Vice President, ACM Information Security, CISO
ACM Global LaboratoriesAbout the role
Position Summary
The Vice President, ACM Information Security; CISO leads the enterprise-wide information security and cyber risk management program for ACM. This role ensures that all information assets—technology, applications, systems, infrastructure, and processes—are protected across the digital ecosystem, and identifies, evaluates, and reports on legal, regulatory, IT, and cybersecurity risks while enabling business objectives.
The position safeguards the confidentiality, integrity, and availability of data and systems supporting R&D, clinical trials, manufacturing, supply chain, regulatory submissions, and commercial operations. It protects high‑value research assets, clinical development systems, proprietary algorithms, and sensitive partner data, while enabling rapid innovation, collaboration, and compliance.
Operating in a highly regulated environment, the VP, ACM Information Security; CISO balances cybersecurity with clinical trial needs, innovation, speed to market, and patient safety.
Key Responsibilities
Strategic Leadership & Governance
Facilitate an ACM information security governance structure through the implementation of a hierarchical governance program, including the formation of an information security steering committee or advisory board.
Define and execute the enterprise information security strategy and roadmap aligned with business objectives and regulatory obligations
Provide regular reporting on the current status of the information security program to enterprise risk teams, senior business leaders and the board of directors as part of a strategic enterprise risk management program, thus supporting business outcomes.
Ensure that IT security requirements are included in vendor contracts by liaising with vendor management and procurement organizations.
Create and manage a targeted information security awareness training program for all employees, contractors and approved system users, and establish metrics to measure the effectiveness of this security training program for the different audiences.
Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems and services, including privacy, risk management, compliance and business continuity management.
Serve as executive advisor on cyber risk to ACM’s Executive Leadership Team (ELT)
Establish security governance, policies, standards, and metrics across global operations
Lead security investment planning and budgeting
IT Security Strategy / Framework Development, Execution and Reporting
Develop an information security vision and strategy that is aligned to organizational priorities and enables and facilitates the organization's business objectives, and ensure senior stakeholder buy-in and mandate.
Develop, implement and monitor a strategic, comprehensive information security program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy and recovery of information assets owned, controlled or/and processed by the organization.
Develop and enhance an up-to-date information security management framework based on ISO 27001.
Create and manage a unified and flexible control framework to integrate and normalize the wide variety and ever-changing requirements resulting from global laws, standards and regulations.
Develop and maintain a document framework of continuously up-to-date information security policies, standards and guidelines. Oversee the approval and publication of these information security policies and practices.
Create a framework for roles and responsibilities with regard to information ownership, classification, accountability and protection of information assets.
Facilitate a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation, and increase the maturity of the information security, and review it with stakeholders at the executive and board levels.
Regulatory & Compliance Leadership
Ensure compliance with regulations and standards, including;
ISO 27001
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s