Responsibilities:
- Define and lead a global cyber compliance program transitioning to continuous, risk-responsive assurance.
- Own and evolve multi-framework compliance (FDA 21 CFR Part 11, GxP, ISO 27001, SOC 2, NIS2, HIPAA, CCPA, PIPL/CSL/DSL, emerging AI governance).
- Maintain executive-ready mapping of obligations to controls; lead gap analysis and risk-ranked remediation roadmaps.
- Drive inspection readiness (documentation, evidence packages, response protocols) and serve as cyber regulatory SME.
- Own LogicGate Risk Cloud compliance module (object hierarchy, workflow automation, integrations) and deliver AI-augmented capabilities (policy intelligence, automated evidence collection, advisory tooling).
- Optimize compliance processes; build data pipelines, predictive analytics, and data governance.
- Mature exception management and embed compliance into security operations.
- Lead cross-functional alignment and enterprise outcome-based reporting.
Qualifications:
- Bachelorβs degree in Information Security, Computer Science, Risk Management, Operations Research, or related.
- 12+ years in cybersecurity compliance/risk/GRC/data operations in complex global environments.
- Experience operating multi-framework, risk-based compliance programs.
- Hands-on enterprise GRC platform experience (LogicGate/ServiceNow GRC/Archer) and regulated inspection/audit success.
- US work authorization required (Lilly does not sponsor visas).
Certifications (within 12 months): CISSP, CISA, CRISC, CISM, or equivalent.
Preferred:
- MBA/MS; FDA/EMA/NIS2/ISO inspection knowledge; CSV/21 CFR Part 11; AI/ML governance (e.g., NIST AI RMF); OT/ICS (NIST 800-82, IEC 62443); data analytics (Python/R/SQL/Tableau/Power BI).
Benefits:
- Eligible for company bonus and comprehensive benefits including 401(k), insurance, vacation/leave, flexible benefits, and well-being.
Application instruction:
- For accommodation, complete: https://careers.lilly.com/us/en/workplace-accommodation