This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As our Information Security Advisor, you will help embed information security in the business by implementing and operating an Information Security Management System (ISMS) and translating requirements into practical ways of working, while coordinating existing processes. The role combines governance and risk work with strong stakeholder management, advisory at multiple organizational levels, and clear communication and presentation.
Job Responsibility:
Coordinate, implement and continuously improve the ISMS across the organization, including governance processes, controls, documentation, and evidence collection – ensuring compliance with NIS2 & FDA’s 21 CFR Part 11
Act as a trusted advisor to stakeholders across Legal, QA, People & Culture, R&D, Procurement and executive management by translating security risk into business impact, options and clear recommendations
Develop and maintain information security policies, standards and guidance, ensuring they are understood, adopted, and fit for purpose in daily operations
Facilitate risk assessments and control reviews for new initiatives, vendors/partners and technology changes, ensuring security is enabled pragmatically
Lead and mature data governance and protection efforts, including data mapping and data classification/labelling, and scaling DLP/information protection (e.g., Microsoft Purview) from limited use to broader adoption
Build security awareness and learning through targeted communication, stakeholder engagement, and presentations tailored to different audiences and levels
Help embed information security in the business by implementing and operating an Information Security Management System (ISMS) and translating requirements into practical ways of working, while coordinating existing processes
Support Legal with stronger data governance and protection by scaling data classification/labelling and further utilizing/implementing DLP capabilities (e.g., Microsoft Purview)
Requirements:
Proven experience implementing and operating an ISMS and working with recognized frameworks (e.g., ISO 27001/27002, NIST CSF, CIS Controls)
Strong stakeholder management skills, including advisory communication at different levels and the ability to drive alignment and decisions
Strong written communication skills (policies/standards/guidance) and strong presentation/facilitation skills (workshops, briefings, decision material), with the ability to translate requirements into practical tools and ways of working
Experience performing and documenting risk assessments and tracking mitigations in a structured way (risk register and follow-up), preferably in OneTrust
Experience with, or strong interest in building, data governance practices including data classification/labelling and DLP/information protection solutions (e.g., Microsoft Purview)
Foundational technical understanding (identity, endpoints, cloud and networking concepts) to collaborate effectively with IT and security specialists
Several years’ experience working with information security in the life science industry
Structured, proactive and collaborative
Communicates clearly, influences without authority
Comfortable facilitating workshops and presenting to both operational teams and executive audiences