Global Director - IT Governance, Risk & Compliance

D-ploy Prague, Czechia
Apply Now

D-ploy is a dynamic IT and Engineering Solutions company operating across the EMEA region, including Switzerland, Germany, Czech Republic, Austria, the UK, and the USA. We are committed to delivering reliable and efficient services to our clients through strong partnerships and a people-focused culture. We are seeking an experienced Global Director – IT Governance, Risk & Compliance to lead and further develop the organization’s global IT governance, compliance and risk management function. The ideal candidate will have extensive experience in IT governance, regulatory compliance, internal controls, risk management, audit programs and continuous improvement, preferably within a pharmaceutical, life sciences or similarly regulated environment. As Global Director – IT Governance, Risk & Compliance, you will define and implement the global IT governance, risk and compliance strategy. You will work closely with senior IT leadership and stakeholders across Quality, Validation, Information Security, Legal, Data Privacy, Internal Audit, Engineering and other business functions. You will be responsible for ensuring that IT processes, systems and services are aligned with business objectives, internal policies, regulatory requirements and recognized control frameworks. ResponsibilitiesIT Governance Strategy• Develop and implement the global IT governance, risk and compliance strategy. • Define and maintain relevant policies, procedures, objectives, functional plans and budgets. • Establish and continuously improve the IT governance framework across global IT operations. • Ensure IT governance activities remain aligned with business priorities and organizational objectives.

IT Risk and Compliance Management• Lead IT compliance, governance and risk management activities across the organization. • Develop and maintain effective IT risk management and compliance programs. • Identify potential IT risks, control weaknesses and areas of non-compliance. • Define and coordinate corrective actions and continuous improvement initiatives. • Work closely with IT, Quality, Validation, Engineering, Information Security, Legal, Data Privacy, Internal Audit and external audit teams.

Regulatory and Framework Compliance• Support compliance with applicable pharmaceutical, GxP, nuclear, cybersecurity and IT control requirements. • Ensure the appropriate implementation of relevant standards and frameworks, including GAMP 5, 21 CFR Part 11, CSV, CSA, ISO 27001, ITIL, COBIT and NIS2, where applicable. • Maintain awareness of regulatory and industry developments that may affect IT governance and compliance activities. • Ensure IT processes and systems comply with internal policies, quality requirements and applicable regulations.

Audits and Assessments• Plan and oversee IT compliance reviews, internal audits, health checks and risk assessments. • Coordinate gap assessments, control reviews and audit-readiness activities. • Support internal and external audits and ensure identified findings are addressed appropriately. • Monitor the implementation and effectiveness of remediation and improvement plans.

Performance Management and Reporting• Define and monitor relevant KPIs, SLAs, metrics and reporting processes. • Evaluate the performance and effectiveness of IT governance, compliance and risk management activities. • Prepare reports, recommendations and updates for senior management. • Use performance data and audit findings to support decision-making and continuous improvement.

IT Communications• Develop and oversee the IT communications approach. • Ensure IT-related information is accurate, consistent and aligned with organizational objectives. • Support effective knowledge sharing and communication across global IT teams and business functions. • Ensure communications comply with relevant legal, regulatory and internal requirements.

Supplier and Service Provider Management• Manage relationships with external suppliers and service providers. • Support supplier selection, contract negotiations and outsourcing activities. • Oversee service-level agreements and monitor supplier performance. • Identify and manage risks associated with third-party IT services.

Team Leadership• Lead, coach and develop the IT governance, risk and compliance team. • Allocate responsibilities and ensure effective workload management. • Manage employee performance, development and career progression. • Support succession planning and long-term capability development within the team.

General Management Responsibilities• Manage departmental priorities, objectives and budgets. • Support organizational transformation and continuous improvement initiatives. • Ensure activities are performed in accordance with relevant quality, safety, health, environmental and company requirements. • Promote a strong culture of compliance, accountability and risk awareness throughout the organization.