Boston Consulting Group: Global management consulting firm specializing in business strategy and transformation.
10+ YOE10+ years in cybersecurity/GRC with federal compliance (CMMC, NIST SP 800-171/53, FedRAMP), experience with assessments/audit defense, AI governance, executive communication, and ability to obtain U.S. Secret clearance.
Alnylam PharmaceuticalsNASDAQ: ALNY: Develops RNAi therapeutics to treat rare and common diseases.
15+ YOE10+ Mgmt15+ years in cybersecurity/risk/compliance, 10+ years leading GRC teams; Bachelor’s in a relevant field required; strong knowledge of NIST, ISO, ERM; CISSP/CISM/CRISC/CISA preferred.
NIST CSF v2.0, NIST 800-53, ISO 27001, ERM, GxP, HIPAA, SOX, FDA, Computer System Validation (CSV), NIS2, IT SDLC
BJ's Wholesale ClubNYSE: BJ: Membership warehouse club selling groceries and general merchandise.
10+ YOE3+ MgmtBachelor's in a related field, 10+ years in IT risk/compliance with 3+ years of people leadership, deep SOX ITGC and PCI DSS experience, executive communication, GRC platform and AI/automation familiarity; relevant certifications preferred.
UNFINYSE: UNFI: Distributors of natural, organic, and conventional food products.
12+ YOE5+ Mgmt12+ years cybersecurity experience,5+ years leadership,BS in CS or related,industry cybersecurity certification,experience with SOC,VM,GRC,incident command,and vendor/MSSP management.
NIST CSF, ISO 27001, FAIR, Zero Trust, SASE, VPN, MSSP, SaaS
Crisis24: Integrated risk management and global crisis response solutions.
5+ YOE5+ years in strategic partner sales/alliances in insurance or risk domains, proven new business development and partnership management, strong negotiation and communication skills, willingness to travel within the Americas.
AlnylamNasdaq: ALNY: Developing and commercializing RNA interference (RNAi) therapeutics for diseases.
15+ YOE10+ MgmtBachelor's degree in a relevant field, 15+ years in cybersecurity/risk/compliance or audit, 10+ years leading GRC or risk teams, deep knowledge of NIST CSF, NIST 800-53, ISO 27001 and ERM; industry certifications (CISSP, CISM, CRISC, CISA) preferred.
NIST CSF v2.0, NIST 800-53, ISO 27001, Enterprise Risk Management (ERM), Computer System Validation (CSV), NIS2, GxP
Assoc Dir, Information Security Governance Risk & Compliance
Boston, Massachusetts, United States
$179k-$212k/yrHybridFull Time
Servier: Independent global pharmaceutical group developing innovative treatments for patients.
8+ YOE3+ Mgmt8+ years in information security GRC or related discipline, 3+ years leadership, expertise with risk frameworks, audit readiness, third-party risk, and strong executive communication.