IT Risk, Compliance & Validation Lead

 

Purpose of the role

The IT Risk, Compliance & Validation Lead is a senior enterprise control leadership role accountable for the governance, risk direction and independent assurance framework that enables Digital Transformation & IT to demonstrate sustained compliance with regulatory, audit, policy, internal-control and computer system validation requirements.

The role sets the strategic direction, standards, decision rights and oversight mechanisms for IT compliance and validation across Pharming's global application landscape. It governs and assures work performed by qualified external partners and application or project teams rather than routinely authoring system-level protocols, test scripts or detailed validation deliverables.

Operating with broad autonomy and delegated authority, the role determines required assurance based on risk, provides independent challenge and may prevent release, implementation or continued use where material compliance or validation requirements are not met. Acceptance of material residual risk remains with the designated accountable executive or governance forum.

The IT Risk, Compliance & Validation Lead is the principal Digital Transformation & IT representative for SOX assurance, internal and external audits and regulatory inspections. The role advises senior leaders, maintains enterprise audit readiness, directs evidence and remediation governance, and holds internal owners and external providers accountable for sustainable control outcomes.

Reporting to the Head of Enterprise Applications, the IT Risk, Compliance & Validation Lead has global accountability for IT validation governance, compliance policy, control assurance, technology risk transparency and audit readiness. The role is accountable for:

 

  • Defining the global IT validation and compliance strategy, multi-year roadmap and annual assurance priorities.
  • Establishing policies, standards, governance principles, control frameworks, exception criteria and minimum evidence requirements proportionate to risk.
  • Defining and enforcing decision rights and accountability across application owners, project teams, Quality Assurance, Finance, Digital Transformation & IT and external partners.
  • Determining assurance scope and rigor based on system criticality, intended use, regulatory impact, control exposure and residual risk.
  • Providing independent assurance over validation and control activities and requiring remediation or additional evidence where conclusions are not adequately supported.
  • Leading Digital Transformation & IT representation during SOX assurance, internal and external audits and regulatory inspections, including senior-level interviews and response governance.
  • Maintaining an enterprise view of compliance health, validation status, control deficiencies, findings, exceptions, overdue remediation, trends and emerging exposure.
  • Exercising delegated stop or delay authority where material validation evidence, approvals or compliance requirements are insufficient.
  • Advising the Head of Enterprise Applications and governance forums on exposure, remediation priorities, investment needs and decisions on residual-risk acceptance.
  • Defining and assuring the operating model, qualification, quality, performance and capacity of outsourced validation and compliance services.

 

The role is accountable for the quality and effectiveness of the IT compliance and validation framework. Operational validation execution remains with qualified delivery teams and partners, while final acceptance of material enterprise risk remains with designated accountable leaders and governance forums.

 

Areas of responsibility:

 

IT compliance and validation governance

  • Own and evolve the IT validation strategy, compliance roadmap, policies, governance model and control framework.
  • Establish risk-based principles, decision criteria and tolerances for validation scope, rigor, approvals, exceptions and required evidence.
  • Define and enforce clear roles, decision rights and escalation paths across Digital Transformation & IT, Quality Assurance, Finance, business owners and external partners.
  • Measure framework adoption and effectiveness, identify systemic weaknesses or inconsistent application and sponsor corrective action and capability improvement.

 

 

 

Independent assurance and decision support

  • Direct risk-based oversight and independent quality assurance of validation approaches, control design and evidence produced by internal teams and external partners.
  • Determine whether the overall body of evidence supports go-live, release, continued operation or closure.
  • Challenge incomplete, inconsistent or unsupported conclusions and require additional evidence or remediation.
  • Exercise delegated authority to stop or delay implementation when material requirements have not been met.
  • Escalate material exposure with clear options and recommendations on remediation, alternative action or residual-risk acceptance to the appropriate governance body.

 

 

Audit, SOX, and inspection readiness

  • Lead the Digital Transformation & IT assurance plan and preparation for SOX, audits and regulatory inspections.
  • Direct evidence requirements, ownership, quality review, submission, traceability and readiness across multiple systems and control owners.
  • Maintain a sustainable, inspection-ready evidence and control environment rather than relying on ad hoc preparation.
  • Represent Digital Transformation & IT in senior audit interviews, walkthroughs, inspections and follow-up discussions.
  • Own response governance for observations and findings in partnership with Quality Assurance, Finance, application owners and accountable leaders.

 

 

Compliance risk and remediation oversight

  • Own the enterprise register and management view of IT compliance risks, findings, exceptions, remediation plans, validation status and overdue actions.
  • Assess the significance, systemic nature and potential business, regulatory and control impact of compliance gaps.
  • Hold remediation owners accountable for timely, sustainable corrective action and challenge inadequate responses.
  • Identify recurring or systemic issues and recommend changes to strategy, governance, controls, investment, processes, sourcing or supplier arrangements.
  • Provide executive-ready reporting on compliance health, trends, exposure, decisions and remediation confidence.

 

 

External validation service governance

  • Define the sourcing and operating model, qualification standards and service expectations for outsourced validation.
  • Lead technical and quality input to the selection, qualification and periodic reassessment of external partners.
  • Establish deliverables, quality criteria, review requirements, decision rights, escalation paths and performance measures.
  • Govern vendor quality, consistency, capacity, timeliness, risk and adherence to Pharming requirements.
  • Require and verify corrective action where services, controls or deliverables do not meet agreed expectations.



Policy management and organizational capability

  • Own the lifecycle, governance approval and adoption of relevant IT compliance and validation policies.
  • Ensure policies remain current, practical, proportionate and aligned with business change, emerging risk and applicable regulatory and audit expectations.
  • Provide authoritative interpretation and senior-level advice on complex IT risk, compliance and validation matters.
  • Set guidance, training expectations, governance materials and decision frameworks for application and project teams.
  • Build organizational capability and promote clear accountability, timely escalation, independent challenge and evidence-based risk decisions.

 

 

Qualifications and experience

  • Bachelor’s degree in information technology, life sciences, quality management, engineering, risk, audit, or a related field, or equivalent professional experience.
  • A master’s degree is preferred.
  • Typically 12+ years of progressive experience in IT compliance, technology risk, validation governance, quality assurance, audit or regulatory assurance, including substantial enterprise governance leadership.
  • Significant experience in pharmaceuticals, biotechnology, life sciences, healthcare or another regulated industry is mandatory.
  • Proven experience designing, implementing and improving enterprise governance and assurance frameworks rather than primarily executing system-level validation documentation.
  • Demonstrated leadership in regulatory inspections, SOX assurance and complex internal or external audits, including senior stakeholder representation and response governance.
  • Advanced experience assessing control design and effectiveness, evidence sufficiency, compliance exposure, system criticality and residual risk and translating conclusions into governance decisions.
  • Significant experience governing outsourced compliance, assurance or validation services, including supplier qualification, performance management and corrective action.
  • Demonstrated ability to influence and constructively challenge senior leaders, business owners, Quality Assurance, Finance, auditors, inspectors and external providers while maintaining independence.
  • Authoritative understanding of computer system validation, regulated application lifecycles, risk-based assurance, data integrity and sustainable control design.
  • Proven leadership of findings, exceptions, risk acceptance, remediation governance, executive reporting and systemic control improvement.
  • Relevant senior qualifications in audit, risk, quality, compliance or validation are strongly preferred.

 

Who we are

We’re built on a simple belief: people living with rare diseases deserve more.

Pharming is a global biotechnology company taking on some of the toughest rare disease challenges. We develop and commercialize innovative therapies for rare and ultra-rare immunological and genetic diseases with significant unmet need, where our scientific and commercial expertise, long-term commitment, and real partnership can help advance care.

We put patients at the heart of our work. Their insights, along with those of caregivers, clinicians, scientists, and partners, shape our strategy, guide our decisions, and help turn science into meaningful progress. We keep it simple, act with urgency, and get it done — expanding access to approved therapies, advancing high-value pipeline programs, and building a leading global rare disease company.


Our vision is simple: a world where people living with rare diseases don’t wait for progress or care. Together with the communities who inspire us, we’re opening new possibilities — proving that breakthroughs aren’t just discovered. They’re created together.

Ready to make a difference? Join us.

 

What it’s like to work here

At Pharming, every role helps move rare disease therapies closer to the people who need them. We make it happen together, across teams, disciplines, and borders, because breakthroughs don’t happen in silos. Rare diseases are complex, and meaningful progress takes people who ask better questions, challenge each other, and turn insight into action. Here, you won’t work on the sidelines. Pharming is a place for builders, problem-solvers, and bold thinkers who move with urgency, take ownership, and stay focused on what matters most: improving the lives of people living with rare diseases. Advancing rare disease care isn’t the work of one team or one leader. It’s all of us, building what’s next together.

 

In addition, we offer:

•    Competitive year salary

•    8.33% holiday allowance

•    A minimum of 30 vacation days for a healthy work-life balance

•    Excellent pension plan to secure your future