Assoc Dir, Information Security Governance Risk & Compliance (Boston, MA, US)

Boston, United States Type not listed
Notify me about similar jobs

Servier is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

About Servier 

Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision.

 

Role Summary

The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the Associate Director, Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk methodology, strategic priorities, and maturity roadmap. The role provides oversight of information security risk management, policy governance, compliance, third-party risk management, control assurance, audit readiness, and risk reporting while directing operational execution through subordinate managers, analysts, contractors, and service providers. This position partners closely with Global Information Security, IT, Legal, Privacy, Procurement, Quality, Internal Audit, and business stakeholders to ensure risks are identified, assessed, communicated, and managed in alignment with enterprise requirements. The role serves as the primary GRC advisor and enables risk-informed decision making by translating information security risk into business, operational, regulatory, and financial impact. This is a high visibility leadership role with the opportunity to build and scale a modern GRC capability aligned to Servier’s global cybersecurity strategy, enterprise risk expectations, regulatory obligations, and business growth.

Primary Responsibilities

Cyber Risk Management and Governance

Establish and lead the US information security risk management framework across the affiliate

Define risk assessment methodologies, risk taxonomy, scoring models, reporting standards, and escalation criteria

Provide oversight and challenge of risk assessments performed by the GRC team

Ensure information security risks are clearly defined, consistently assessed, and aligned to Group methodology and enterprise risk expectations

Review material risks, treatment recommendations, mitigation strategies, and risk acceptance proposals before escalation

Drive risk-based prioritization of remediation activities, investment recommendations, and control improvement initiatives

Local Risk Coordinator and GRC Program Leadership

Serve as the senior US GRC leader responsible for coordinating information security risk governance across the affiliate

Act as the primary US liaison to Global Information Security for GRC-related risk, compliance, policy, and assurance activities

Establish governance routines, program cadences, reporting expectations, and execution standards for the US GRC function

Ensure alignment between US affiliate execution and Global risk management methodology, policy baselines, and governance expectations

Escalate material risks, systemic issues, overdue remediation, and governance concerns through US and Global governance channels

Governance, Policy and Control Assurance

Establish governance expectations for information security policies, standards, procedures, control requirements, and exception management

Sponsor the local information security policy lifecycle, ensuring alignment with Global baselines, US business requirements, and regulatory obligations

Define the control assurance approach used to evaluate control design, implementation, effectiveness, and maturity

Oversee control monitoring, compliance validation, gap analysis, and continuous improvement activities

Define and monitor KPIs and KRIs measuring policy adoption, control maturity, security posture, remediation progress, and governance effectiveness

Third-Party Risk and Enterprise Risk Integration

Establish the strategic direction for third-party information security risk management across the US vendor ecosystem

Define governance requirements, risk acceptance criteria, assessment standards, and escalation paths for third-party engagements

Partner with Procurement, Legal, Privacy, IT, and business stakeholders to ensure vendor security risks are appropriately assessed and managed

Oversee integration of third-party security risk into enterprise risk management, procurement processes, contractual reviews, and business decision making

Drive cross-domain alignment across Information Security, IT, Legal, Privacy, Procurement, Quality, and business functions

Audit, Compliance and Assurance Oversight

Oversee information security audit readiness across internal audits, external audits, regulatory engagements, and assurance activities

Establish governance over evidence collection, control validation, audit response, remediation tracking, and management reporting

Ensure audit findings, compliance gaps, and control deficiencies are translated into clear risk treatment plans with defined owners, timelines, and measurable outcomes

Partner with Internal Audit, Quality, Legal, Privacy, and Global Information Security to support assurance activities and regulatory expectations

Executive Engagement and Cross-Functional Influence

Act as a trusted advisor on information security governance, risk, compliance, and assurance matters

Translate complex information security risks into business, operational, regulatory, financial, and reputational impact

Deliver executive-level reporting on information security risk posture, governance maturity, compliance status, control effectiveness, and remediation progress

Support governance committees, leadership forums, business reviews, and strategic planning discussions with clear risk-based recommendations

Represent US GRC priorities in Global information security and enterprise risk forums, influencing alignment where appropriate

Organizational Leadership and Capability Building

Lead and develop the US Information Security Governance Risk and Compliance function

Manage GRC managers, analysts, contractors, consultants, managed service providers, and supporting resources

Define the GRC organizational structure, operating procedures, quality standards, workforce strategy, and capability development roadmap

Build scalable and repeatable GRC processes aligned to information security maturity objectives and organizational growth

Identify opportunities to improve efficiency through automation, process standardization, documentation quality, tooling, and operating model maturity

 

Education and Required Skills

Minimum of 8+ years of experience in information security GRC, IT risk management, cybersecurity, compliance, audit, security operations, or related disciplines

Minimum of 3+ years in a leadership role with responsibility for program ownership, people leadership, functional leadership, or management of managers

Bachelor’s degree preferred in Cybersecurity, Information Technology, Information Systems, Business, Risk Management, or a related field

Deep expertise in information security risk frameworks and governance models, including NIST CSF 2.0, ISO 27001, PCI, SOX, FAIR, or similar methodologies

Experience leading policy governance, third-party risk management, compliance oversight, audit readiness, control assurance, and remediation governance programs

Strong executive communication skills with the ability to influence senior stakeholders in a global, matrixed organization

Relevant certifications such as CISSP, CISM, CRISC, CISA, CGRC, FAIR, or equivalent preferred

Travel and Location

Onsite in Boston preferred 1-2 days hybrid; Remote considered with occasional travel to Boston

Estimated travel required: 5-10%

Servier’s Commitment

Servier is committed to modeling diversity, equity, and inclusion within the industry. We are dedicated to fostering an environment that maintains equitable treatment for all and we welcome applicants who are passionate, committed, and innovative individuals. We encourage candidates to apply to our open roles as we are always willing to consider experiences and skills beyond what is listed in the job description.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Salary Range

The salary range for this role is $179,000-$212,000. An employee’s pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs. We may ultimately pay more or less than the posted range, and the range may be modified in the future. Employees in this position are also eligible for Short-Term and Long-Term incentive programs. Servier also offers a competitive and comprehensive benefits package that includes benefits such as medical, dental, vision, flexible time off (Servier provides unlimited sick time and flex time, and does not accrue time off), 401(k), life and disability insurance, recognition programs among other great benefits (all benefits are subject to eligibility requirements).  For more information on our benefits, please visit this link .

]]>

Job details

Seniority
Not listed
Function
Information Technology
Therapeutic area
Not listed
Location
Boston, United States
Employment type
Not listed

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 1273 comparable Information Technology roles across 74 biopharma companies.

1273Comparable roles tracked
1174Currently active
74Companies hiring similar roles
36Countries represented

Salary context

151 of 1273 peers report a salary range (USD, annualized)

Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.

This roleSubject $179,000/yr – $212,000/yr
Lowest disclosed · Senior Data Security Engineer (Insider Risk Management – Engineering) · AbbVie $0/hr – $0/hr (≈ $0–$0/yr)
Peer group range $0 – $339,950 (median $167,700)

Where these roles are based

Top locations among the 1273 comparable roles

India579
United States273
Spain119
Poland87
Portugal27
China23

+ 30 more countries

Seniority mix

676 of 1273 peers have a known seniority level

Senior307
Manager169
Principal53
Associate Director47
Associate45
Director36
Intern/Fellow/Postdoc10
Senior Director6
Executive/VP3

Therapeutic area mix

1 of 1273 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

Vaccines & Infectious Disease1

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

40%similar
Lilly San Francisco, California, United States of America
Same function Same country
40%similar
Roche Santa Clara, California, United States of America Principal
Same function Same country
40%similar
Roche Santa Clara, California, United States of America
Same function Same country
40%similar
Gilead Sciences, Inc. Foster City, United States Manager
Same function Same country
40%similar
Gilead Sciences, Inc. Raleigh, United States Associate Director
Same function Same country
40%similar
Gilead Sciences, Inc. Raleigh, United States
Same function Same country

Notify me about similar jobs

Get an email when we spot other openings like this one – same job function, comparable seniority, roles you'd actually want to see.

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

40%
Technical Lead - Software Developer, Data Foundry
Lilly · San Francisco, California, United States of America · Seniority not listed
Function Therapeutic area Seniority Country
40%
Senior Manager, SAP – Planning and Manufacturing
Gilead Sciences, Inc. · Foster City, United States · Manager
Function Therapeutic area Seniority Country
40%
Director, IT Procurement Solutions
Gilead Sciences, Inc. · Foster City, United States · Director
Function Therapeutic area Seniority Country
40%
Director, IT SAP Product Lifecycle and Quality
Gilead Sciences, Inc. · Foster City, United States · Director
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.