Responsibilities
• Define and lead the global cyber compliance program
• Set the vision and drive execution for AI, automation and GRC platform capabilities
• Own and evolve Lilly's multi-framework compliance program
• Maintain a current-state, executive-ready view of how Lilly's cyber control environment satisfies each applicable regulatory framework
• Drive effort to create and sustain inspection-ready documentation
• Serve as Lilly's primary internal and external subject‑matter authority on cyber regulatory interpretation
• Serve as the service owner for the LogicGate Risk Cloud compliance module
• Champion and deliver AI‑augmented compliance capabilities
• Design and implement lightweight, scalable compliance processes that eliminate bottlenecks
• Collaborate with Cyber service areas
Requirements
• Bachelor's degree in Information Security, Computer Science, Risk Management, Operations Research, or related field
• 12+ years of dynamic experience in cybersecurity compliance, risk management, GRC, or data operations roles within complex, global technology environments
• Experience designing and operating multi‑framework compliance programs that prioritize controls based on risk rather than static regulatory checklists
• Hands‑on experience implementing or operating a modern GRC platform (LogicGate, ServiceNow GRC, Archer) at enterprise scale
• Experience in highly regulated, multinational environments with demonstrated regulatory engagement, inspection support, and audit management success (FDA, EMA, ISO, NIS2, or equivalent)
• Qualified applicants must be authorized to work in the United States on a full‑time basis
• One or more certifications required or to be obtained within 12 months of hire: CISSP, CISA, CRISC, CISM, or equivalent advanced cybersecurity certification