D-ploy GmbH

Global Director - IT Governance, Risk & Compliance

D-ploy GmbH  •  Prague, CZ (Onsite)  •  1 hour ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

D-ploy is a dynamic IT and Engineering Solutions company operating across the EMEA region, including Switzerland, Germany, Czech Republic, Austria, the UK, and the USA. We are committed to delivering reliable and efficient services to our clients through strong partnerships and a people-focused culture.

We are seeking an experienced Global Director – IT Governance, Risk & Compliance to lead and further develop the organization’s global IT governance, compliance and risk management function.

The ideal candidate will have extensive experience in IT governance, regulatory compliance, internal controls, risk management, audit programs and continuous improvement, preferably within a pharmaceutical, life sciences or similarly regulated environment.

As Global Director – IT Governance, Risk & Compliance, you will define and implement the global IT governance, risk and compliance strategy. You will work closely with senior IT leadership and stakeholders across Quality, Validation, Information Security, Legal, Data Privacy, Internal Audit, Engineering and other business functions.

You will be responsible for ensuring that IT processes, systems and services are aligned with business objectives, internal policies, regulatory requirements and recognized control frameworks.

Responsibilities

IT Governance Strategy

  • Develop and implement the global IT governance, risk and compliance strategy.
  • Define and maintain relevant policies, procedures, objectives, functional plans and budgets.
  • Establish and continuously improve the IT governance framework across global IT operations.
  • Ensure IT governance activities remain aligned with business priorities and organizational objectives.

IT Risk and Compliance Management

  • Lead IT compliance, governance and risk management activities across the organization.
  • Develop and maintain effective IT risk management and compliance programs.
  • Identify potential IT risks, control weaknesses and areas of non-compliance.
  • Define and coordinate corrective actions and continuous improvement initiatives.
  • Work closely with IT, Quality, Validation, Engineering, Information Security, Legal, Data Privacy, Internal Audit and external audit teams.

Regulatory and Framework Compliance

  • Support compliance with applicable pharmaceutical, GxP, nuclear, cybersecurity and IT control requirements.
  • Ensure the appropriate implementation of relevant standards and frameworks, including GAMP 5, 21 CFR Part 11, CSV, CSA, ISO 27001, ITIL, COBIT and NIS2, where applicable.
  • Maintain awareness of regulatory and industry developments that may affect IT governance and compliance activities.
  • Ensure IT processes and systems comply with internal policies, quality requirements and applicable regulations.

Audits and Assessments

  • Plan and oversee IT compliance reviews, internal audits, health checks and risk assessments.
  • Coordinate gap assessments, control reviews and audit-readiness activities.
  • Support internal and external audits and ensure identified findings are addressed appropriately.
  • Monitor the implementation and effectiveness of remediation and improvement plans.

Performance Management and Reporting

  • Define and monitor relevant KPIs, SLAs, metrics and reporting processes.
  • Evaluate the performance and effectiveness of IT governance, compliance and risk management activities.
  • Prepare reports, recommendations and updates for senior management.
  • Use performance data and audit findings to support decision-making and continuous improvement.

IT Communications

  • Develop and oversee the IT communications approach.
  • Ensure IT-related information is accurate, consistent and aligned with organizational objectives.
  • Support effective knowledge sharing and communication across global IT teams and business functions.
  • Ensure communications comply with relevant legal, regulatory and internal requirements.

Supplier and Service Provider Management

  • Manage relationships with external suppliers and service providers.
  • Support supplier selection, contract negotiations and outsourcing activities.
  • Oversee service-level agreements and monitor supplier performance.
  • Identify and manage risks associated with third-party IT services.

Team Leadership

  • Lead, coach and develop the IT governance, risk and compliance team.
  • Allocate responsibilities and ensure effective workload management.
  • Manage employee performance, development and career progression.
  • Support succession planning and long-term capability development within the team.

General Management Responsibilities

  • Manage departmental priorities, objectives and budgets.
  • Support organizational transformation and continuous improvement initiatives.
  • Ensure activities are performed in accordance with relevant quality, safety, health, environmental and company requirements.
  • Promote a strong culture of compliance, accountability and risk awareness throughout the organization.

Requirements

  • Higher vocational education, university degree or equivalent professional experience.
  • At least 10 years of relevant professional experience in IT governance, risk management, compliance, internal controls, audit or a related area.
  • Proven experience in a senior leadership or management role.
  • At least 5 years of experience managing and developing teams.
  • Strong experience with IT governance, IT compliance, risk management, audit programs, internal controls and continuous improvement.
  • Strong understanding of IT infrastructure, IT processes, IT systems and service management environments.
  • Experience working within pharmaceutical, life sciences or another highly regulated industry.
  • Knowledge of GMP compliance and relevant control frameworks or industry standards, such as GAMP 5 and PIC/S.
  • Knowledge of Computer System Validation and assurance methodologies, including CSV and CSA.
  • Experience implementing or managing compliance programs, control frameworks, risk assessments and audit activities.
  • Strong understanding of KPIs, SLAs, performance reporting and budget management.
  • Experience working with internal and external auditors.
  • Excellent analytical, diagnostic and problem-solving skills.
  • Ability to assess complex risks and translate them into practical actions and recommendations.
  • Strong leadership, strategic thinking, planning and organizational skills.
  • Ability to manage change, competing priorities and unexpected or sensitive situations.
  • Excellent communication, collaboration and stakeholder management skills.
  • Ability to influence and work effectively with stakeholders at different organizational levels.
  • Fluent written and spoken English.
  • Willingness to provide a recent criminal record extract (not older than three months).

Desirable Experience

  • Experience with NIS2, PCI DSS, ISO 27001, ITIL or COBIT.
  • Knowledge of SSAE 16, ISAE 3402, SOC 1 or SOC 2.
  • Experience with FDA-related requirements, including 21 CFR Part 11.
  • Experience preparing control narratives, self-assessment documentation or audit evidence.
  • Experience managing outsourcing activities and third-party service providers.
  • Experience supporting automation, digitalization or IT transformation projects.
  • Experience leading change across global or matrix-based organizations.

Benefits

  • Broad range of activities, tasks, and projects
  • Flexible working conditions
  • Paid sick days
  • Vouchers (B-day voucher, wedding, and new born surprise)
  • Contributions to wellness programs (multisport card)
  • Fishing for Friends program – our referral program
  • Further development and professional advancement
  • Friendly and international working environment
  • Company-sponsored events
  • Competitive salary and various benefits

Is IT in your DNA?

D-ploy GmbH

About D-ploy GmbH

D-ploy is an IT Engineering and Consulting Company with a wide portfolio of services and solutions suitable for globally as well as regionally operating companies.

Our strength is in providing proven standard and individually tailored solutions helping our customers achieve their strategic and business goals.

Our core competencies are operational IT Infrastructure services and consulting in the areas of Service Management, Program and Project Management as well as Quality Management.

Company Profile

Founded in January 2003 in Kaiseraugst, Switzerland, D-ploy has been growing steadily by expanding its expertise, portfolio and geographical presence across Europe and in the US. Our main focus has always been on ensuring that IT enables the Business, supports value generation and contributes to the overall work efficiency. With the customer-centric attitude and pragmatic approach to IT, we became a trusted and preferred IT partner to many customers proving again and again, that we can do IT.

Building our expertise and establishing long-term partnerships with our customers, we understand the value of sustainable practices driven by compliance with industry standards and implementing best practices. Therefore, since 2016 D-ploy has been ISO 9001 and ISO/IEC 20000-1 and as of 2017 ISO/IEC 27001 certified.

We strive to continuously offer the most suitable and innovative service solutions to our current and future customers by staying agile, understanding the industry needs and keeping up to date on the market trends.

Industry
IT & Software
Company Size
201-500 employees
Headquarters
Kaiseraugst, CH
Year Founded
2003
Website
d-ploy.ch
Social Media