Global Director IT Governance, Risk & Compliance

Date: 30 Jul 2026

Location: Prague, Czech Republic, 19000

Company: curium

Summary of Position

The Group IT Governance, Risk & Compliance Director is responsible for ensuring that Curium’s global IT governance, risk management, compliance, communications and performance management activities are aligned with business objectives, regulatory requirements and internal policies. The role formulates and executes the corporate IT Compliance, Governance, Communications and Risk Management strategy, builds and maintains the IT governance framework, and drives continuous improvement across IT processes, controls and services.

The Group IT Governance, Risk & Compliance Director reports directly to the Group Chief Information Officer (CIO) and indirectly to the VP of Operations, Petten & MPF.

Essential Functions

  • Adheres to internal company policies and processes advised by respective internal teams, Compliance, HR SOPs, Quality, Legal, Data Privacy, Security and other relevant functions.
  • Develop, maintain and execute the corporate IT Governance, Risk & Compliance strategy, policies, procedures and functional plans, including associated objectives and budgets.
  • Build and maintain the corporate IT governance framework to support alignment, performance monitoring, reporting and continuous improvement across global IT operations.
  • Own and oversee corporate IT compliance, governance and risk management processes in partnership with IT, Quality, Validation, Nuclear, Engineering, Data Security, Legal, Data Privacy, Internal Audit and external audit teams.
  • Implement and maintain effective IT infrastructure compliance programs, risk management processes, health checks, internal audits, gap assessments and readiness assessments.
  • Support compliance with applicable pharmaceutical, nuclear, GxP, NIS2.0 and IT control requirements, including relevant frameworks such as 21 CFR Part 11, CSV/CSA, GAMP5, ISO 27001, ITIL and COBIT where applicable.
  • Identify weaknesses, risks and opportunities for improvement; develop and drive continuous improvement action plans across IT governance, compliance and control environments.
  • Monitor compliance and governance performance through appropriate KPIs, metrics, SLAs and reporting mechanisms.
  • Manage IT communications strategy to ensure effective, accurate and legally compliant knowledge transfer aligned with corporate objectives and vision.
  • Oversee departmental activities, supplier relationships, contract negotiations and service level agreements with third parties.
  • Lead, coach and develop directly managed employees, including work allocation, performance management, career development and succession planning.
  • Ensure work is performed in accordance with applicable safety, health, welfare, environmental, quality and company requirements.

Requirements

Must have Experience/Skills:

  • Higher vocational education or equivalent professional and intellectual ability.
  • 10+ years of professional experience, including experience in a leadership role.
  • 5+ years of experience leading a team.
  • Strong knowledge of business and pharmaceutical processes, IT infrastructure techniques, IT processes and systems.
  • Experience with IT governance, IT compliance, risk management, internal controls, audit programs and continuous improvement.
  • Knowledge of GMP compliance and/or control frameworks and standards, such as GAMP5 and PIC/S.
  • Knowledge of Computer System Validation methodologies, including CSV and CSA.
  • Strong understanding of metrics, SLAs, KPIs, budget management and effective communications.
  • Excellent oral and written English language skills, with strong communication and collaboration skills.
  • Strong analytical, diagnostic and problem-solving skills.
  • Ability to prioritize, manage change, respond to unexpected situations and handle sensitive or difficult situations with diplomacy.
  • Leadership, strategic and conceptual thinking, decisiveness, flexibility, planning and organization skills.

 

Nice to have Experience/Skills:

  • Experience with NIS2.0, PCI-DSS, ISO 27001, SSAE 16/ISAE 3402/SOC 1, SOC 2, ITIL and COBIT.
  • Experience with FDA-related requirements, including 21 CFR Part 11, narratives and control self-assessment documentation.
  • Experience supporting or overseeing automation projects within or outside a company/group environment.
  • Experience managing outsourcing activities and third-party service providers.
  • Ability to drive transformational change across global or matrix organizations.
  • Strong interpersonal and consultative approach with the ability to influence stakeholders at different levels.