This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Support global IT and compliance objectives by managing cybersecurity governance, risk, and compliance processes. This position ensures adherence to regulatory requirements (such as GxP, GDPR, ISO 27001, and NIST) and oversees exceptions management and workflow automation to maintain a secure and compliant IT environment.
Job Responsibility:
Maintain and update cybersecurity policies, standards, and procedures aligned with ISO 27001, NIST, and GxP requirements
Ensure IT governance processes support business and regulatory objectives
Conduct IT risk assessments and maintain risk registers
Monitor compliance with data protection laws and internal security policies
Prepare for and support internal/external audits (regulatory and customer)
Manage policy exceptions lifecycle: request, approval, tracking, and expiration
Assess risk impact of exceptions and ensure mitigation plans are in place
Design and optimize workflows for compliance tasks (risk assessments, audits, incident handling)
Implement automation in GRC tools (e.g., ServiceNow, Archer) for exception handling and reporting
Track and report Key Risk Indicators (KRIs) and compliance metrics
Provide dashboards and reports to management for decision-making
Requirements:
Bachelor’s degree in Information Security, IT, or related field
2–4 years of experience in GRC or cybersecurity compliance, preferably in pharmaceutical industry
Knowledge of frameworks: ISO 27001, NIST CSF, GDPR, GxP
Familiarity with GRC platforms (ServiceNow, Archer) and workflow automation
Certifications (preferred): CISM, CISA, CISSP, ISO 27001 Implementer
Microsoft Certified: Azure Security
Strong analytical, communication, and stakeholder management skills
Ability and eligibility to work in Switzerland (hybrid set-up)
Nice to have:
Certifications (preferred): CISM, CISA, CISSP, ISO 27001 Implementer