Description
At Norstella, our mission is simple: to help our clients bring life-saving therapies to market quicker—and help patients in need.
Founded in 2022, but with history going back to 1939, Norstella unites best-in-class brands to help clients navigate the complexities at each step of the drug development life cycle —and get the right treatments to the right patients at the right time.
Each organization (Citeline, Evaluate, MMIT, Panalgo, The Dedham Group) delivers must-have answers for critical strategic and commercial decision-making. Together, via our market-leading brands, we help our clients:
- Citeline – accelerate the drug development cycle
- Evaluate – bring the right drugs to market
- MMIT – identify barrier to patient access
- Panalgo – turn data into insight faster
- The Dedham Group – think strategically for specialty therapeutics
By combining the efforts of each organization under Norstella, we can offer an even wider breadth of expertise, cutting-edge data solutions and expert advisory services alongside advanced technologies such as real-world data, machine learning and predictive analytics.
As one of the largest global pharma intelligence solution providers, Norstella has a footprint across the globe with teams of experts delivering world class solutions in the USA, UK, The Netherlands, Japan, China and India.
We are looking for a Governance, Risk, and Compliance (GRC) Engineer to support our global information security program. In this role, you will serve as a key liaison across multiple concurrent SOC 2 audit engagements, leading compliance and audit activities and driving evidence management and effective reporting. You will work directly with GRC leadership in driving risk assessments, customer assurance questionnaires, third-party risk management, policy development, vendor reviews, and compliance automation - while collaborating with team members and partners across the organization.
This is a hands-on role where communication, attention to detail, and strong organizational skills are critical. You will operate in a high-impact role with significant autonomy across a complex global compliance environment, working alongside a high performing team in the healthcare and data science spaces.
- External Audit Liaison & Management
Act as an extension of audit leadership in coordinating with external auditors across multiple concurrent SOC 2 engagements, including fielding auditor inquiries, coordinating with internal SMEs, and helping guide auditors and our internal resources through the organization’s control environment. Ensure each engagement stays on track and that auditors receive timely, accurate responses and documentation throughout the audit lifecycle.
- Audit Timeline & Readiness Management
Support the management of the end-to-end audit calendar by tracking milestones, deadlines, and deliverable due dates across multiple concurrent audits or compliance cycles (e.g., SOC 2, HITRUST). Proactively monitor progress against timelines, surface risks to audit leadership, and coordinate across teams to help maintain year-round audit readiness rather than point-in-time preparation.
- SME Coordination & Evidence Collection
Identify and engage subject matter experts (SMEs) across development, operations, legal, and other business functions to support audit and compliance activities. Prepare SMEs to participate in auditor interviews and walkthroughs by clearly communicating compliance requirements, expected evidence, and the scope of their involvement. Drive the structured collection, review, and organization of evidence across teams, ensuring completeness, accuracy, and timeliness under audit deadlines.
- Regulatory & Contractual Compliance Management
Ensure compliance obligations are tracked and evidence is properly collected and organized for audits, regulatory inspections, or customer reviews. You’ll help keep our organization audit-ready at all times.
- Audit Engineering & Automation
Bring hands-on experience with scripting or APIs to automate evidence collection and reduce manual toil, paired with a solid understanding of cloud environments.
- Policy & Standards Development
Contribute to the drafting and updating of policies by documenting processes, proposing improvements, and assisting with reviews under the guidance of senior team members.
- Risk Management & Assessment
Lead risk assessments and internal control testing with minimal direction, identifying control gaps, documenting findings, and driving remediation to closure. Translate risk outputs into actionable mitigation plans and communicate them clearly to stakeholders.
- Third-Party & Vendor Risk Management
Perform due diligence checks on vendors and partners, documenting outcomes and highlighting potential risks for senior team review.
- Security Architecture & Control Design Governance
Assist in reviewing technical designs against established compliance checklists, helping ensure new systems meet governance standards from the start.
Partner with our Learning Management team in delivering information security training and phishing campaigns, reinforcing compliance expectations and building awareness across the organization.
- AI/ML Governance & Responsible Use
Assist in monitoring AI/ML systems for compliance and help document reporting issues, contributing to our efforts to use emerging technologies responsibly.
A bachelor’s degree in Cybersecurity, Computer Science, Information Assurance, or a related field is preferred, but equivalent professional experience will also be considered. Relevant certifications (such as CISA, CRISC, or a GIAC certification) are strongly preferred.
At least 4 years of experience in GRC related fields, or equivalent experience gained by independently executing compliance and audit tasks. This is a role for someone who can operate as a lead on audit and compliance programs, running engagements with autonomy while keeping leadership informed.
- Experience managing external audit vendor relationships (assessor firms, QSAs) including scoping negotiations and cost/schedule estimation and management.
- Audit Process Proficiency
Proven experience managing multiple SOC 2 audit cycles end-to-end as the primary liaison between external auditors and the business, including evidence collection, validation, and report preparation. Comfortable operating as the day-to-day point of contact for auditors with minimal escalation.
- Regulatory & Framework Knowledge
Working knowledge of key regulatory frameworks such as HITRUST, ISO 27001, SOC 2, HIPAA, GDPR, or NIST. You should be able to independently apply and interpret these frameworks across audit and compliance programs.
- Industry & Domain Expertise
Familiarity with concepts in SaaS, cloud-native environments, or regulated industries like healthcare or life sciences. You bring relevant domain context that informs how you approach compliance in complex, regulated environments.
- Risk Analysis & Management
Demonstrated ability to independently identify, document, and drive mitigation of risks. Experienced in translating risk assessment outputs into business-relevant recommendations for leadership.
- Metrics & Reporting Ability
Independently build and maintain compliance metrics and reporting cadences for leadership. Comfortable turning raw data into actionable insights that drive program decisions.
- Policy Writing Abilities / Experience
Independently draft, update, and maintain policy documentation, ensuring accuracy and traceability to regulatory obligations. Able to own a policy domain with minimal oversight.
- AI/ML Governance & Responsible Use
Working knowledge of compliance and ethical considerations in AI/ML systems, with the ability to independently assess and document risk as these technologies are adopted across the organization.
01: Bold, Passionate, Mission-First
02: Integrity, Truth, Reality
03: Kindness, Empathy, Grace
04: Resilience, Mettle, Perseverance
05: Humility, Gratitude, Learning
- Health Insurance
- Provident Fund
- Reimbursement of Certification Expenses
- Gratuity
- 24x7 Health Desk
Norstella is an equal opportunity employer. All job applicants will receive equal treatment regardless of race, creed, color, religion, alienage or national origin, ancestry, citizenship status, age, physical or mental disability or handicap, medical condition, sex (including pregnancy and pregnancy-related conditions), marital or domestic partner status, military or veteran status, gender, gender identity or expression, sexual orientation, genetic information, reproductive health decision making, or any other protected characteristic as established by federal, state, or local law.
Sometimes the best opportunities are hidden by self-doubt. We disqualify ourselves before we have the opportunity to be considered. Regardless of where you came from, how you identify, or the path that led you here- you are welcome. If you read this job description and feel passion and excitement, we’re just as excited about you.
All legitimate roles with Norstella will be posted on Norstella’s job board which is located at norstella.com/careers. If a role is not posted on this job board, a candidate should assume the role is not a legitimate role with Norstella. Norstella is not responsible for an application that may be submitted by or through a third-party and candidates should proceed with extreme caution if a third-party approaches them about an open role with Norstella. Norstella will never ask for anything of value or any type of payment during or as part of any recruitment, interview, or pre-hire onboarding process. If you are aware of or have reason to believe a job posting purportedly for a role with Norstella is fraudulent or otherwise not authorized by Norstella, please contact the Company using the following email address: [email protected]