is a leading global company dedicated to the pool and wellness sector. Founded in 1969, Fluidra has long-standing experience developing innovative products and services in the global residential and commercial pool market. Fluidra's mission is to create...


  • Barcelona, España AstraZeneca A tiempo completo

    Are you ready to be part of the future of healthcare? Can you think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data, and innovative ways of working....


  • Barcelona, España Fluidra A tiempo completo

    **We are a leading company in the global pool & wellness industry**: Fluidra, a multinational group listed on the Spanish Stock Exchange, is the global leader in the pool and wellness industry. Founded in 1969, Fluidra has long-standing experience in developing innovative products and services in the global residential and commercial pool market. Fluidra...