At Daiichi Sankyo, we are united by a single purpose, to improve lives around the world through innovative medicines. With a legacy of innovation since 1899, a presence in more than 30 countries, and more than 19,000 employees, we are advancing breakthrough therapies in oncology, cardiovascular disease, rare diseases, and immune disorders. Guided by our 2030 vision to "be an innovative global healthcare company contributing to the sustainable development of society", we are shaping a healthier, more hopeful future for patients, their families, and society.
Purpose of the function
Join Daiichi Sankyo as the Global Head of Information Security Governance and lead the enterprise-wide Cyber Security Governance, Risk, and Compliance (GRC) for a top-tier global pharmaceutical company with critical assets in Germany, the US, and Japan. This key transformation leadership role will drive the redesign and operation of a scalable, automated cyber governance framework aligned with international best practices.
Your Role:
- Lead the global Cyber GRC strategy, setting long-term direction and driving execution across the organization.
- Continuously develop and improve the Daiichi Sankyo Cyber GRC Framework to ensure measurable adherence and anticipate future developments.
- Define and manage enterprise-level cyber policies, standards, and guidelines within the Daiichi Sankyo Management System.
- Own the enterprise-wide cyber risk management framework, enabling consistent risk assessment, reporting, and mitigation aligned with risk appetite.
- Ensure compliance with cyber-related regulations and contracts; lead audit readiness and support cyber audits.
- Develop and implement third-party and supply chain security strategies to manage ecosystem risks.
- Oversee cybersecurity due diligence and integration during mergers and acquisitions.
- Promote continuous improvement by embedding cyber risks into business decision-making and enabling effective policy adoption.
- Lead and develop a high-performing global Cyber GRC team and drive executive stakeholder engagement across the organization
Your Profile:
- Minimum 12+ years of experience in cyber security with senior or leadership roles in global organizations
- Advanced degree in Information Security, Cyber Security, IT Security, or related fields, or equivalent professional experience
- Relevant certifications such as CISSP, CISM, CRISC, CISA, ISO/IEC27001 Lead Auditor/Implementor or equivalent
- Proven strategic leadership in Cyber GRC, with expertise in frameworks like NIST CSF/800-53 and ISO/IEC 27000 series
- Experience building and managing enterprise management systems, control frameworks, and audit readiness
- Track record of driving compliance across multiple regulatory jurisdictions and managing contractual security requirements
- Strong communication skills to engage stakeholders at all levels and foster an inclusive, high-performance culture
- Experience leading international, cross-functional teams with strategic planning and operational excellence
- Fluent in German and English (written and spoken); knowledge of Japanese or experience working with Japanese teams is a plus
