Take a look inside the world’s largest discreet leadership platform for technology leadership399 open mandates52 countriesEverything technology leaders need

Confidential mandate

EVP – Risk and Resilience — Clinical Data Organisation

Planned Hiring / New

EVP – Risk and Resilience mandate in Zurich, Switzerland · Biotechnology

Build a defensible risk system for a Zurich clinical-data platform as it integrates its analytics and evidence services into a global development portfolio.

The mandate

A clinical-data company in Zurich is negotiating a multi-year partnership that would embed its analytics and evidence services in a global development portfolio. The partnership requires the company to demonstrate that every output can be reconstructed from authorised source data through documented transformations and lineage records.

Weeks later, a specialist subcontractor supporting data ingestion suffered a ransomware outage. The company activated workarounds and met the immediate study deadline, yet recovery depended on individual knowledge, duplicate files and after-hours intervention. Existing risk registers had rated the supplier low because annual spend was modest; they did not capture its position in the clinical workflow. The events have not triggered a public regulatory action, but the board recognises that commercial scale now depends on demonstrable resilience and data trust.

The EVP – Risk and Resilience will create one enterprise framework across clinical quality, data governance, privacy, cyber security, third parties, business continuity and contractual risk. The role will not absorb independent quality or information-security accountability; it will make their evidence visible at the point where the executive team accepts commitments. The successful leader must convert controls into an operating capability that satisfies sponsors and regulators without turning scientists and delivery teams into risk administrators.

Approximately 300 employees and partners fall within the operating perimeter across Switzerland, the European Union, the United Kingdom and the United States. The EVP will be based in Zurich, report to the Chief Executive or designated executive sponsor and have direct access to the relevant board forum. The incoming partnership must not be signed until its data, service-level, audit and liability obligations are matched to capabilities or funded remediation.

Why this seat is open

This is a newly created executive role. Quality, privacy, cyber and continuity have developed separately under capable functional leaders, but no one owns their combined effect on a clinical-data service or a partner promise. The diligence finding and supplier outage demonstrated the gap. The board has authorised an enterprise seat rather than distributing additional controls among the existing functions.

What you will own

  • Map the end-to-end control chain for priority clinical-data products, from authorised source and consent through ingestion, transformation, statistical use, output, retention and deletion.
  • Establish an enterprise risk appetite and escalation model covering patient impact, regulatory evidence, privacy, cyber, partner delivery, subcontractors and financial exposure.
  • Lead the remediation of lineage gaps, ensuring manual transformations, code versions, approvals and exceptions can be reconstructed without relying on personal memory.
  • Redesign third-party criticality assessment around workflow dependency, data access, substitutability and recovery time rather than contract value alone.
  • Govern resilience tests for data ingestion, analysis and regulated reporting, including loss of a cloud region, a key supplier, privileged access or essential personnel.
  • Review the proposed partnership’s security, audit, service-level, data-use, incident, indemnity and termination terms; make unpriced obligations explicit before signature.
  • Convene quality, privacy, security, legal and delivery leaders around one evidence set while preserving functional independence and statutory accountabilities.
  • Build a small enterprise risk and assurance team and develop risk ownership among roughly 300 employees and material partners through scenario-based practice.

The first 12 months

  • Days 1–90: Complete a fact-based review of the lineage exception and supplier outage, close immediate risks and identify every live service with the same failure modes. Rank critical suppliers and workflows, agree interim partnership boundaries and give the board a transparent remediation and residual-risk view.
  • Months 4–9: Implement lineage and change-control requirements in the priority platform, renegotiate critical supplier provisions and conduct recovery exercises using real study deadlines. Agree the enterprise risk appetite, executive escalation thresholds and a contractual obligation register linked to operating owners and funded capabilities.
  • Months 10–12: Demonstrate reconstruction of selected clinical outputs, complete an independent assurance review and close the material diligence findings. Run a cross-border disruption exercise with executives and the board, confirm replacement or continuity options for critical suppliers and embed quarterly risk decisions in portfolio governance.

What the board will measure

  • Complete and timely closure of the partner-diligence findings, supported by evidence an independent reviewer and the counterparty accept.
  • Reconstructability of priority outputs from authorised source through every material transformation, approval and release step.
  • Recovery of critical data services within board-approved time and data-loss limits during tested scenarios, not only documented plans.
  • Coverage of critical suppliers through current assurance, incident notification, recovery, data-return and exit provisions, with unsupported exceptions explicitly accepted.
  • No material partnership obligation signed without a named operating owner, verified capability, cost and escalation path.
  • Reduction in repeat control exceptions and emergency workarounds while study delivery and scientific productivity remain within agreed service levels.

The person

You are an EVP, chief risk, quality, security or data-governance leader in clinical research, biotechnology, health technology, diagnostics or another regulated data business. Your 22–28 years include enterprise responsibility for services in which the integrity and availability of data affect regulatory or patient decisions. You have influenced at least 250 employees and controlled a risk, technology or remediation portfolio of at least CHF 100 million or equivalent.

You understand clinical-data lineage beyond labels. You can test how source, consent, transformations, code, review and release form a defensible record, and know when a manual step is acceptable only if it is controlled and reproducible. You have led a material cyber, privacy, quality or availability response and then changed architecture, supplier design or decision rights—not merely completed the incident report.

Candidates may come from clinical research, biopharma, regulated analytics, medical technology or financial and critical-infrastructure data services where auditability and continuity are comparable. Direct work with regulators, sponsors or independent assurance providers is required. You must be capable of negotiating contractual risk in commercial terms while refusing obligations that the organisation cannot honestly perform.

The role is based in Zurich with international travel for partner, supplier and assurance work. The board seeks a leader who makes risk concrete: able to explain the exact pathway from a control weakness to study, patient or contractual impact, then target investment accordingly.

Compensation and terms

The indicative base salary is CHF 340,000–470,000, with annual incentive and long-term participation. Measures will emphasise evidenced control, recovery performance, partner assurance and reduction of concentrated dependency rather than the volume of policies issued. This permanent appointment includes access to the relevant board forum. Relocation and demonstrable forfeited awards may be considered.

Confidentiality

The client, partner, supplier and affected datasets are intentionally unnamed. Identifying information will be shared only through the authorised search after candidate relevance and confidentiality protections have been established. Applicants must not seek to infer the parties through market contacts or reported cyber events.

Each response must contain no more than 49 words.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.