Lead, Governance, Risk & Compliance (Remote)

Emergent Biosolutions
$155,500 - $188,200Remote

About The Position

Emergent is a leading public health company that delivers protective and life-saving solutions to communities around the world. The Lead for Governance, Risk and Compliance will oversee cybersecurity governance, risk management and compliance processes including the data protection and security awareness training programs. This position is an individual contributor role, reporting to the IT Vice President and CISO at Emergent. This role will initially focus on maturing enterprise-wide data protection capabilities, including data classification, data loss prevention, information protection and data governance frameworks. Over time, the role will expand to support Manufacturing OT security and oversee broader GRC functions, including cybersecurity risk management, regulatory compliance, security policies and standards and security governance. The ideal candidate combines strong cybersecurity expertise with program leadership, executive communications and experience implementing security programs leveraging governance and technologies. This position will be hands-on and require strong collaboration with various IT and business functions to satisfy our governance, risk management and compliance processes. This position is full-time remote.

Requirements

  • Bachelor’s Degree in Business or Information Systems, or equivalent experience.
  • 5+ years in cybersecurity, compliance, risk management or 7+ years of related/industry experience
  • Experience leading cybersecurity projects and programs
  • Experience working with cybersecurity tools, methodologies and technologies
  • Experience supporting cybersecurity programs within manufacturing environments, including familiarity with cybersecurity risks associated with industrial operation
  • Must understand network and computing, vulnerability management, IAM/PAM
  • Must be familiar with Sarbanes Oxley (SOX), SSAE 18 SOC reports, NIST CSF, ISO27001 and CMMC
  • Strong interpersonal and collaboration skills to work well with all IT and business stakeholders
  • Strong communication skills (oral, written, presentation) to influence across all levels of the organization
  • Adequate program management and organizational skills to ensure accuracy and timeliness of job duties
  • Must be able to author policy documents, provide business risk assessments, and communicate well with other teams.
  • Must be able to identify sensitive information, such as PII, PHI, Clinical Data, etc.
  • Demonstrated experience working across organizations to resolve conflicts
  • Demonstrated experience with organization-wide communications.
  • Demonstrated experience managing and documenting security risks.

Responsibilities

  • Lead implementation and governance of technologies supporting: Data Classification and Labeling, Data Loss Prevention (DLP), Insider Risk Management, Data Discovery and Inventory, Records and Information Management
  • Partner with business stakeholders to identify, classify, and protect information
  • Establish governance processes for data owners, custodians, and users
  • Define data protection metrics, KPIs, and reporting for executive leadership
  • Lead remediation efforts for large volumes of inadequately protected data
  • Oversee data protection policy compliance across all technology platforms
  • Drive adoption of data protection capabilities via training and change management
  • Lead the organization on improved maturity with regards to IS27001, CMMC or related industry certifications based on the NIST framework.
  • Lead cybersecurity maturity assessments and create/maintain cybersecurity KPI and metrics for efficient decision making with functional leaders
  • Establish and maintain cybersecurity governance frameworks and operating models.
  • Support various cyber councils, governance forums and program steering committees
  • Collaborate with IT and functional leaders to align cybersecurity initiatives with business objectives
  • Create and maintain the Cybersecurity risk register and support risk quantification and prioritization efforts that are appropriate for the environment
  • Partner with business leaders to evaluate technology, operational, third-party, data-related risks and document risk assessments and their approvals
  • Support risk reporting dashboards for executive management and governance councils
  • Assist the vulnerability management program to document risks and plans of actions.
  • Lead, own and develop new information security policies and review existing policies for updates and approvals
  • Lead, maintain and continuously improve security awareness and training programs, cybersecurity company-wide campaign, and
  • Lead cybersecurity audits internally and develop readiness activities. Support internal and external audits and assessments.
  • Support the manufacturing security program workstreams around network segmentation, secure remote access, logging and OT incident management.
  • Create and lead the cyber training and awareness for manufacturing sites
  • Support the execution of periodic BCP and Cybersecurity table top exercises

Benefits

  • merit increases
  • annual bonus
  • long-term incentives in the form of stock options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service