yoinka

Senior Director - GRC Engineer

Eli Lilly

Indianapolis, Indiana, United States of AmericaFull TimeStaff
Sign in to applyVerified 1h ago
Location
Indianapolis, Indiana, United States of America
Employment
Full Time
Work model
On-Site
Level
Staff
Posted
10h ago

About this role

At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us.  The Senior Director, Governance Risk and Compliance (GRC) Engineer is a senior leader within the Digital Legal Office (DLO) GRC & Service Management organization. The role translates the DLO’s privacy, AI, and data governance frameworks into effective, auditable, and increasingly automated control designs. The GRC Engineer bridges the gap between what regulatory and policy obligations require, and how those obligations are implemented as operational controls by business control owners across the enterprise. The GRC Engineer leads the engineering team that ensures controls are well-designed, produce the evidence required for KRI/KPI measurement, and can be sustained and automated over time. They also have responsibility for the control maturity roadmap; synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a strategic plan that prioritizes where and how controls need to mature. The GRC Engineer is the primary technical enablement partner for the DLO Embedded Team, equipping them to guide business control owners through implementation. This influence model requires a senior individual who can credibly engage at the right level across the enterprise, driving adoption of control designs with stakeholders who have contending priorities and significant organizational authority. This role also serves as the DLO’s peer-level liaison to Cyber Engineering and Security Architecture teams, ensuring that DLO-owned control designs are technically coherent with the broader enterprise security architecture, and that shared control boundaries are clearly defined.

Key Responsibilities

1. Control Design & Architecture Own end-to-end design of DLO-owned privacy, AI, and data governance controls—translating regulatory obligations, policy requirements, and risk appetite into auditable, repeatable control architectures. Define and retain control design specifications for each control in the DLO GRC Framework, including test procedures, evidence requirements, data flows, and automation targets. Apply privacy-by-design and AI-by-design principles throughout the control engineering lifecycle, from inception through deployment and ongoing sustainment. Lead technical analysis to identify control gaps, design deficiencies, and automation opportunities; propose and drive remediation with appropriate urgency. Develop and publish design documentation, technical specifications, and implementation guides that create consistency in how controls are built and validated. Design control evidence outputs that directly feed KRI/KPI measurement—ensuring that what gets measured is a function of control design, not manual data collection. 2. Control Maturity Roadmap & Strategic Direction Be responsible for the DLO control maturity roadmap—a multi-year strategic plan defining how DLO-owned controls will evolve in response to regulatory change, technology advancement, and enterprise risk posture shifts. Synthesize inputs from GRC Analysts (risk assessments, control effectiveness ratings, gap analyses) and KRI/KPI performance data to identify where controls are underperforming, immature, or misaligned to risk appetite—and translate those findings into prioritized maturity initiatives. Define maturity targets for each control domain (privacy, AI, data governance), establishing clear

Senior Director - GRC Engineer at Eli Lilly, Indianapolis, Indiana, United States of America | Yoinka