Sr. Director of Compliance – Cyber GRC

Lilly
Indianapolis, Indiana, US
Full-time
We are sorry. The job offer you are looking for is no longer available.

Is this the next step in your career Find out if you are the right candidate by reading through the complete overview below.

At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana.

Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism.

We give our best effort to our work, and we put people first. We’re looking for people who are determined to make life better for people around the world.

What You’ll Be Doing :

The Sr Director of Compliance, Cybersecurity will be a key member of the lead team of Cybersecurity Governance, Risk, and Compliance (GRC) at Lilly, serving as both a hands-on practitioner and a leader / mentor for the compliance team.

The Director will be responsible for ensuring the organization adheres to all regulatory and industry standards, conducting mock audits, performing gap analyses, implementing corrective actions, managing attestations and certifications, and overseeing cyber insurance processes.

Additionally, the Director will have managerial responsibilities, collaborating with subject matter experts (SMEs) across the company.

The ideal candidate will bring extensive experience in cybersecurity compliance and a strategic mindset to drive continuous improvement in our security posture.

What You Should Bring :

  • Excellent knowledge of cybersecurity frameworks and standards; proficiency in frameworks and standards such as ISO 27001, NIST, SOC 2, and others is essential for ensuring compliance and maintaining relevant certifications and attestations.
  • Active participation in a leadership role in conducting audits, assessments, and gap analyses, demonstrating technical expertise and leading by example.
  • Contribute to the development and implementation of compliance processes, tools, and automation scripts to improve efficiency and effectiveness.
  • Stay up to date with the latest cybersecurity trends, technologies, and best practices, and provide guidance to the team on leveraging new solutions and methodologies.

How You'll Succeed :

  • Regulatory Compliance : Stay abreast of global regulatory changes and ensure the organization’s cybersecurity practices comply with relevant laws and regulations.
  • Mock Audits : Plan and conduct regular mock audits to assess the organization’s compliance with internal and external cybersecurity standards and regulations.
  • Gap Analysis : Perform comprehensive gap analyses to identify areas of non-compliance and potential security risks.
  • Corrective Action Plans : Develop and oversee the implementation of corrective action plans to address identified gaps and vulnerabilities.
  • Follow-up on Corrective Actions : Ensure timely follow-up and closure of corrective actions identified during audits and assessments.
  • Attestations and Certifications : Manage the process for achieving and maintaining relevant cybersecurity certifications and attestations, including ISO 27001, SOC 2, and others.
  • GRC tools and platforms : Knowledge of Governance, Risk, and Compliance (GRC) tools and platforms would be beneficial for managing compliance processes and reporting effectively.
  • Policies : Collaborate with the Cybersecurity Governance team to stay updated on cybersecurity policies and procedures.
  • Risk Management : Collaborate with the Cybersecurity Risk Management team to stay updated on the risk management process.
  • Data Analysis and Reporting : Proficiency in data analysis tools (e.g., Qualtrics, Power BI) for querying and analyzing security data.

Experience with creating and presenting comprehensive compliance reports and dashboards to senior management.

  • Cyber Insurance : Oversee the management of the company’s cyber insurance policy, ensuring adequate coverage and compliance with policy requirements.
  • Managerial Responsibilities : Lead and coach a team of compliance professionals, providing guidance, support, and professional development opportunities through hands-on mentoring, knowledge sharing, and collaborative problem-solving.
  • Collaboration : Work closely with other relevant SMEs at Lilly and across the organization to ensure a cohesive and comprehensive approach to cybersecurity compliance.

Your Basic Qualifications :

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field
  • 8+ years of experience in cybersecurity governance, risk management, and compliance
  • 3+ years of experience managing a team

Preferred Qualifications :

  • In-depth knowledge of ISO 27001 controls, including information security policies, risk assessments, and implementation of security controls.
  • Expertise in mapping NIST Cybersecurity Framework controls to organizational processes and systems.
  • Risk management certifications (e.g., CRISC, CISA)
  • Audit-related certifications (e.g., CISA, CGEIT)
  • Cloud security certifications (e.g., AWS Certified Security - Specialty, Microsoft Azure Security Engineer Associate)
  • Understanding of SOC 2 criteria and the ability to assess and report on relevant controls.
  • Familiarity with cloud security best practices and experience with cloud service provider (CSP) security controls and compliance requirements.
  • Proven experience in conducting audits, gap analyses, and implementing corrective actions.
  • Excellent understanding of regulatory requirements and industry best practices.
  • Strong analytical and problem-solving skills.
  • Exceptional communication and interpersonal skills.
  • Ability to manage multiple projects and priorities in a fast-paced environment.
  • High level of integrity and professional ethics.
  • Knowledge of the MITRE attack framework.
  • Hands-on experience with vulnerability management tools, security information and event management (SIEM) systems, and other security monitoring solutions.
  • Proficiency in scripting languages (e.g., Python, PowerShell) for automating tasks, data manipulation, and report generation.
  • Experience in the pharmaceutical industry or a similar, heavily regulated environment.
  • Proficiency with GRC tools and platforms.
  • Demonstrated leadership and team management skills.

Additional Information :

This role is in Indianapolis, IN with a hybrid work model - relocation required

J-18808-Ljbffr

4 days ago
Related jobs
Promoted
Eli Lilly and Company
Indianapolis, Indiana

The Sr Director of Compliance, Cybersecurity will be a key member of the lead team of Cybersecurity Governance, Risk, and Compliance (GRC) at Lilly, serving as both a hands-on practitioner and a leader/mentor for the compliance team. Have excellent knowledge of cybersecurity frameworks and standards...

Promoted
Salesforce.com, Inc.
Indianapolis, Indiana

Own parts of our cross-industry product Point of View and directional roadmap including how it works with/leverages partner integrations. At Salesforce we believe that the business of business is to improve the state of our world. To get the best candidate experience, please consider applying for a ...

Medical Service Company
Indianapolis, Indiana

Director of Healthcare Compliance, Regulatory & Risk. Director of Regulatory Compliance. Works with organization’s leadership to ensure understanding and ongoing verification of corporate compliance. Holds position of company privacy officer. ...

jobbot
Indianapolis, Indiana

Our organization is seeking a seasoned Sr Director of Global Supply Chain for our expanding Manufacturing and Supply Chain division. We have a team of both hybrid and remote employees across the globe supporting international roll-outs of cancer-saving treatments and advancing late-stage clinical pr...

Jobot
Indianapolis, Indiana

Our organization is seeking a seasoned Sr Director of Global Supply Chain for our expanding Manufacturing and Supply Chain division. We have a team of both hybrid and remote employees across the globe supporting international roll-outs of cancer-saving treatments and advancing late-stage clinical pr...

CNO Financial Group
Carmel, Indiana
Remote

This role will create and provide AML, financial crimes and watchlist compliance guidance and training to business partners and insurance agents pertaining to various compliance matters including money laundering, financial crimes, elder abuse, sales practice activities and compliance risk monitorin...

BCforward
Crows Nest, Indiana

BCforward is currently seeking a highly motivated Global Supply Chain Compliance Administrator in Indianapolis, IN 46268. Global Supply Chain Compliance Administrator. Should have experience with Root Cause Analysis, Compliance and Distribution Safety. Need to have knowledge of shipping & compliance...

Russell Tobin
Indianapolis, Indiana

As a Government Audit Finance and Compliance Analyst, you will work within a broader group of Financial and Compliance Analysts within the Government Finance team. Government Audit Finance and Compliance Analyst?. This team is responsible for supporting all Defense Contract Audit Agency (DCAA) audit...

CVS Health
Indianapolis, Indiana
Remote

Applies basic knowledge of compliance, business, analytical, and communication skills to support compliance programs and processes that promote compliant and ethical behavior, meet regulatory obligations, and prevent, detect, and mitigate compliance risks. This position will focus on compliance with...

Mindlance
Indianapolis, Indiana

Summary: The main function of a compliance analyst is to ensure the organizations operations and procedures meet government and industry compliance standards. A compliance analyst may research regulations and policies, communicate requirements, and apply for compliance certifications on behalf of th...