At a Glance
- Tasks: Lead IT risk management and ensure compliance with governance frameworks.
- Company: Join Mundipharma, a global healthcare innovator making a real difference.
- Benefits: Flexible benefits, learning opportunities, and a collaborative work environment.
- Other info: Diversity and inclusion are at the heart of our culture.
- Why this job: Be part of a team that drives impactful change in healthcare.
- Qualifications: Degree in IT and experience in GRC roles preferred.
The predicted salary is between 60000 - 60000 £ per year.
Join us and make a difference when it matters most! At Mundipharma, we are proud of the work we do to bring innovative treatments to patients. We challenge ourselves constantly to deliver more for patients, healthcare professionals, our partners, and our employees.
The IT Governance, Risk & Compliance (GRC) Specialist will join the IT team at Mundipharma ensuring the organisation understands its key risks and manages them appropriately in line with its risk appetite, while maintaining effective governance, controls, and oversight. Translating requirements into practical, proportionate controls embedded across business and technology processes, and ensures suitable evidence is maintained to demonstrate compliance and control effectiveness.
Role and Responsibilities
- Lead the end-to-end IT risk management practice, ensuring legal obligations are met and enterprise risks are detailed, owned, mitigated, and clearly communicated to leadership.
- AI Governance & Risk Management - Establish and oversee AI risk frameworks, ensuring the responsible, transparent, and compliant use of AI technologies across all organizational use cases.
- Policy Framework & Governance: Maintain and review IT policies, partnering with department heads to identify documentation gaps, execute review cycles, and drive continuous policy improvement.
- Conduct regular audits of internal IT processes to verify compliance with governance frameworks and implement structured remediation plans.
- Act as the primary point of contact for internal and external IT audits, coordinating with system owners to deliver consistent responses while minimizing operational disruption.
- Identify, track, and remediate potential audit risks and control weaknesses proactively to prevent formal audit findings.
- Build and sustain strong working relationships with internal audit teams to ensure ongoing alignment between IT operations and enterprise governance goals.
- Manage and administer IT governance, security, and policy training programs across IT and the wider business via the Global Learning Management System (LMS).
- Support the development of engaging training content and deliver regular compliance reporting against key performance indicators.
- Maintain macro- and micro-level risk reporting for IT leadership while collaborating with global training and compliance teams to adopt best practices.
What you’ll bring
- University or Master’s degree in IT (or related field), backed by proven experience managing risks within an IT organisation.
- Previous experience in an IT Governance, Risk & Compliance (GRC) related position in the Pharmaceutical industry would be advantageous but other industries would be considered.
- Deep understanding of audit operations and a track record of successfully managing responses to both internal and external audits.
- Sound knowledge of core GRC practices and industry frameworks, such as ISO 27001, ISO 9001, ITIL, and COBIT.
- Expertise in quality management principles, policy governance, and administering Document Management Systems.
- Experience using GRC platforms like Vanta (preferred) and creating SCORM-compliant training content with Articulate would be advantageous.
- Practical experience implementing ITIL processes and collaborating directly with cybersecurity teams to mitigate risk.
- Excellent negotiation and global stakeholder relationship-building skills with the ability to influence management-level stakeholders in a global environment.
- Strong process mindset with a proven ability to spot improvement opportunities and lead them through to completion.
- Adaptable, solution-focused team player who enjoys learning new skills and driving a positive impact across the business.
What we offer in return
- Flexible benefits package
- Opportunities for learning & development through our varied programme
- Collaborative, inclusive work environment
Diversity and inclusion
Building an inclusive environment where people can thrive, grow and achieve their full potential is a priority. We believe this isn’t just the right thing, but also the smart thing to do. We are on a journey and will seek to move forward together through education and awareness to build a culture that welcomes and celebrates diversity and uniqueness. We will create a workplace environment where everyone can, every day, bring their authentic selves and is treated with dignity and respect.
About Mundipharma
Mundipharma is a global healthcare company focussing on customers across Africa, Asia Pacific, Canada, Europe, Latin America, and the Middle East. Mundipharma is dedicated to bringing innovative treatments to patients in the areas of pain management, infectious disease as well as other severe and debilitating disease areas. Their guiding principles, centered around Integrity and Patient-Centricity, are at the heart of everything they do.
Join our talent pool if you’re not sure this role is right for you but you’re keen to hear about future opportunities at Mundipharma, join our talent community and be the first to hear about new roles.
IT GRC Specialist employer: Mundipharma
Mundipharma is an exceptional employer, offering a dynamic and flexible hybrid work environment in the vibrant city of Cambridge, UK. With a strong focus on professional development, employees are encouraged to grow their skills while engaging with leading experts in the field of opioid agonist treatment therapy. The collaborative work culture fosters innovation and allows for meaningful contributions to global medical strategies.
StudySmarter Expert Advice🤫
We think this is how you could land IT GRC Specialist
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Mundipharma, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Mundipharma
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Mundipharma. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace IT GRC Specialist
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Mundipharma insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Mundipharma that you’re committed to staying ahead in the game.
How to prepare for a job interview at Mundipharma
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Mundipharma to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Mundipharma.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.