Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Director, IT Risk & Compliance image - Rise Careers
Job details

Director, IT Risk & Compliance

Company Description

At EVERSANA, we are proud to be certified as a Great Place to Work across the globe. We’re fueled by our vision to create a healthier world. How? Our global team of more than 7,000 employees is committed to creating and delivering next-generation commercialization services to the life sciences industry. We are grounded in our cultural beliefs and serve more than 650 clients ranging from innovative biotech start-ups to established pharmaceutical companies. Our products, services and solutions help bring innovative therapies to market and support the patients who depend on them. Our jobs, skills and talents are unique, but together we make an impact every day. Join us!

Across our growing organization, we embrace diversity in backgrounds and experiences. Improving patient lives around the world is a priority, and we need people from all backgrounds and swaths of life to help build the future of the healthcare and the life sciences industry. We believe our people make all the difference in cultivating an inclusive culture that embraces our cultural beliefs.  We are deliberate and self-reflective about the kind of team and culture we are building. We look for team members that are not only strong in their own aptitudes but also who care deeply about EVERSANA, our people, clients and most importantly, the patients we serve. We are EVERSANA.  

Job Description

The Director, IT Risk & Compliance is responsible for leading and managing the company's information security and technology risk management program. The Director will lead efforts to maintain compliance with relevant regulations, standards, and frameworks This role will play a critical part in identifying, assessing, and mitigating risks across the organization's IT infrastructure, applications, and data. The successful candidate will possess a strong understanding of industry best practices, regulatory requirements (e.g., SOX, HIPAA, GDPR), and emerging threats.

ESSENTIAL DUTIES AND RESPONSIBILITIES:
Our employees are tasked with delivering excellent business results through the efforts of their teams.  These results are achieved by:

  • Manage and mentor a team of risk analysts and security professionals.
  • Develop and maintain a comprehensive Enterprise IS/IT Risk Management framework, including risk assessments, threat modeling, and vulnerability management.
  • Conduct regular risk assessments across the organization, including business impact analyses (BIA) and threat and vulnerability assessments (TVAs).
  • Oversee the implementation of risk mitigation controls and monitor their effectiveness.
  • Develop and maintain key risk indicators and key performance indicators (KPIs) to track and measure risk levels.
  • Advise senior management on risk-related decisions and provide recommendations for improving the company's overall security posture.
  • Stay abreast of emerging threats and vulnerabilities and advise on appropriate countermeasures.
  • Collaborate with internal and external stakeholders, including IT, legal, compliance, and business units.
  • Ensure compliance with relevant industry regulations and standards.
  • Participate in incident response activities and post-mortem analysis.
  • Develop and deliver presentations and reports to senior management and the Board of Directors.
  • Ensure compliance with applicable laws, regulations, and industry standards.
  • Develop and maintain IT policies, procedures, and standards.
  • Conduct internal and external audits to assess compliance.
  • Manage relationships with external auditors and regulatory bodies.
  • Stay abreast of changes in regulatory requirements and industry best practices.
  • Demonstrate a commitment to diversity, equity, and inclusion through continuous development, modeling inclusive behaviors, and proactively managing bias.
  • All other duties as assigned.

Consistent with the Americans with Disabilities Act (ADA) and applicable state and local laws, it is the policy of EVERSANA to provide reasonable accommodation when requested by an employee with a disability, unless such accommodation would cause an undue hardship for EVERSANA. If reasonable accommodation is needed to perform the essential functions of your job position, please contact Human Resources.

PEOPLE LEADER:

People leaders must possess both the skills to effectively accomplish these tasks and the emotional intelligence to do so in alignment with our cultural values.  In addition to the critical management and leadership tasks listed above, this role also includes the following unique responsibilities:

  • Responsible for and oversee their respective department.
  • Interview, select and supervise the activities of the department staff; communicate interpret and discuss with team the company policies and procedures.
  • Determine job objectives, work methods and performance standards; review performance relative to departmental objectives discussion appraisal with each employee and performance; authorize and communicate salary changes, promotions, transfers, discipline, and discharge and administer all other personnel actions.

EXPECTATIONS OF THE JOB:

  • Travel (10-20%)
  • Hours (40-45 hours per week, Monday through Friday)

The above list reflects the general details necessary to describe the expectations of the position and shall not be construed as the only expectations that may be assigned for the position.

An individual in this position must be able to successfully perform the expectations listed above.

Qualifications

MINIMUM KNOWLEDGE, SKILLS AND ABILITIES:

The requirements listed below are representative of the experience, education, knowledge, skill and/or abilities required.

  • Bachelor's degree in Computer Science, Information Systems, or a related field.
  • 10+ years of experience in information security and risk management roles, with at least 5 years in a leadership position.
  • Proven experience in developing and implementing enterprise-wide risk management frameworks.
  • Strong understanding of industry best practices, regulatory requirements (e.g., SOX, HIPAA, GDPR), and emerging threats.
  • Experience with risk assessment methodologies, including threat modeling, vulnerability scanning, and penetration testing.
  • Excellent analytical and problem-solving skills.
  • Strong leadership and mentoring skills.

PREFERRED QUALIFICATIONS:

  • Strong communication and presentation skills, with the ability to effectively communicate complex technical information to both technical and non-technical audiences.  
  • Ability to work independently and as part of a team.
  • Experience with GRC tools and technologies a plus.
  • Relevant industry certifications (e.g., CISSP, CISM, CRISC) preferred.

PHYSICAL/MENTAL DEMANDS AND WORKING ENVIRONMENT:

The physical and mental requirements along with the work environment characteristics described here are representative of those an individual encounters while performing the essential functions of this position.

Office: While performing the essential functions of this job the employee is frequently required to reach, grasp, stand and/or sit for long periods of time (up to 90% of the shift), walk, talk and hear; occasionally required to lift and/or move up to 25 pounds. The noise level in the work environment is usually moderately quiet, with frequent interruptions and multiple demands.

Additional Information

OUR CULTURAL BELIEFS:

Patient Minded I act with the patient’s best interest in mind.

Client Delight I own every client experience and its impact on results.

Take Action I am empowered and empower others to act now.

Grow Talent I own my development and invest in the development of others. 

Win Together I passionately connect with anyone, anywhere, anytime to achieve results.

Communication Matters I speak up to create transparent, thoughtful and timely dialogue.

Embrace Diversity I create an environment of awareness and respect.

Always Innovate I am bold and creative in everything I do.

Our team is aware of recent fraudulent job offers in the market, misrepresenting EVERSANA. Recruitment fraud is a sophisticated scam commonly perpetrated through online services using fake websites, unsolicited e-mails, or even text messages claiming to be a legitimate company. Some of these scams request personal information and even payment for training or job application fees. Please know EVERSANA would never require personal information nor payment of any kind during the employment process. We respect the personal rights of all candidates looking to explore careers at EVERSANA.

From EVERSANA’s inception, Diversity, Equity & Inclusion have always been key to our success. We are an Equal Opportunity Employer, and our employees are people with different strengths, experiences, and backgrounds who share a passion for improving the lives of patients and leading innovation within the healthcare industry. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion, and many other parts of one’s identity. All of our employees’ points of view are key to our success, and inclusion is everyone's responsibility.

Consistent with the Americans with Disabilities Act (ADA) and applicable state and local laws, it is the policy of EVERSANA to provide reasonable accommodation when requested by a qualified applicant or candidate with a disability, unless such accommodation would cause an undue hardship for EVERSANA. The policy regarding requests for reasonable accommodations applies to all aspects of the hiring process. If reasonable accommodation is needed to participate in the interview and hiring process, please contact us at [email protected].

Follow us on LinkedIn | Twitter

EVERSANA Glassdoor Company Review
3.4 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
EVERSANA DE&I Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of EVERSANA
EVERSANA CEO photo
Jim Lang
Approve of CEO

Average salary estimate

$165000 / YEARLY (est.)
min
max
$140000K
$190000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
EVERSANA Hybrid Chicago, IL, USA
Posted 8 hours ago

Lead and inspire the copywriting team at EVERSANA INTOUCH® to craft compelling content that drives action and advances healthcare marketing goals.

Photo of the Rise User
Target Hybrid 7000 Target Pkwy N,NCD-0375 Brooklyn Park,MN 55445
Posted 24 hours ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony

Target's Cybersecurity team is looking for a skilled Senior Engineer to enhance threat detection capabilities using cutting-edge tools and intelligence.

Photo of the Rise User
Posted 3 hours ago

Seeking an experienced Oracle CC&B Technical Architect to lead critical technical implementations and architecture for Enbridge's utility technology solutions.

Photo of the Rise User
Flexport Hybrid San Francisco, California, United States
Posted 23 hours ago

Flexport is seeking a Senior Systems Engineer to manage and secure SaaS collaboration tools and endpoint management platforms in a dynamic, mission-driven environment.

Photo of the Rise User

Contribute as a Workday Application Developer at the American Heart Association, enhancing integrations and system configurations to support vital health initiatives.

Photo of the Rise User

Experienced Epic Willow Application Analyst needed at Intermountain Health to support and optimize healthcare IT systems onsite in Broomfield, Colorado.

DaVita Hybrid 06797 - DPS CKD OPS
Posted 4 hours ago

Epic Analyst II role at DaVita focusing on building and supporting Epic CKD modules to enhance nephrology practice workflows and patient care.

Photo of the Rise User
Posted 9 hours ago

Lead enterprise-scale infrastructure design and implementation as Principal IT Systems Engineer at iPipeline, a pioneering software provider in the insurance sector.

Experienced Network Administrator needed to support enterprise network operations and cybersecurity for defense communications at Picatinny Arsenal under a veteran-owned joint venture.

Meredith Hybrid New York, NY - 225 Liberty Street
Posted 13 hours ago

A dynamic End-User Support Administrator position at Dotdash Meredith offering hands-on technical support within an in-office IT Service Desk team.

Photo of the Rise User

Lead Montana State University's network infrastructure as Director of Network Services, managing technical projects and staff to ensure superior network performance and security.

Odyssey Systems is looking for a Cybersecurity Compliance Specialist to ensure DoD and Air Force cybersecurity standards are met on-site at Hanscom AFB.

PNC Hybrid Cleveland Ops Ctr - North Annex (OH005)
Posted 10 hours ago

Experienced Business Systems Analyst needed at PNC in Cleveland to support technology applications and improve business processes in access control systems.

Photo of the Rise User
Posted 10 hours ago

Verathon seeks an experienced Business Systems Analyst III to lead ERP system design, configuration, and support in a dynamic medical device environment.

A Vision to Advance Life Sciences Services “Sana” is latin for healthy. So naturally, when service leaders – spanning the patient experience to global channel distribution – combined into one powerful platform, we became EVERSANA. Together, we w...

64 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
July 25, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!