ActiveJobs
Pharming Group

Leiden IT Risk, Compliance & Validation Lead

Pharming Group

Full-timeOn-sitePosted 6 October 2026
Apply on Company Site →

Job description

IT Risk, Compliance & Validation Lead Purpose of the role The IT Risk, Compliance & Validation Lead is a senior enterprise control leadership role accountable for the governance, risk direction and independent assurance framework that enables Digital Transformation & IT to demonstrate sustained compliance with regulatory, audit, policy, internal-control and computer system validation requirements. The role sets the strategic direction, standards, decision rights and oversight mechanisms for IT compliance and validation across Pharming's global application landscape. It governs and assures work performed by qualified external partners and application or project teams rather than routinely authoring system-level protocols, test scripts or detailed validation deliverables. Operating with broad autonomy and delegated authority, the role determines required assurance based on risk, provides independent challenge and may prevent release, implementation or continued use where material compliance or validation requirements are not met. Acceptance of material residual risk remains with the designated accountable executive or governance forum. The IT Risk, Compliance & Validation Lead is the principal Digital Transformation & IT representative for SOX assurance, internal and external audits and regulatory inspections. The role advises senior leaders, maintains enterprise audit readiness, directs evidence and remediation governance, and holds internal owners and external providers accountable for sustainable control outcomes. Reporting to the Head of Enterprise Applications, the IT Risk, Compliance & Validation Lead has global accountability for IT validation governance, compliance policy, control assurance, technology risk transparency and audit readiness. The role is accountable for: Defining the global IT validation and compliance strategy, multi-year roadmap and annual assurance priorities. Establishing policies, standards, governance principles, control frameworks, exception criteria and minimum evidence requirements proportionate to risk. Defining and enforcing decision rights and accountability across application owners, project teams, Quality Assurance, Finance, Digital Transformation & IT and external partners. Determining assurance scope and rigor based on system criticality, intended use, regulatory impact, control exposure and residual risk. Providing independent assurance over validation and control activities and requiring remediation or additional evidence where conclusions are not adequately supported. Leading Digital Transformation & IT representation during SOX assurance, internal and external audits and regulatory inspections, including senior-level interviews and response governance. Maintaining an enterprise view of compliance health, validation status, control deficiencies, findings, exceptions, overdue remediation, trends and emerging exposure. Exercising delegated stop or delay authority where material validation evidence, approvals or compliance requirements are insufficient. Advising the Head of Enterprise Applications and governance forums on exposure, remediation priorities, investment needs and decisions on residual-risk acceptance. Defining and assuring the operating model, qualification, quality, performance and capacity of outsourced validation and compliance services. The role is accountable for the quality and effectiveness of the IT compliance and validation framework. Operational validation execution remains with qualified delivery teams and partners, while final acceptance of material enterprise risk remains with designated accountable leaders and governance forums. Areas of responsibility: IT compliance and validation governance Own and evolve the IT validation strategy, compliance roadmap, policies, governance model and control framework. Establish risk-based principles, decision criteria and tolerances for validation scope, rigor, approvals, exceptions and required evidence. Define and enforce clear roles, decision rights and escalation paths across Digital Transformation & IT, Quality Assurance, Finance, business owners and external partners. Measure framework adoption and effectiveness, identify systemic weaknesses or inconsistent application and sponsor corrective action and capability improvement. Independent assurance and decision support Direct risk-based oversight and independent quality assurance of validation approaches, control design and evidence produced by internal teams and external partners. Determine whether the overall body of evidence supports go-live, release, continued operation or closure. Challenge incomplete, inconsistent or unsupported conclusions and require additional evidence or remediation. Exercise delegated authority to stop or delay implementation when material requirements have not been met. Escalate material exposure with clear options and recommendations on remediation, alternative action or residual-risk acceptance to the appropriate governance body. Audit, SOX, and inspection readiness Lead the Digital Transformation & IT assurance plan and preparation for SOX, audits and regulatory inspections. Direct evidence requirements, ownership, quality review, submission, traceability and readiness across multiple systems and control owners. Maintain a sustainable, inspection-ready evidence and control environment rather than relying on ad hoc preparation. Represent Digital Transformation & IT in senior audit interviews, walkthroughs, inspections and follow-up discussions. Own response governance for observations and findings in partnership with Quality Assurance, Finance, application owners and accountable leaders. Compliance risk and remediation oversight Own the enterprise register and management view of IT compliance risks, findings, exceptions, remediation plans, validation status and overdue actions. Assess the significance, systemic nature and potential business, regulatory and control impact of compliance gaps. Hold remediation owners accountable for timely, sustainable corrective action and challenge inadequate responses. Identify recurring or systemic issues and recommend changes to strategy, governance, controls, investment, processes, sourcing or supplier arrangements. Provide executive-ready reporting on compliance health, trends, exposure, decisions and remediation confidence. External validation service governance Define the sourcing and operating model, qualification standards and service expectations for outsourced validation. Lead technical and quality input to the selection, qualification and periodic reassessment of external partners. Establish deliverables, quality criteria, review requirements, decision rights, escalation paths and performance measures. Govern vendor quality, consistency, capacity, timeliness, risk and adherence to Pharming requirements. Require and verify corrective action where services, controls or deliverables do not meet agreed expectations. Policy management and organizational capability Own the lifecycle, governance approval and adoption of relevant IT compliance and validation policies. Ensure policies remain current, practical, proportionate and aligned with business change, emerging risk and applicable regulatory and audit expectations. Provide authoritative interpretation and senior-level advice on complex IT risk, compliance and validation matters. Set guidance, training expectations, governance materials and decision frameworks for application and project teams. Build organizational capability and promote clear accountability, timely escalation, independent challenge and evidence-based risk decisions. Qualifications and experience Bachelor’s degree in information technology, life sciences, quality management, engineering, risk, audit, or a related field, or equivalent professional experience. A master’s degree is preferred. Typically 12+ years of progressive experience in IT compliance, technology risk, validation governance, quality assuranc

Verified and listed by ActiveJobs. Applications are made directly on Pharming Group's own career page — we never sit in the middle.