Director, Data & AI Risk Management

AstraZeneca UK - London Updated 17 September 2026
PharmaRegulatory AffairsQuality Assurancegdpcroinform

Job description

We're building a connected, end-to-end Enterprise AI engine - uniting data foundations, AI technology, process reinvention, and business-facing AI to accelerate results across the whole value chain. Success depends on being exceptional connectors : you'll actively leverage existing capabilities, celebrate and promote reuse, export breakthrough ideas across geographies and functions, and obsess over scaling impact rather than building in isolation. If you thrive in high-collaboration environments where your role is to turn complex, cross-functional problems into reusable, enterprise-wide capabilities - and where the measure of success is adoption and scale, not just innovation - you'll have the platform (and sponsorship) to make it real . The Director, Data & AI Risk Management , leads and delivers enterprise risk management activities that help AstraZeneca identify , assess, govern, report, and reduce Data & AI risk. The role provides practical risk advisory, consulting, governance, and risk appetite support across regulatory compliance, data protection, AI governance, and related risk domains. Reporting to the Senior Director, Data & AI Risk Management, the Director partners across Data & AI Trust and Assurance and with business and enabling functions to translate complex risk and regulatory expectations into clear decisions, proportionate mitigations, and measurable improvements in risk posture. The role also leads cross-functional projects and supports enterprise governance forums and Enterprise Risk Management reporting, enabling responsible and confident use of Data & AI at scale. Typical Accountabilities Provide trusted risk advisory, consulting, and risk appetite support across Data & AI risks, helping stakeholders make timely , proportionate, and well-informed decisions. Provide governance and business analysis support across regulatory compliance, data protection, AI governance, and other Data & AI risk areas, translating complex requirements into clear risk positions, decisions, and actions. Lead and/or project manage priority initiatives across Data & AI Trust and Assurance, irrespective of team boundaries, including Standards and Controls rollout and regulatory compliance programmes covering requirements such as the US Data Security Program, EU AI Act, European Health Data Space, and other emerging obligations. Improve visibility of Data & AI risk posture by developing clear narratives, indicators, dashboards, and insights on material exposures, trends, mitigations, residual risk, and progress against appetite. Engage business and functional stakeholders to build relationships and understand risk exposure, challenge the adequacy of mitigations, agree pragmatic remediation, and help drive residual risk and overall risk posture down. Lead selected aspects of Data & AI risk aggregation, analysis, and reporting for Enterprise Risk Management, senior leadership, and governance bodies. Facilitate risk assessments, workshops, and decision forums for complex or novel Data & AI use cases, balancing enablement, compliance, and protection of patients, the company, and its information and intellectual property. Synthesize complex issues into concise, executive-ready narratives; anticipate stakeholder concerns; navigate ambiguity; and influence decisions in high-stakes forums. Partner with Regulatory Intelligence, Legal, Compliance, Privacy, Cyber Risk, Enterprise Risk Management, Data Offices, and risk teams in R&D, Operations, Commercial, Enabling Units, and other business functions to align risk approaches and accountabilities. Work across Data & AI Trust and Assurance teams to accomplish shared goals, resolve cross-cutting issues, and deliver integrated outcomes across policy, standards and controls, assurance, monitoring, risk, and regulatory readiness. Identify opportunities to simplify and continuously improve Data & AI risk management processes, governance, reporting, and stakeholder experience while preserving effective oversight. Promote a culture of responsible, compliant, and value-focused use of Data & AI, demonstrating AstraZeneca values in all interactions. Education, Qualifications, Skills, and Experience Essential Bachelor's degree in business administration , Risk Management, Information/Data Science, Informatics, Computer Science, Economics, Law, or a related discipline, or equivalent relevant experience. Significant experience in risk management, assurance, governance, regulatory compliance, or second-line oversight within a complex, global organisation. Demonstrated experience assessing and managing data, technology, digital, and/or AI risks and translating complex issues into pragmatic business decisions. Strong project leadership and project management capability, including delivery through cross-functional and matrixed teams, such as Regulatory Compliance, areas of organisational risk, AI governance, or related disciplines. Experience providing risk advisory or consulting support, including risk appetite, mitigation, escalation, and risk acceptance discussions. Working knowledge of relevant Data & AI regulatory and compliance requirements, such as the US Data Security Program, EU AI Act, European Health Data Space, GDPR, GxP , NIS2, or comparable frameworks. Experience with governance forums, executive reporting, risk indicators, dashboards, or Enterprise Risk Management processes. Strong business analysis, facilitation, and problem-solving skills, with the ability to structure ambiguity and establish clear ownership and actions. This includes working across domains such as r

Stand out for this role

NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.

Tailor my CV now — free to try