Jobs and Careers
AD

Sr Director, Enterprise Security GRC

Advarra
United States of America, United States, United StatesRemotefull_timeVerifiedPosted 1 Apr 2025
💰 $270,700/yr

About the role

Company Information

At Advarra, we are passionate about making a difference in the world of clinical research and advancing human health. With a rich history rooted in ethical review services combined with innovative technology solutions and deep industry expertise, we are at the forefront of industry change. A market leader and pioneer, Advarra breaks the silos that impede clinical research, aligning patients, sites, sponsors, and CROs in a connected ecosystem to accelerate trials.

Company Culture 

Our employees are the heart of Advarra. They are the key to our success and the driving force behind our mission and vision. Our values (Patient-Centric, Ethical, Quality Focused, Collaborative) guide our actions and decisions. Knowing the impact of our work on trial participants and patients, we act with urgency and purpose to advance clinical research so that people can live happier, healthier lives. 

At Advarra, we seek to foster an inclusive and collaborative environment where everyone is treated with respect and diverse perspectives are embraced. Treating one another, our clients, and clinical trial participants with empathy and care are key tenets of our culture at Advarra; we are committed to creating a workplace where each employee is not only valued but empowered to thrive and make a meaningful impact.

Job Overview Summary 

Reporting to the Chief Information Security Officer (CISO), the Sr Director, Enterprise Security Governance, Risk and Compliance (GRC) will be responsible for the oversight and ongoing success of the Governance, Risk and Compliance team within the Advarra Enterprise Information Security department. The Head of GRC is both an experienced leader and a subject matter expert who will address cyber security from a strategic lens and provide guidance to leadership for managing risks to information security.

Job Duties & Responsibilities 

  • Working with Quality and Compliance to oversee the development of information security policies that are consistent with the organizations commitment to protect the health information and privacy of our customers and to comply with all legal and regulatory requirements.
  • Oversees the information security Cloud governance framework, including any policies, procedures and standards necessary to protect the organizations adoption of Cloud resources, recommending, documenting and monitoring the implementation of cloud security solutions for identity, data protection and other compliance measures
  • Developing technical Application Security and compliance standards across the organization to meet applicable regulations and contractual obligations; to meet our technical security objectives and that the associated controls are designed, implemented, and executed effectively, consistently, efficiently, and economically
  • Maintains and enhances the vendor due diligence process for 3rd party and Supply Chain Risk Management. Including monitoring for alerts around compliance concerns and progress towards remediation.
  • Develops, supports and serves as custodian for the Enterprise IT Risk Register consolidating risk for the relevant risk management programs including IT Risks, 3rd Party risk, Business Continuity, and containing the necessary attributions, remediation plans and acceptance
  • Serves as the internal auditor and internal security consultant for information security processes. Recommending, documenting, and monitoring the implementation of any prescribed corrective actions resulting from assigned security assessments or audits
  • Works with the privacy team to define the Data Protection policies and standards necessary to protect the safety of protected health information, personally identifiable information and other classes of data available on-premise and in the cloud
  • Supports any requests for information by any external authoritative agencies and customer review requests as required (E.g., assessors, auditors, investigators, etc.)
  • Performing, reviewing, evaluating, assessing, documenting, and communicating the results of the annual enterprise IT risk assessment.  
  • Supporting the Operations, Engineering and Applications teams by providing the necessary security expertise required to ensure compliance with company objectives for risk acceptance
  • Lead the enterprise security awareness and education efforts, including any associated committees and workgroups. 
  • Establishes and operates the metrics collection and reporting to measure security maturity facilitate  reporting mechanisms for continual program improvements. 
  • Consults with all departments on related issues, inquiries, and projects. 

Location 

This role is open to candidates working remotely in ​the United States. 

Basic

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Advarra

View company profile →