Context
Besins Healthcare is a fast-paced, fast-growing, international pharmaceutical company (~1,800 employees, €800M€ revenue) entering a critical phase of enterprise-wide transformation.
The organization is transitioning from a traditional IT operating model toward a product-driven, cloud-enabled, and data-centric environment, while operating within a highly regulated framework (GxP, data integrity, privacy, and global compliance).
Technology is becoming central to the company’s growth strategy — supporting:
- R&D and scientific innovation
- Supply chain and manufacturing
- Commercial and customer engagement
- Data-driven decision-making
In this context, cybersecurity is not only a risk function — it is a business enabler.
The Director of Cybersecurity will play a pivotal role in ensuring that security, compliance, and resilience are embedded into the organization’s transformation, without slowing innovation.
Role Mission
The Director of Cybersecurity is responsible for defining, implementing, and continuously evolving the organization’s cybersecurity strategy, risk posture, and security operating model.
The Director of Cybersecurity ensures that security is designed into systems and processes from the outset (“security by design”), enabling the business to scale safely in a complex regulatory and threat environment.
The successful candidate will have the opportunity to shape cybersecurity in a transforming organization, not maintain legacy, with direct exposure to executive leadership and strategic decisions, and the ability to influence a global, regulated, and growing business. The Director of Cybersecurity will be expected to find the right balance between governance, architecture, and pragmatic delivery, and play a critical role at the intersection of technology, risk, and business value.
Key Responsibilities
- Cybersecurity Strategy & Governance – Define and lead the enterprise cybersecurity strategy, governance framework and multi-year roadmap, aligned with business and technology transformation objectives, and tailored to a regulated pharma environment.
- Risk Management & Compliance – Own the cyber risk management framework and ensure alignment with GxP requirements, data privacy regulations (GDPR and equivalents), and industry best practices (ISO 27001, NIS2, NIST, etc.). Partner with Quality (CSV) to ensure validated systems remain secure, and security controls support audit readiness.
- Security Architecture & Security by Design – Embed Security by Design principles across products, platforms, cloud environments, enterprise applications and data ecosystems, in partnership with architecture, engineering and technology teams.
- Security Operations & Incident Response – Oversee cybersecurity operations, resilience, vulnerability management, incident response and crisis management capabilities, ensuring effective protection against evolving threats. Lead response to major security incidents, ensuring rapid containment, clear communication, and root cause resolution.
- Identity, Access & Data Protection – Define and strengthen identity and access management strategy (IAM) and data protection strategies to safeguard critical scientific, patient and business information. Drive implementation of least privilege models, identity federation, and zero trust principles where appropriate.
- Awareness & Culture – Promote a strong security culture across the organization by fostering awareness, shared accountability and alignment between business objectives and risk management practices.
- Leadership & Stakeholder Management – Build and lead a high-performing cybersecurity team (with internal & external partners) while acting as a trusted advisor to executive leadership, business stakeholders, external vendors, regulators and auditors.
Experience & Profile
The ideal candidates combines strategic vision, operational pragmatism, and deep understanding of regulated environments.
- 12–15+ years of experience in cybersecurity and IT risk.
- Proven experience in senior leadership roles (Director of Cybersecurity / Head of Security / CISO).
- Experience in complex, regulated environments (pharma, healthcare, manufacturing, or similar).
- Strong track record in building or transforming security functions, managing enterprise risk programs, and securing cloud and modern architectures.
A previous exposure to GxP environments and validation constraints (CSV), an experience in organizations undergoing digital / cloud transformation, or a familiarity with ERP environments and industrial systems would be greatly appreciated, as well as a background in both security strategy and operations.