Sr. Director of Compliance – Cyber GRC

Lilly
Indianapolis, Indiana, US
Full-time
We are sorry. The job offer you are looking for is no longer available.

Is this the next step in your career Find out if you are the right candidate by reading through the complete overview below.

At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana.

Our employees around the world work to discover and bring life-changing medicines to those who need them, improve the understanding and management of disease, and give back to our communities through philanthropy and volunteerism.

We give our best effort to our work, and we put people first. We’re looking for people who are determined to make life better for people around the world.

What You’ll Be Doing :

The Sr Director of Compliance, Cybersecurity will be a key member of the lead team of Cybersecurity Governance, Risk, and Compliance (GRC) at Lilly, serving as both a hands-on practitioner and a leader / mentor for the compliance team.

The Director will be responsible for ensuring the organization adheres to all regulatory and industry standards, conducting mock audits, performing gap analyses, implementing corrective actions, managing attestations and certifications, and overseeing cyber insurance processes.

Additionally, the Director will have managerial responsibilities, collaborating with subject matter experts (SMEs) across the company.

The ideal candidate will bring extensive experience in cybersecurity compliance and a strategic mindset to drive continuous improvement in our security posture.

What You Should Bring :

  • Excellent knowledge of cybersecurity frameworks and standards; proficiency in frameworks and standards such as ISO 27001, NIST, SOC 2, and others is essential for ensuring compliance and maintaining relevant certifications and attestations.
  • Active participation in a leadership role in conducting audits, assessments, and gap analyses, demonstrating technical expertise and leading by example.
  • Contribute to the development and implementation of compliance processes, tools, and automation scripts to improve efficiency and effectiveness.
  • Stay up to date with the latest cybersecurity trends, technologies, and best practices, and provide guidance to the team on leveraging new solutions and methodologies.

How You'll Succeed :

  • Regulatory Compliance : Stay abreast of global regulatory changes and ensure the organization’s cybersecurity practices comply with relevant laws and regulations.
  • Mock Audits : Plan and conduct regular mock audits to assess the organization’s compliance with internal and external cybersecurity standards and regulations.
  • Gap Analysis : Perform comprehensive gap analyses to identify areas of non-compliance and potential security risks.
  • Corrective Action Plans : Develop and oversee the implementation of corrective action plans to address identified gaps and vulnerabilities.
  • Follow-up on Corrective Actions : Ensure timely follow-up and closure of corrective actions identified during audits and assessments.
  • Attestations and Certifications : Manage the process for achieving and maintaining relevant cybersecurity certifications and attestations, including ISO 27001, SOC 2, and others.
  • GRC tools and platforms : Knowledge of Governance, Risk, and Compliance (GRC) tools and platforms would be beneficial for managing compliance processes and reporting effectively.
  • Policies : Collaborate with the Cybersecurity Governance team to stay updated on cybersecurity policies and procedures.
  • Risk Management : Collaborate with the Cybersecurity Risk Management team to stay updated on the risk management process.
  • Data Analysis and Reporting : Proficiency in data analysis tools (e.g., Qualtrics, Power BI) for querying and analyzing security data.

Experience with creating and presenting comprehensive compliance reports and dashboards to senior management.

  • Cyber Insurance : Oversee the management of the company’s cyber insurance policy, ensuring adequate coverage and compliance with policy requirements.
  • Managerial Responsibilities : Lead and coach a team of compliance professionals, providing guidance, support, and professional development opportunities through hands-on mentoring, knowledge sharing, and collaborative problem-solving.
  • Collaboration : Work closely with other relevant SMEs at Lilly and across the organization to ensure a cohesive and comprehensive approach to cybersecurity compliance.

Your Basic Qualifications :

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field
  • 8+ years of experience in cybersecurity governance, risk management, and compliance
  • 3+ years of experience managing a team

Preferred Qualifications :

  • In-depth knowledge of ISO 27001 controls, including information security policies, risk assessments, and implementation of security controls.
  • Expertise in mapping NIST Cybersecurity Framework controls to organizational processes and systems.
  • Risk management certifications (e.g., CRISC, CISA)
  • Audit-related certifications (e.g., CISA, CGEIT)
  • Cloud security certifications (e.g., AWS Certified Security - Specialty, Microsoft Azure Security Engineer Associate)
  • Understanding of SOC 2 criteria and the ability to assess and report on relevant controls.
  • Familiarity with cloud security best practices and experience with cloud service provider (CSP) security controls and compliance requirements.
  • Proven experience in conducting audits, gap analyses, and implementing corrective actions.
  • Excellent understanding of regulatory requirements and industry best practices.
  • Strong analytical and problem-solving skills.
  • Exceptional communication and interpersonal skills.
  • Ability to manage multiple projects and priorities in a fast-paced environment.
  • High level of integrity and professional ethics.
  • Knowledge of the MITRE attack framework.
  • Hands-on experience with vulnerability management tools, security information and event management (SIEM) systems, and other security monitoring solutions.
  • Proficiency in scripting languages (e.g., Python, PowerShell) for automating tasks, data manipulation, and report generation.
  • Experience in the pharmaceutical industry or a similar, heavily regulated environment.
  • Proficiency with GRC tools and platforms.
  • Demonstrated leadership and team management skills.

Additional Information :

This role is in Indianapolis, IN with a hybrid work model - relocation required

J-18808-Ljbffr

3 days ago
Related jobs
Promoted
Eli Lilly and Company
Indianapolis, Indiana

The Sr Director of Compliance, Cybersecurity will be a key member of the lead team of Cybersecurity Governance, Risk, and Compliance (GRC) at Lilly, serving as both a hands-on practitioner and a leader/mentor for the compliance team. Have excellent knowledge of cybersecurity frameworks and standards...

jobbot
Indianapolis, Indiana

Our organization is seeking a seasoned Sr Director of Global Supply Chain for our expanding Manufacturing and Supply Chain division. We have a team of both hybrid and remote employees across the globe supporting international roll-outs of cancer-saving treatments and advancing late-stage clinical pr...

Jobot
Indianapolis, Indiana

Our organization is seeking a seasoned Sr Director of Global Supply Chain for our expanding Manufacturing and Supply Chain division. We have a team of both hybrid and remote employees across the globe supporting international roll-outs of cancer-saving treatments and advancing late-stage clinical pr...

Medical Service Company
Indianapolis, Indiana

Director of Healthcare Compliance, Regulatory & Risk. Director of Regulatory Compliance. Works with organization’s leadership to ensure understanding and ongoing verification of corporate compliance. Holds position of company privacy officer. ...

Promoted
UnitedHealth Group
Indianapolis, Indiana

Establish, mandate and implement standard policies, procedures and best practices across the company to promote compliance with applicable laws and contractual obligations. Conduct state-specific legal research and monitor changes in requirements to mitigate risks and achieve compliance. Support the...

Promoted
Old National Bank
Indianapolis, Indiana

We are currently seeking a Compliance Testing Analyst that will be responsible for performing testing activities for various regulatory compliance requirements applicable to Old National lines of business. This position will report to the Compliance Testing Manager and is part of the Corporate Compl...

Acara Solutions
Indianapolis, Indiana

As a government audit finance and compliance analyst with the client, you will work with a broader group of financial and compliance analysts within the government finance team. Government Audit Finance and Compliance Analyst . This team supports all Defense Contract Audit Agency (DCAA) audits and a...

Mindlance
Indianapolis, Indiana

Summary: The main function of a compliance analyst is to ensure the organizations operations and procedures meet government and industry compliance standards. A compliance analyst may research regulations and policies, communicate requirements, and apply for compliance certifications on behalf of th...

Deloitte
Indianapolis, Indiana

Compliance Senior Analyst, Independence Consultation – Business Relationships, Independence & Conflicts Network (ICN). Do you have a focus on compliance with regulations and policies? Are you passionate about quality-assurance and risk-management in a professional services environment? Then our Inde...

BCforward
Crows Nest, Indiana

BCforward is currently seeking a highly motivated Global Supply Chain Compliance Administrator in Indianapolis, IN 46268. Global Supply Chain Compliance Administrator. Should have experience with Root Cause Analysis, Compliance and Distribution Safety. Need to have knowledge of shipping & compliance...