Padmi
AstraZeneca logo
AstraZeneca

oncology · biopharmaceuticals

Director - Cyber Security Access Governance and Compliance

ChennaiPosted 1 month ago
Technology ManagementStaff+Full Time; Regular
Apply at AstraZeneca

Opens the source posting on shine.com

Source description

About the role

View original

Director, Cyber Security Access Governance & Compliance Director, Cyber Security Access Governance & Compliance GCL: F Introduction to role: Are you ready to define how a global enterprise governs access at scale and turn control assurance into a competitive advantage In this role, you will build the strategy and execution of identity and access governance that safeguards our science, data, and platforms, so we can deliver lifechanging medicines to patients faster and with confidence. You will lead a high-impact program that reduces access risk, elevates stewardship, and produces auditready evidence across workforce, privileged, and external access. Working with brand-new platforms including Sail Point Identity Security Cloud and analytics, you will expand automation, raise certification quality, and accelerate remediation. Accountabilities: Direct the endtoend Access Governance & Compliance program, aligning initiatives to business objectives and industry guidelines while ensuring leastprivilege governance and auditready outcomes. Expand Sail Point Identity Security Cloud certification automation, uplift entitlement quality, and reduce manual effort through systematic application onboarding and control design improvements. Define and implement access governance policies, certification standards (scope, cadence, critical issue), evidence and retention requirements, Sod/toxic combination controls, and timeboxed exception management. Provide executivelevel mentorship on cyber risk, regulatory compliance, and data privacy as they relate to identity and access, including riskbased prioritization, compensating controls, and defensible outcomes. Design and implement governance health dashboards, exception registers, and automated evidence outputs to enable realtime control transparency and efficient audit support. Establish an access risk management framework and security metrics program with clear control objectives, benchmark targets, tier reporting, and recurring governance rhythms with service owners and collaborators. Chair access governance steering groups and partner with application owners, HR/vendor management, internal audit, compliance, and infrastructure/platform teams to drive ownership and timely remediation. Direct comprehensive governance assessments and testing, including certification quality reviews, manual attestations for nonintegrated apps, reconciliations against authoritative sources, and closure of systemic gaps via supervised plans. Own stewardship health by defining data quality standards and supervising key attributes such as identity completeness, group/role ownership, entitlement ownership, and application owner accountability for human and nonhuman identities. Set a multiquarter plan for Access Governance & Compliance, mentor and develop managers and practitioners, and build capabilities in certification design/QA, control testing, data stewardship, and analytics. Deliver and supervise budgets, capacity plans, and investments to support operations, reporting/analytics enablement, and continuous improvement within agreed constraints. Lead multiregional initiatives and drive largescale change through teams and partners; produce executiveready dashboards and tier reporting to increase accountability and speed remediation. Essential Skills/Experience: 15+ years of experience in developing and implementing enterprise-wide cyber security strategies and frameworks, specifically as applied to access governance, control efficiency, and audit-ready evidence. Proven record developing and completing long-term strategic plans that measurably improve governance outcomes Confirmed expertise in reducing cyber risk in large, global enterprises through least-privilege governance, SoD management, and continuous control monitoring. Experience partnering with or operating alongside operational teams (e.g., IAM Operations and/or SOC) to ensure governance signals drive timely remediation and sustained control health. Proven experience working with cyber threat vectors, charge methodologies, and mitigation techniques relevant to identity and access Significant experience leading multiple large-scale cyber security systems/projects/processes, including governance automation Experience working within a quality and compliance environment and application of policies, procedures, and guidelines to meet audit and regulatory expectations. Experience co-working with multi-functional global leadership and other senior collaborators, influencing application owners and service owners to remediate risk and sustain governance outcomes. Desirable Skills/Experience: Relevant security certifications applicable to the governance/risk domain, preferred (e.g., security management, audit/risk, IAM/IGA platform certifications). When we put unexpected teams in the same room, we fuel bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect .

One address, no account. We’ll tell you when matching roles go live.

More at AstraZeneca

Related open roles

View all roles