Associate Director IT Compliance
About the Role
The Associate Director, IT Compliance is responsible for organising, leading, and continuously improving Novotech's IT Compliance function across a global CRO environment. This role provides leadership for IT governance, compliance assurance, audit readiness, vendor and sponsor audit responses, ISMS governance, ISO/IEC 27001:2022 certification activities, and regulatory compliance guidance for GxP computerised systems. It acts as a key interface between IT, Information Security, Quality Assurance, Legal, Privacy, Business Operations, system owners, sponsors, vendors, and external auditors.
Responsibilities
- Leadership of the IT Compliance Function: Lead, organise, and manage the global IT Compliance function, ensuring clear priorities, operating cadence, responsibilities, documentation standards, and service expectations. Act as the primary IT Compliance lead for technology governance, IT control assurance, IT audit readiness, and regulatory support.
- Vendor, Sponsor, and Regulatory Audit Management: Manage and coordinate IT responses to vendor, sponsor, client, and regulatory audits involving IT systems, IT practices, information security controls, and data privacy controls. Handle reviews related to emerging AI and Machine Learning capabilities and participate in strategy discussions related to AI.
- ISMS Governance and ISO/IEC 27001:2022 Certification: Manage and maintain Information Security Management System records, registers, evidence repositories, and governance documentation. Support the ongoing operation, monitoring, and continual improvement of Novotech's ISMS.
- GxP and Computerised System Compliance Guidance: Provide guidance to IT, Quality Assurance, system owners, and business process owners on regulatory compliance expectations for GxP computerised systems. Support interpretation and practical application of relevant regulatory and industry expectations, including GxP, computerised system validation, data integrity, 21 CFR Part 11, EU Annex 11, and GAMP 5-aligned risk-based validation principles.
- Governance, Risk, and Control Assurance: Lead or support technology risk assessments for new and existing systems, vendors, services, and IT processes. Identify control gaps, compliance risks, and documentation deficiencies, and work with accountable owners to define appropriate remediation or risk treatment plans.
- Vendor and Third-Party Compliance Oversight: Support supplier and vendor compliance assessments for technology vendors, cloud service providers, SaaS platforms, and GxP-relevant suppliers. Review supplier control evidence such as ISO certifications, SOC reports, validation documentation, security questionnaires, privacy documentation, and contractual compliance requirements.
- Documentation, Training, and Business Guidance: Own or contribute to IT Compliance policies, SOPs, work instructions, templates, guidance materials, and evidence packs. Translate complex regulatory, security, and quality requirements into practical, business-friendly guidance.
Key Deliverables
- Effective operation of the global IT Compliance function.
- Timely, accurate, and defensible IT responses to vendor, sponsor, client, and regulatory audits.
- Maintained and audit-ready ISMS records, evidence, registers, and governance artefacts.
- Successful support for ISO/IEC 27001:2022 certification, surveillance, and recertification activities.
- Clear compliance guidance for GxP systems, SaaS platforms, cloud services, and technology projects.
- Improved audit evidence reuse, response consistency, and inspection readiness.
- Well-maintained IT Compliance SOPs, work instructions, templates, and control documentation.
- Measurable tracking of IT compliance risks, findings, corrective actions, and continual improvement initiatives.
Qualifications
- Bachelor's Degree in Information Technology, Computer Science, Information Security, Quality, Life Sciences, Regulatory Compliance, or a related discipline.
- Significant experience in IT compliance, technology risk, governance, information security, quality systems, or regulated technology environments.
- Experience working in a regulated industry such as clinical research, pharmaceutical, biotechnology, medical device, healthcare, or life sciences.
- Demonstrated experience supporting vendor, sponsor, client, regulatory, or certification audits.
- Practical knowledge of ISO/IEC 27001, preferably ISO/IEC 27001:2022.
- Experience maintaining ISMS records, control evidence, risk registers, audit records, policies, procedures, or compliance documentation.
- Understanding of GxP computerised system compliance and risk-based validation principles.
- Familiarity with regulatory frameworks and expectations such as 21 CFR Part 11, EU Annex 11, GAMP 5, data integrity principles, GDPR, or other privacy/security obligations.
- Experience working with SaaS, cloud-hosted systems, vendor qualification, supplier audits, or third-party risk assessments.
- Experience engaging with cross-functional stakeholders across IT, QA, Legal, Privacy, Information Security, and business operations.
Preferred Qualifications
- ISO/IEC 27001 Lead Implementer, Lead Auditor, Internal Auditor, or equivalent certification.
- CISA, CRISC, CISM, CISSP, CGEIT, or other relevant governance, risk, audit, or information security certification.
- GxP, CSV, CSA, GAMP 5, or life sciences validation training.
- Privacy or data protection certification such as CIPP/E, CIPM, or equivalent.
- Experience in a Contract Research Organisation, clinical trial technology environment, pharmaceutical sponsor environment, or regulated SaaS ecosystem.
- Experience with ServiceNow, SharePoint, Smartsheet, Microsoft 365, GRC platforms, audit management tools, or document management systems.
- Experience with emerging AI technologies as related to GxP system validation and functions.
Pay
Salary Band - Associate Director IT Compliance: $160,000 to $180,000 USD. Salary offered will be based on the candidate's experience level.
Find out more about working at Novotech at: www.novotech-cro.com/careers
Novotech is proud to offer a great workplace. We are committed to being an employer of choice for gender equality and providing an inclusive work environment where everyone is treated fairly and with respect. Our team members are passionate about what we do, but we understand work is only one of the things that is important to them. We support our team members with flexible working options, paid parental leave for both parents, flexible leave entitlements, wellness programs, and ongoing development programs. We are looking for people who are passionate about working in clinical research and biotech, including people who identify as LGBTIQ+, have a disability, or have caring responsibilities. We are a Circle Back Initiative Employer and commit to responding to every application. We look forward to contacting you regarding your application.