Governance, Risk and Compliance Lead

Governance, Risk and Compliance Lead

European Organization for Nuclear Research (CERN)

September 24, 2026November 8, 2026GenevaSwitzerland
Job Description
Job Posting Organization:
CERN, the European Organization for Nuclear Research, is a leading scientific research institution established to explore the fundamental structure of the universe. It employs physicists and engineers who utilize the world's largest and most complex scientific instruments to study fundamental particles. CERN's mission is to push the boundaries of science and technology, and it operates in multiple countries, fostering a diverse workforce that is central to its success. The organization values diversity and inclusion, which has been integral to its mission since its foundation.

Job Overview:
The Governance, Risk and Compliance Lead position within the Office of the CIO at CERN involves advising senior management and governance bodies on critical aspects such as data governance, architecture, cybersecurity, ICT risk, and compliance. The role requires establishing frameworks, principles, and accountabilities that facilitate the coherent and sustainable use of data and technology across CERN's federated environment. The successful candidate will lead and coordinate Governance, Risk, and Compliance activities, ensuring alignment across various departments and technical stakeholders while respecting distributed responsibilities. This position is pivotal in overseeing technology risk, compliance, audit, and vendor governance, collaborating closely with cybersecurity and other specialist functions to ensure a robust governance framework is in place.

Duties and Responsibilities:
  • Lead and coordinate Governance, Risk, and Compliance activities across the Office of the CIO (OCIO).
  • Drive alignment across departments, experiments, and technical stakeholders while respecting distributed responsibilities.
  • Oversee technology risk, compliance, audit, and vendor governance, coordinating with cybersecurity and other specialist functions.
  • Define and lead enterprise policy and governance frameworks across data governance, enterprise architecture, and technology risk.
  • Influence senior stakeholders and lead cross-Organization collaboration effectively.
  • Operate strategically in a federated environment with distributed responsibilities.
  • Ensure strong experience in enterprise risk, compliance, and assurance frameworks.
  • Maintain a broad understanding of cybersecurity and related risk frameworks, working effectively with specialist functions.
  • Analyze, define, and improve processes related to ICT systems and risk management. 1
  • Implement best practices for ICT security" style="border-bottom: 1px dotted #007bff !important;">security standards and policies.

Required Qualifications:
  • A Master's Degree or PhD or equivalent relevant experience in Information Technology or a related field.
  • Proven ability to define and lead enterprise policy and governance frameworks.
  • Extensive experience in influencing senior stakeholders and leading cross-Organization collaboration.
  • Strong experience in enterprise risk, compliance, and assurance frameworks.
  • Broad understanding of cybersecurity and related risk frameworks.
  • Technical competencies in architecture and design of ICT systems, process analysis, and risk management.
  • Behavioral competencies including creating vision and strategic partnerships, building relationships, and communicating effectively.

Educational Background:
Candidates must possess a Master's Degree or PhD in Information Technology or a related field, or have equivalent relevant experience that demonstrates their capability to fulfill the responsibilities of the position.

Experience:
The position requires extensive experience in defining and leading enterprise policy and governance frameworks, influencing senior stakeholders, and leading cross-Organization collaboration. Candidates should have a strong background in enterprise risk, compliance, and assurance frameworks, as well as a broad understanding of cybersecurity and related risk frameworks.

Languages:
Fluency in spoken and written English is mandatory, with a commitment to learn French being a desirable asset for the role.

Additional Notes:
The position is a limited duration contract for 5 years, with the possibility of extension up to 8 years and eligibility for an indefinite contract tenure. The working hours are set at 40 hours per week, with hybrid job flexibility. The role may require work during nights, Sundays, and official holidays as needed by the Organization. The job grade is classified as grade 8, and the position is open to applicants from all Member States and Associate Member States.
Apply now
Similar Jobs