1

Grc Director Jobs in Indiana (NOW HIRING)

Senior Director - GRC Engineer

Indianapolis, IN · On-site

$101K - $138K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Senior Director, Governance Risk and Compliance (GRC) Engineer is a senior leader within the Digital Legal Office (DLO) GRC & Service Management organization. The role translates the DLO ...

Manager, Cyber Security

Indianapolis, IN · Hybrid

$150K - $165K/yr

With one direct report, the Cybersecurity Manager must be capable of operating independently ... Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust) * Experience with PAM ...

Manager, Cyber Security

Indianapolis, IN · On-site

$150K - $165K/yr

With one direct report, the Cybersecurity Manager must be capable of operating independently ... Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust) * Experience with PAM ...

Manager, Cyber Security

Indianapolis, IN · On-site

$150K - $165K/yr

With one direct report, the Cybersecurity Manager must be capable of operating independently ... Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust) * Experience with PAM ...

... met as directed by the team lead and management. * Perform assigned vendor risk management ... Must have two to three years of external and/or internal information technology, auditing or GRC ...

Information Security Operations Lead/Manager

Carmel, IN · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... and GRC processes * Participate in the process to on-board new clients to enVista's managed ... Temporarily lead the Information Security team in the Director's absence (Manager) * Periodic ...

Senior AI Governance Analyst

Warsaw, IN · On-site

$60 - $67.60/hr

  • Medical

  • Life

The Sr Analyst is expected to be a self-directed executor who can also contribute proactive ... Experience with GRC platforms such as OneTrust, AuditBoard, ServiceNow, or similar, preferred

... met as directed by the team lead and management. * Perform assigned vendor risk management ... Must have two to three years of external and/or internal information technology, auditing or GRC ...

Information Security Operations Lead/Manager

Carmel, IN · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... and GRC processes * Participate in the process to on-board new clients to enVista's managed ... Temporarily lead the Information Security team in the Director's absence (Manager) * Periodic ...

Grc Director information

What are some common challenges a GRC Director faces when aligning compliance initiatives across multiple departments?

A GRC Director often encounters challenges such as differing departmental priorities, varying levels of compliance awareness, and inconsistent processes. Successfully aligning compliance initiatives requires strong communication, the ability to build consensus, and the development of standardized frameworks that can be adapted across departments. Regular cross-functional meetings and ongoing training can help overcome these barriers and ensure that all teams are working towards the same compliance objectives.

What is the difference between Grc Director vs Compliance Manager?

AspectGrc DirectorCompliance Manager
CredentialsCertifications like CRISC, CISA, or CISM often preferredSimilar certifications, often CCEP or CISA
Work EnvironmentOversees enterprise-wide risk, governance, and compliance strategiesFocuses on specific compliance programs within organizations
Industry UsageCommon in finance, healthcare, and large corporationsWidespread across industries, especially regulated sectors
Search IntentUnderstanding high-level risk and governance rolesLooking for specific compliance responsibilities

The Grc Director typically manages enterprise risk, governance, and compliance strategies at a high level, requiring broader oversight and strategic planning. In contrast, a Compliance Manager focuses on implementing and maintaining specific compliance programs within an organization. Both roles require similar certifications and are prevalent in regulated industries, but the Grc Director has a wider scope and strategic responsibilities.

What are the key skills and qualifications needed to thrive as a GRC Director?

To thrive as a GRC Director, you need deep knowledge of governance, risk management, and compliance frameworks, often supported by a relevant degree and certifications such as CISA, CRISC, or CISSP. Expertise with GRC software platforms, regulatory databases, and risk assessment tools is typically required. Exceptional leadership, strategic thinking, and communication skills enable effective cross-functional collaboration and influence at the executive level. These capabilities are critical for ensuring organizational resilience, regulatory adherence, and informed decision-making across the enterprise.

What does a GRC Director do?

A GRC Director oversees an organization’s Governance, Risk, and Compliance (GRC) programs. They are responsible for developing strategies and policies to ensure the company meets regulatory requirements, manages risks effectively, and maintains strong corporate governance. This role involves coordinating cross-functional teams, implementing compliance frameworks, and reporting to senior leadership on risk exposures and controls. The GRC Director also stays updated on changing regulations and industry best practices to protect the organization from legal and reputational risks.

Are GRC director jobs hard to get?

GRC Director roles are competitive and typically require extensive experience in governance, risk management, and compliance, along with relevant certifications such as CISA or CISSP. Strong leadership skills and knowledge of regulatory frameworks can improve chances, but the position often demands a proven track record in managing complex security and compliance programs.
What are the most commonly searched types of Grc jobs in Indiana? The most popular types of Grc jobs in Indiana are:
What are popular job titles related to Grc Director jobs in Indiana? For Grc Director jobs in Indiana, the most frequently searched job titles are:
What cities in Indiana are hiring for Grc Director jobs? Cities in Indiana with the most Grc Director job openings:
Infographic showing various Grc Director job openings in Indiana as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

Senior Director - GRC Engineer

Eli Lilly and Company

Indianapolis, IN

$101K - $138K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 9 days ago


Eli Lilly and Company rating

8.8

Company rating: 8.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

11th of 86 rated pharmaceutical


Job description

At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work-but it's work worth doing. If you're driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us.


The Senior Director, Governance Risk and Compliance (GRC) Engineer is a senior leader within the Digital Legal Office (DLO) GRC & Service Management organization. The role translates the DLO's privacy, AI, and data governance frameworks into effective, auditable, and increasingly automated control designs. The GRC Engineer bridges the gap between what regulatory and policy obligations require, and how those obligations are implemented as operational controls by business control owners across the enterprise.

The GRC Engineer leads the engineering team that ensures controls are well-designed, produce the evidence required for KRI/KPI measurement, and can be sustained and automated over time. They also have responsibility for the control maturity roadmap; synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a strategic plan that prioritizes where and how controls need to mature.

The GRC Engineer is the primary technical enablement partner for the DLO Embedded Team, equipping them to guide business control owners through implementation. This influence model requires a senior individual who can credibly engage at the right level across the enterprise, driving adoption of control designs with stakeholders who have contending priorities and significant organizational authority.

This role also serves as the DLO's peer-level liaison to Cyber Engineering and Security Architecture teams, ensuring that DLO-owned control designs are technically coherent with the broader enterprise security architecture, and that shared control boundaries are clearly defined.

Key Responsibilities1. Control Design & Architecture
  • Own end-to-end design of DLO-owned privacy, AI, and data governance controls-translating regulatory obligations, policy requirements, and risk appetite into auditable, repeatable control architectures.
  • Define and retain control design specifications for each control in the DLO GRC Framework, including test procedures, evidence requirements, data flows, and automation targets.
  • Apply privacy-by-design and AI-by-design principles throughout the control engineering lifecycle, from inception through deployment and ongoing sustainment.
  • Lead technical analysis to identify control gaps, design deficiencies, and automation opportunities; propose and drive remediation with appropriate urgency.
  • Develop and publish design documentation, technical specifications, and implementation guides that create consistency in how controls are built and validated.
  • Design control evidence outputs that directly feed KRI/KPI measurement-ensuring that what gets measured is a function of control design, not manual data collection.
2. Control Maturity Roadmap & Strategic Direction
  • Be responsible for the DLO control maturity roadmap-a multi-year strategic plan defining how DLO-owned controls will evolve in response to regulatory change, technology advancement, and enterprise risk posture shifts.
  • Synthesize inputs from GRC Analysts (risk assessments, control effectiveness ratings, gap analyses) and KRI/KPI performance data to identify where controls are underperforming, immature, or misaligned to risk appetite-and translate those findings into prioritized maturity initiatives.
  • Define maturity targets for each control domain (privacy, AI, data governance), establishing clear progression criteria from initial/ad-hoc through optimized/automated states.
  • Lead strategic planning processes that translate the roadmap into prioritized, funded, and governed initiatives with clear milestones, owners, and success metrics.
  • Anticipate regulatory and technology trends (e.g., EU AI Act enforcement, evolving NIST frameworks, agentic AI) and proactively incorporate their implications into control design direction and maturity targets.
  • Partner with GRC Analysts and Service Management to align the control maturity roadmap with the risk assessment calendar and service delivery capacity.
  • Engage DLO leadership and senior stakeholders regularly to communicate roadmap progress, emerging risks, and recommended strategic investments in control maturity.
3. Embedded Team & Business Control Owner Enablement
  • Serve as the senior technical enablement partner for the DLO Embedded Team, providing control design blueprints, reference architectures, and technical guidance that equip them to work effectively with business control owners.
  • Develop reusable control design frameworks, templates, and implementation patterns that business teams can adapt to their specific processes and technology environments.
  • Directly engage business control owners on complex or contested control designs-providing the technical authority and credibility required to resolve design disagreements, negotiate evidence requirements, and drive adoption of control standards.
  • Provide support and direction on how to translate assessment findings, incidents, and issues into actionable control improvements.
  • Triage and advise on sophisticated, ambiguous control scenarios where regulatory guidance, technical constraints, and business priorities must be carefully balanced.
  • Build engagement models that create a consistent control design culture across the enterprise-proactively sharing protocols, lessons learned, and design patterns.
4. Cyber Engineering & Architecture Partnership
  • Serve as the DLO's peer-level liaison to the CISO organization's Engineering and Security Architecture teams for matters of control design, technical integration, and shared control boundaries.
  • Ensure DLO-owned controls are technically coherent with enterprise security architecture-particularly where privacy, AI, and cybersecurity controls share infrastructure, tooling, or evidence sources.
  • Partner on control design reviews where DLO and Cyber controls intersect (e.g., data protection controls that serve both privacy and security objectives).
  • Evaluate and recommend privacy-enhancing technologies (PETs), AI governance tools, and GRC platform capabilities in coordination with Cyber Architecture's technology roadmap.
  • Coordinate with the AI Strategy & Digital Risk role to present a coherent DLO interface to the CISO organization.
5. GRC Platform & Automation Enablement
  • Partner with Service Management to design control configurations within the GRC platform (ServiceNow IRM), ensuring that what is designed can be operationalized, monitored, and reported against.
  • Provide engineering leadership for the automation and AI-enablement of control operations across DLO owned and non-DLO owned controls-identifying where intelligent workflows, AI agents, and tooling can reduce manual effort and improve control reliability.
  • Ensure that changes to the regulatory environment or technology landscape trigger appropriate design reviews and service updates, maintaining a living control ecosystem.
  • Contribute to the DLO service catalog by ensuring controls are represented as managed services with defined inputs, outputs, SLAs, and continuous improvement mechanisms.
Basic Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or a related technical field.
  • 10+ years of progressive experience in GRC, risk engineering, privacy engineering, or security architecture
  • 5+ years of experience focused on control design, implementation, or assurance at an enterprise scale.
  • Qualified applicants must be authorized to work in the United States on a full-time basis. Lilly will not provide support for or sponsor work authorization or visas for this role, including but not limited to
    F-1 CPT, F-1 OPT, F-1 STEM OPT, J-1, H-1B, TN, O-1, E-3, H-1B1, or L-1.
Preferred Qualifications
  • Demonstrated ability to translate regulatory and policy requirements into technical control specifications and implementation guidance.
  • Experience influencing senior team members on control design decisions in a matrixed, federated operating model.
  • Experience with GRC platforms (ServiceNow IRM preferred) including control configuration, evidence management, and reporting design.
  • Deep solid understanding of privacy and AI regulatory frameworks (GDPR, NIST Privacy Framework, NIST AI RMF, EU AI Act, U.S. state privacy laws).
  • Experience developing and owning control maturity roadmaps, including defining maturity models, setting progression targets, and aligning investment to risk posture.
  • Experience operating within a federated risk model, enabling business control owners rather than implementing controls directly.
  • Strong verbal and written communication skills, with demonstrated ability to convey technical control design concepts to non-technical senior leaders.
  • Experience in regulated industries-pharmaceutical, healthcare, or life sciences strongly preferred.
  • Professional certification in privacy, risk, or security (e.g., CIPP/E, CIPT, CRISC, CISSP, CDPSE).
  • Experience with privacy-enhancing technologies (PETs), AI governance tooling, or data classification technologies.
  • Familiarity with ISO 27001/27701, SOC 2 controls, or equivalent control frameworks.
  • Experience scaling control capabilities across a large, matrixed enterprise with multiple lines of defense.
  • Hands-on experience with control automation, including workflow orchestration, API-based evidence collection, or AI-assisted monitoring.
  • Prior exposure to 2nd/3rd line of defense coordination (Internal Audit, Enterprise Risk, Quality).
  • Track record of partnering with cybersecurity engineering and architecture functions on shared control design.

Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.


Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status.


Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia (AMECA), Black Employees at Lilly (BE@Lilly), Chinese Culture Network (CCN), EnAble, Evolve, Lilly Indian Network (LIN), Organization of Latinx at Lilly (OLA), Pride (LGBTQ+ Allies), Veterans Leadership Network (VLN) and Women's Initiative for Leading at Lilly (WILL).


Actual compensation will depend on a candidate's education, experience, skills, and geographic location. The anticipated wage for this position is

$154,500 - $226,600

Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly's compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees.

#WeAreLilly


What Eli Lilly and Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Eli Lilly logo

About Eli Lilly

Sourced by ZipRecruiter

Eli Lilly, based in Indianapolis, IN, US, is one of the pioneers in the pharmaceutical industry with a rich history dating back to 1876. This global pharmaceutical company focuses on discovering, developing, manufacturing and selling pharmaceutical products in approximately 120 countries. The company's product categories include endocrinology, oncology, cardiovascular, neuroscience, and immunology. Having invested over $9 billion in research and development in the past decade, Eli Lilly is also committed to creating high-quality medicines that meet real needs. As a recipient of several awards and recognitions, Eli Lilly is known for its focus on life-saving research and drug development. Their mission is to make medicines that help people live longer, healthier, and more active lives.

Industry

Pharmaceutical product wholesalers

Company size

10,000+ Employees

Headquarters location

Indianapolis, IN, US

Year founded

1876