Logo for Viatris

Director, Information Security Governance Risk Compliance

Role overview

Qualifications

  • Minimum of a Bachelor’s degree in MIS, IT, or Engineering
  • Minimum of eight years of IT or Cybersecurity experience
  • Knowledge of cybersecurity and privacy principles
  • Knowledge of enterprise risk management methodologies

Responsibilities

  • Develop and maintain enterprise cybersecurity governance, risk, and compliance strategies
  • Direct enterprise risk assessments and compliance reviews across business and technology environments
  • Lead development and implementation of cybersecurity policies and governance frameworks
  • Oversee third-party cybersecurity risk management processes

Key facts

Hard skills

Other skills

  • Governance

About the company

Viatris logo

Viatris

Pharmaceutical Manufacturing

Viatris Inc. (NASDAQ: VTRS) is a global healthcare company uniquely positioned to bridge the traditional divide between generics and brands, combining the best of both to more holistically address healthcare needs globally. With a mission to empower people worldwide to live healthier at every stage of life, we provide access at scale. In 2022 alone, we supplied high-quality medicines to approximately 1 billion patients around the world. With our exceptionally extensive and diverse portfolio of medicines, a one-of-a-kind global supply chain designed to reach more people when and where they need them, and the scientific expertise to address some of the world’s most enduring health challenges, access takes on deep meaning at Viatris. We have the ability to touch all of life’s moments, from birth to end of life, acute conditions to chronic diseases. We are headquartered in the U.S., with global centers in Pittsburgh, Shanghai and Hyderabad, India Social Media Guidelines: https://newsroom.viatris.com/social-media-community-guidelines Investors: https://investor.viatris.com Corporate Social Responsibility: https://www.viatris.com/sustainability Connect with Viatris Instagram: https://www.instagram.com/viatrisinc X: https://www.twitter.com/viatrisinc Viatris and our recruiting firms will not ask for sensitive personal information, such as your social security number, date of birth or bank account details via text, email or social media. Additionally, Viatris representatives do not request payment or personal bank information nor send payment to purchase hardware on your own. Viatris.com is the primary source of all company job postings and authorized third-party career websites.

Company details

Company typeXLarge
IndustryPharmaceutical Manufacturing
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Mylan Inc.

Viatris is a global healthcare company uniquely positioned to bridge the traditional divide between generics and brands, combining the best of both to more holistically address healthcare needs globally. With a mission to empower people worldwide to live healthier at every stage of life, we provide access at scale, currently supplying high-quality medicines to approximately 1 billion patients around the world annually and touching all of life's moments, from birth to the end of life, acute conditions to chronic diseases.

We have been included on number of award lists that demonstrate the impact we are making.

Every day, we rise to the challenge to make a difference and here’s how the Director, Information Security Governance Risk Compliance role will make an impact:

The primary purpose of the Director, Governance, Risk & Compliance (GRC) is to provide strategic leadership and enterprise oversight for the GRC program supporting the organization’s cybersecurity, privacy, quality, and regulatory obligations. The Director is responsible for establishing and maturing enterprise-wide cybersecurity governance processes, risk management frameworks, compliance monitoring activities, third-party risk management, and audit readiness programs. This role partners with executive leadership, legal, privacy, quality, manufacturing, and global technology teams to ensure cybersecurity risks are identified, communicated, and managed in alignment with business objectives and regulatory requirements applicable to the pharmaceutical industry including GxP, HIPAA, SOX, GDPR, and FDA expectations. The Director leads cross-functional initiatives, develops strategic roadmaps, directs remediation priorities, and ensures effective communication of cyber risk posture to executive leadership and governance committees.

Key responsibilities for this role include:

  • Develop and maintain enterprise cybersecurity governance, risk, and compliance strategies aligned with organizational objectives and regulatory requirements.

  • Direct enterprise risk assessments, compliance reviews, and control maturity evaluations across business and technology environments.

  • Lead development and implementation of cybersecurity policies, standards, procedures, and governance frameworks.

  • Provide strategic oversight for audit readiness activities supporting internal audits, regulatory inspections, and third-party assessments.

  • Review and communicate enterprise cyber risk posture, key risk indicators, and remediation priorities to executive leadership and governance committees.

  • Oversee third-party cybersecurity risk management processes including supplier risk evaluations and contractual security requirements.

  • Coordinate enterprise-wide remediation strategies for vulnerabilities, audit findings, and risk treatment plans.

  • Guide strategic planning and budgeting activities for cybersecurity governance and compliance initiatives.

  • Collaborate with legal, privacy, quality, manufacturing, and IT leadership to align cybersecurity governance with enterprise risk management objectives.

  • Support development of business continuity and operational resilience strategies for critical business processes.

  • Partner with architecture and engineering teams to ensure security controls and compliance requirements are integrated into technology solutions.

  • Promote cybersecurity awareness and risk-informed decision making across business functions and leadership teams.

  • Support organizational initiatives involving mergers, acquisitions, and digital transformation by evaluating cybersecurity and compliance risks.

The minimum qualifications for this role are:

  • Minimum of a Bachelor’s degree with a focus in MIS ,IT or Engineering or equivalent is required.  Masters degree in MIS, IT, Engineering or related is preferred.  Related experience and/or education may be considered.

  • Minimum of eight years of IT or Cybersecurity experience is required.

  • Knowledge of cybersecurity and privacy principles, frameworks, and regulatory requirements applicable to global pharmaceutical organizations.

  • Knowledge of enterprise risk management methodologies, governance structures, and compliance assessment techniques.

  • Knowledge of audit practices, internal controls, and regulatory compliance requirements including SOX, HIPAA, GDPR, and GxP expectations.

  • Knowledge of third-party risk management concepts and vendor governance processes.

  • Knowledge of incident management, vulnerability management, and security operations governance.

  • Knowledge of security architecture concepts, cloud technologies, and data protection methodologies.

Exact compensation may vary based on skills, experience, and location. The salary range for this position is $112,000.00 - $236,000.00 USD.

At Viatris, we offer competitive salaries, benefits and an inclusive environment where you can use your experiences, perspectives and skills to help make an impact on the lives of others.

Viatris is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, gender expression, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Viatris

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.