Director, Internal Audit, IT and Digital
About The Role
The Director, Internal Audit is a key leader within Insmed's Internal Audit function, responsible for advancing a risk-based technology assurance program that strengthens technology governance, cybersecurity, risk management, and internal controls across the organization. Reporting to the Head of Internal Audit, you will serve as a trusted advisor to Technology, Digital, Information Security, and business leadership while leading technology assurance activities across cybersecurity, digital platforms, data, and enterprise technology environments. You will help shape the future of Internal Audit at Insmed by identifying emerging technology risks, advancing innovative audit approaches, and delivering practical insights that support business objectives and strengthen organizational performance. The Director will oversee the technology components of Insmed's SOX compliance program, coordinate closely with external auditors and co-sourced partners, and contribute to the development of a modern, scalable Internal Audit function aligned with the Global Internal Audit Standards. Success in this role requires balancing independent assurance with proactive business partnership, helping the organization manage evolving technology, cybersecurity, digital, and AI-related risks while supporting strategic growth and innovation. This is an exciting opportunity for a strategic, hands-on leader who enjoys partnering across the organization, challenging the status quo, and helping a growing global biotechnology company navigate technology risk while enabling digital transformation.
What You'll Do
In this role, you'll have the opportunity to lead Insmed's technology SOX compliance program, including IT General Controls (ITGCs), IT Automated Controls (ITACs), interfaces, and key report testing in collaboration with IT. You'll also:
- Develop and execute the technology SOX strategy, risk assessment, testing approach, and annual compliance plan.
- Coordinate technology-related SOX and audit activities with external auditors and co-sourced providers to drive quality, efficiency, and opportunities for reliance.
- Partner with IT and project stakeholders to evaluate the impact of planned and implemented changes to systems, applications, infrastructure, and business processes on the control environment.
- Execute technology-focused audits covering cybersecurity, infrastructure, cloud environments, enterprise applications, digital platforms, data governance, and emerging technologies.
- Partner with the Head of Internal Audit to develop and execute a risk-based technology audit plan aligned with strategic priorities and emerging risks.
- Oversee all phases of audit engagements and ensure work is performed in accordance with Internal Audit methodology and the Global Internal Audit Standards.
- Assess the effectiveness of technology governance, cybersecurity, risk management, and internal controls, providing practical recommendations that drive business value.
- Support the preparation of executive-level reporting and Audit Committee materials and present audit results and key insights to senior leadership, as appropriate.
- Partner with Technology, Digital, Data, Information Security, and business leaders to identify, assess, and respond to technology-related risks while serving as a trusted advisor who provides insights to strengthen decision making, governance, cybersecurity, and risk management practices.
- Participate in AI governance, data governance, and digital transformation initiatives while providing independent risk and control perspectives on emerging technology risks.
- Champion the use of data analytics, automation, and AI-enabled auditing techniques to enhance audit effectiveness and efficiency.
Who You Are
You have a minimum of a Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Accounting, Business Administration, or a related discipline along with 12+ years of progressive experience in IT audit, technology risk, cybersecurity, internal audit, or related advisory roles.
- CISA, required.
- Demonstrated experience leading technology audits, IT SOX programs, cybersecurity assessments, and technology risk management initiatives.
- Strong knowledge of IT General Controls (ITGCs), IT Automated Controls (ITACs), cybersecurity frameworks, cloud environments, and technology governance practices.
- Experience assessing technology risks within regulated environments.
- Proven ability to build relationships and influence stakeholders at all levels of the organization.
- Excellent communication, presentation, and executive presence, with the ability to influence and engage stakeholders at all levels of the organization, including senior leadership and the Audit Committee.
- Experience managing external service providers and co-sourced audit relationships.
Nice To Have (but not required)
- CPA, CIA, CISSP, CRISC, CDPSE, or other relevant professional certifications.
- Experience within the biotechnology, pharmaceutical, medical device, or broader life sciences industry.
- Experience supporting global organizations operating in regulated environments.
- Familiarity with Oracle, Workday, Veeva, ServiceNow, Microsoft Azure, AWS, or similar enterprise technology platforms.
- Experience evaluating cybersecurity programs, cloud environments, digital transformation initiatives, and emerging technologies.
Where You'll Work
This is a hybrid role based out of our Bridgewater, NJ office. You'll have the option to work remotely most of the time, with in-person collaboration when it matters most.
Travel Requirements
This role requires occasional travel (up to 15%).
Pay
$177,000.00-242,000.00 Annual
Life at Insmed
At Insmed, you'll find a culture as human as our mission—intentionally designed for the people behind it. You deserve a workplace that reflects the same care you bring to your work each day, with support for how you work, how you grow, and how you show up for patients, your team, and yourself.
Highlights of our U.S. offerings include:
- Comprehensive medical, dental, and vision coverage and mental health support, annual wellbeing reimbursement, and access to our Employee Assistance Program (EAP)
- Generous paid time off policies, fertility and family-forming benefits, caregiver support, and flexible work schedules with purposeful in-person collaboration
- 401(k) plan with a competitive company match, annual equity awards, and participation in our Employee Stock Purchase Plan (ESPP), and company-paid life and disability insurance
- Company Learning Institute providing access to LinkedIn Learning, skill building workshops, leadership programs, mentorship connections, and networking opportunities
- Employee resource groups, service and recognition programs, and meaningful opportunities to connect, volunteer, and give back
Eligibility for specific programs may vary and is subject to the terms and conditions of each plan.