Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the ...
SECURITY ENGNIEER
South Plainfield, NJ · On-site
Information Security Engineer Location: Newark NJ Duration: Contract (in months) 8 Must Have Skills (Top 3 technical skills only): * Process Information Security Governance Risk and Compliance ...
SECURITY ENGNIEER
South Plainfield, NJ · On-site
Information Security Engineer Location: Newark NJ Duration: Contract (in months) 8 Must Have Skills (Top 3 technical skills only): * Process Information Security Governance Risk and Compliance ...
Director, Security Governance
$176K - $205K/yr
Leads IT Security Governance, Risk and Compliance program. (essential) Collaborates with IT Security Leader on building a culture focused on proactive risk management and security best practices ...
Director, Security Governance
$176K - $205K/yr
Leads IT Security Governance, Risk and Compliance program. (essential) Collaborates with IT Security Leader on building a culture focused on proactive risk management and security best practices ...
Information Technology - Information Security Officer (ISO)
Marana, AZ · On-site
$120 - $180/hr
Information Technology - Information Security Officer (ISO) Marana Main Health Center, 13395 N ... This position develops and maintains enterprise-wide security, governance, and risk management ...
Posted today
Information Technology - Information Security Officer (ISO)
Marana, AZ · On-site
$120 - $180/hr
Information Technology - Information Security Officer (ISO) Marana Main Health Center, 13395 N ... This position develops and maintains enterprise-wide security, governance, and risk management ...
Posted today
Contract. Job Decription: - The contractor will develop, revise, and maintain information security governance documentation. - The work includes creating technically accurate, enforceable ...
Quick apply
Contract. Job Decription: - The contractor will develop, revise, and maintain information security governance documentation. - The work includes creating technically accurate, enforceable ...
Head of Information Security
Belgrade, MT · On-site
$120 - $180/hr
... Information Security to lead our global Governance, Risk & Compliance (GRC) function ... Reporting directly to the CISO, you'll define and scale Unlimit's global security governance ...
Head of Information Security
Belgrade, MT · On-site
$120 - $180/hr
... Information Security to lead our global Governance, Risk & Compliance (GRC) function ... Reporting directly to the CISO, you'll define and scale Unlimit's global security governance ...
The Information Security Officer (ISO) is responsible for. providing enterprise leadership ... This position develops and maintains enterprise-wide security, governance, and risk management ...
The Information Security Officer (ISO) is responsible for. providing enterprise leadership ... This position develops and maintains enterprise-wide security, governance, and risk management ...
The Information Security Officer (ISO) is responsible for. providing enterprise leadership ... This position develops and maintains enterprise-wide security, governance, and risk management ...
The Information Security Officer (ISO) is responsible for. providing enterprise leadership ... This position develops and maintains enterprise-wide security, governance, and risk management ...
This role will focus on developing security governance frameworks, conducting risk assessments, and ensuring regulatory alignment. Responsibilities : • Develop, review, and maintain information ...
This role will focus on developing security governance frameworks, conducting risk assessments, and ensuring regulatory alignment. Responsibilities : • Develop, review, and maintain information ...
Data Security Governance Analyst (Hybrid Role) - New York, NY 10172
New York, NY · On-site
$70 - $75/hr
The Data Security Governance Analyst supports the enterprise data security and information protection program by defining, maintaining, and operationalizing governance frameworks, policies, and ...
Quick apply
Data Security Governance Analyst (Hybrid Role) - New York, NY 10172
New York, NY · On-site
$70 - $75/hr
The Data Security Governance Analyst supports the enterprise data security and information protection program by defining, maintaining, and operationalizing governance frameworks, policies, and ...
Information Security Project Manager (PMP) Immediate Contract | Hybrid | Fort Lauderdale, FL Are ... Ensure projects align with security governance, compliance requirements, and organizational ...
Quick apply
Information Security Project Manager (PMP) Immediate Contract | Hybrid | Fort Lauderdale, FL Are ... Ensure projects align with security governance, compliance requirements, and organizational ...
... Information Security to lead our global Governance, Risk & Compliance (GRC) function ... Reporting directly to the CISO, you'll define and scale Unlimit's global security governance ...
... Information Security to lead our global Governance, Risk & Compliance (GRC) function ... Reporting directly to the CISO, you'll define and scale Unlimit's global security governance ...
Senior GRC Information Security Systems Analyst - Direct Hire
Minneapolis, MN · On-site
$110K - $140K/yr
Senior GRC Information Security Systems Analyst Location: Minneapolis, MN (Preferred) or one of the ... This role is responsible for leading Governance, Risk, and Compliance (GRC) initiatives while ...
New
Quick apply
Senior GRC Information Security Systems Analyst - Direct Hire
Minneapolis, MN · On-site
$110K - $140K/yr
Senior GRC Information Security Systems Analyst Location: Minneapolis, MN (Preferred) or one of the ... This role is responsible for leading Governance, Risk, and Compliance (GRC) initiatives while ...
New
Chief Information Security Officer (CISO)
Denver, CO · On-site
$275 - $300/hr
Information Security Governance * Design and lead TCM's enterprise-wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800-53, covering corporate IT and OT ...
Chief Information Security Officer (CISO)
Denver, CO · On-site
$275 - $300/hr
Information Security Governance * Design and lead TCM's enterprise-wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800-53, covering corporate IT and OT ...
Chief Information Security Officer (CISO)
Denver, CO · On-site
$275 - $300/hr
Information Security Governance * Design and lead TCM's enterprise‑wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800‑53, covering corporate IT and OT ...
Chief Information Security Officer (CISO)
Denver, CO · On-site
$275 - $300/hr
Information Security Governance * Design and lead TCM's enterprise‑wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800‑53, covering corporate IT and OT ...
Chief Information Security Officer (CISO)
Denver, CO · On-site
$275 - $300/hr
Job Responsibilities Information Security Governance * Design and lead TCM's enterprise‑wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800‑53, covering ...
Chief Information Security Officer (CISO)
Denver, CO · On-site
$275 - $300/hr
Job Responsibilities Information Security Governance * Design and lead TCM's enterprise‑wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800‑53, covering ...
Senior Analyst, Information Security Governance, Risk, & Compliance
Commerce, CA · On-site
$121K - $152K/yr
Job Overview The Senior Analyst, Information Security Governance, Risk, & Compliance will be responsible for the corporate-wide Information Security GRC program. This person will work closely with ...
Senior Analyst, Information Security Governance, Risk, & Compliance
Commerce, CA · On-site
$121K - $152K/yr
Job Overview The Senior Analyst, Information Security Governance, Risk, & Compliance will be responsible for the corporate-wide Information Security GRC program. This person will work closely with ...
Senior Security Governance and Policy Analyst with Security Clearance
Washington, DC · On-site
$105K - $137K/yr
Key Responsibilities Serve as a principal security policy advisor to the Chief Information Security ... Provide security governance recommendations for both cloud and on-premise environments. Coordinate ...
Senior Security Governance and Policy Analyst with Security Clearance
Washington, DC · On-site
$105K - $137K/yr
Key Responsibilities Serve as a principal security policy advisor to the Chief Information Security ... Provide security governance recommendations for both cloud and on-premise environments. Coordinate ...
Reporting directly to the CITO, the CISO will own information security governance, compliance, risk management, and controls, ensuring that TCM's security posture satisfies the demands of ...
Reporting directly to the CITO, the CISO will own information security governance, compliance, risk management, and controls, ensuring that TCM's security posture satisfies the demands of ...
Information Security Governance * Design and lead TCM's enterprise-wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800-53, covering corporate IT and OT ...
Information Security Governance * Design and lead TCM's enterprise-wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800-53, covering corporate IT and OT ...
Information Security Governance information
See salary details
$29.5K - $42.3K
23% of jobs
$46.1K is the 25th percentile. Wages below this are outliers.
$42.3K - $55.1K
6% of jobs
$55.1K - $68K
5% of jobs
$68K - $80.8K
6% of jobs
The median wage is $89.2K / yr.
$80.8K - $93.6K
14% of jobs
$93.6K - $106.4K
8% of jobs
$106.4K - $119.2K
12% of jobs
$119.6K is the 75th percentile. Wages above this are outliers.
$119.2K - $132K
8% of jobs
$132K - $144.9K
8% of jobs
$144.9K - $157.7K
5% of jobs
$157.7K - $170.5K
3% of jobs
$29.5K
$94.9K
$170.5K
How much do information security governance jobs pay per year?
What is information security governance?
An Information Security Governance job focuses on establishing and maintaining an organization's security strategy, policies, and compliance framework. Professionals in this role ensure that security aligns with business objectives, regulatory requirements, and industry best practices. They define security policies, assess risks, oversee compliance, and provide guidance to stakeholders. This role often involves collaboration with IT, legal, and executive teams to mitigate security threats while supporting business goals.
What does someone in information security governance do?
Professionals in Information Security Governance regularly assess and update security policies, perform risk assessments, and ensure compliance with industry standards such as ISO 27001 or NIST frameworks. They often collaborate with IT, legal, and business teams to align security objectives with organizational goals and to address emerging threats. Regular activities may include preparing reports for leadership, facilitating security training sessions, and overseeing audits or incident reviews. This role is both strategic and collaborative, playing a key part in protecting the organization's information assets while supporting overall business operations.
What are the key skills and qualifications needed to thrive in information security governance?
To excel in Information Security Governance, a strong background in cybersecurity principles, risk management, compliance frameworks, and policy development is essential, often supported by a degree in information security or related fields. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, as well as certifications such as CISSP, CISM, or ISO 27001 Lead Implementer, is highly valuable. Exceptional analytical thinking, communication, and stakeholder management skills help professionals stand out in this role. These competencies ensure organizations effectively mitigate security risks, maintain regulatory compliance, and foster a culture of security awareness.

Other
Medical, Dental, Vision, Life, Retirement
Posted 6 days ago
Job description
About Servier
Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision.
Role Summary
The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the Associate Director, Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk methodology, strategic priorities, and maturity roadmap. The role provides oversight of information security risk management, policy governance, compliance, third-party risk management, control assurance, audit readiness, and risk reporting while directing operational execution through subordinate managers, analysts, contractors, and service providers. This position partners closely with Global Information Security, IT, Legal, Privacy, Procurement, Quality, Internal Audit, and business stakeholders to ensure risks are identified, assessed, communicated, and managed in alignment with enterprise requirements. The role serves as the primary GRC advisor and enables risk-informed decision making by translating information security risk into business, operational, regulatory, and financial impact. This is a high visibility leadership role with the opportunity to build and scale a modern GRC capability aligned to Servier's global cybersecurity strategy, enterprise risk expectations, regulatory obligations, and business growth.
Primary Responsibilities
Cyber Risk Management and Governance
- Establish and lead the US information security risk management framework across the affiliate
- Define risk assessment methodologies, risk taxonomy, scoring models, reporting standards, and escalation criteria
- Provide oversight and challenge of risk assessments performed by the GRC team
- Ensure information security risks are clearly defined, consistently assessed, and aligned to Group methodology and enterprise risk expectations
- Review material risks, treatment recommendations, mitigation strategies, and risk acceptance proposals before escalation
- Drive risk-based prioritization of remediation activities, investment recommendations, and control improvement initiatives
Local Risk Coordinator and GRC Program Leadership
- Serve as the senior US GRC leader responsible for coordinating information security risk governance across the affiliate
- Act as the primary US liaison to Global Information Security for GRC-related risk, compliance, policy, and assurance activities
- Establish governance routines, program cadences, reporting expectations, and execution standards for the US GRC function
- Ensure alignment between US affiliate execution and Global risk management methodology, policy baselines, and governance expectations
- Escalate material risks, systemic issues, overdue remediation, and governance concerns through US and Global governance channels
Governance, Policy and Control Assurance
- Establish governance expectations for information security policies, standards, procedures, control requirements, and exception management
- Sponsor the local information security policy lifecycle, ensuring alignment with Global baselines, US business requirements, and regulatory obligations
- Define the control assurance approach used to evaluate control design, implementation, effectiveness, and maturity
- Oversee control monitoring, compliance validation, gap analysis, and continuous improvement activities
- Define and monitor KPIs and KRIs measuring policy adoption, control maturity, security posture, remediation progress, and governance effectiveness
Third-Party Risk and Enterprise Risk Integration
- Establish the strategic direction for third-party information security risk management across the US vendor ecosystem
- Define governance requirements, risk acceptance criteria, assessment standards, and escalation paths for third-party engagements
- Partner with Procurement, Legal, Privacy, IT, and business stakeholders to ensure vendor security risks are appropriately assessed and managed
- Oversee integration of third-party security risk into enterprise risk management, procurement processes, contractual reviews, and business decision making
- Drive cross-domain alignment across Information Security, IT, Legal, Privacy, Procurement, Quality, and business functions
Audit, Compliance and Assurance Oversight
- Oversee information security audit readiness across internal audits, external audits, regulatory engagements, and assurance activities
- Establish governance over evidence collection, control validation, audit response, remediation tracking, and management reporting
- Ensure audit findings, compliance gaps, and control deficiencies are translated into clear risk treatment plans with defined owners, timelines, and measurable outcomes
- Partner with Internal Audit, Quality, Legal, Privacy, and Global Information Security to support assurance activities and regulatory expectations
Executive Engagement and Cross-Functional Influence
- Act as a trusted advisor on information security governance, risk, compliance, and assurance matters
- Translate complex information security risks into business, operational, regulatory, financial, and reputational impact
- Deliver executive-level reporting on information security risk posture, governance maturity, compliance status, control effectiveness, and remediation progress
- Support governance committees, leadership forums, business reviews, and strategic planning discussions with clear risk-based recommendations
- Represent US GRC priorities in Global information security and enterprise risk forums, influencing alignment where appropriate
Organizational Leadership and Capability Building
- Lead and develop the US Information Security Governance Risk and Compliance function
- Manage GRC managers, analysts, contractors, consultants, managed service providers, and supporting resources
- Define the GRC organizational structure, operating procedures, quality standards, workforce strategy, and capability development roadmap
- Build scalable and repeatable GRC processes aligned to information security maturity objectives and organizational growth
- Identify opportunities to improve efficiency through automation, process standardization, documentation quality, tooling, and operating model maturity
Education and Required Skills
- Minimum of 8+ years of experience in information security GRC, IT risk management, cybersecurity, compliance, audit, security operations, or related disciplines
- Minimum of 3+ years in a leadership role with responsibility for program ownership, people leadership, functional leadership, or management of managers
- Bachelor's degree preferred in Cybersecurity, Information Technology, Information Systems, Business, Risk Management, or a related field
- Deep expertise in information security risk frameworks and governance models, including NIST CSF 2.0, ISO 27001, PCI, SOX, FAIR, or similar methodologies
- Experience leading policy governance, third-party risk management, compliance oversight, audit readiness, control assurance, and remediation governance programs
- Strong executive communication skills with the ability to influence senior stakeholders in a global, matrixed organization
- Relevant certifications such as CISSP, CISM, CRISC, CISA, CGRC, FAIR, or equivalent preferred
Travel and Location
- Onsite in Boston preferred 1-2 days hybrid; Remote considered with occasional travel to Boston
- Estimated travel required: 5-10%
Servier's Commitment
Servier is committed to modeling diversity, equity, and inclusion within the industry. We are dedicated to fostering an environment that maintains equitable treatment for all and we welcome applicants who are passionate, committed, and innovative individuals. We encourage candidates to apply to our open roles as we are always willing to consider experiences and skills beyond what is listed in the job description.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Salary Range
The salary range for this role is $179,000-$212,000. An employee's pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs. We may ultimately pay more or less than the posted range, and the range may be modified in the future. Employees in this position are also eligible for Short-Term and Long-Term incentive programs. Servier also offers a competitive and comprehensive benefits package that includes benefits such as medical, dental, vision, flexible time off (Servier provides unlimited sick time and flex time, and does not accrue time off), 401(k), life and disability insurance, recognition programs among other great benefits (all benefits are subject to eligibility requirements). For more information on our benefits, please visit this link.