Roche
Expert - Information Security & Privacy Governance
- Ubicación
- Madrid · Presencial
- Jornada
- Jornada completa
- Publicada
- hace 4 días
Qué piden
ImprescindibleSeguridad informáticaGRCEvaluaciones de riesgoGDPRISO 27001
ValorableAWSAzureGCPServiceNowDPIACCPANISTCISSP
La oferta
En Roche puedes ser tú mismo y sentirte valorado por tus cualidades únicas. Nuestra cultura fomenta la expresión personal, el diálogo abierto y las conexiones genuinas, donde eres valorado, aceptado y respetado por lo que eres, permitiéndote prosperar tanto de manera personal como profesionalmente. Así es como buscamos prevenir, detener y curar enfermedades y asegurarnos de que todos tengan acceso a la atención sanitaria hoy y para las futuras generaciones. Únete a Roche, donde cada voz importa.
La posición
As an Expert within Information Security & Privacy Advisory (ISPA), you move beyond "checking boxes" to become a high-impact partner for System Owners and global Engineering hubs.
The ISPA team serves as the strategic bridge between IT, business, and legal functions at Roche. You will lead critical security and privacy risk assessments to operationalize "Security and Privacy-by-Design" principles, ensuring complex digital initiatives, from AI platforms to enterprise systems, remain resilient, secure, and compliant.
Key Responsibilities
1. Expert Advisory & Risk Mitigation
- High-Risk Reviews: Execute Security Expert Reviews (SER) for complex, high-risk system landscapes, performing deep-dive technical and privacy evaluations.
- Risk Control & Mitigation: Negotiate risk-mitigating control objectives with business and technical stakeholders; ensure clear risk ownership and accountability.
- Technical Baselines: Collaborate on Security Design Patterns and Technical Baselines for emerging technologies, including Generative AI, Cloud-native security, and advanced data platforms.
2. Strategic Liaison & Regulatory Governance
- Data Privacy Partnership: Bridge IT, Legal, and Data Protection Officers (DPOs) to translate global legal requirements into technical and organizational controls.
- ISMS Guidance: Advise business and IT owners on navigating Roche's Information Security Management System (ISMS) framework and external legal mandates.
- Cross-Functional Support: Provide pragmatic guidance to strategic functions (e.g., R&D, Commercial, P&C) across global and local operational realities.
3. Agile Governance & Continuous Excellence
- Workflow Management: Utilize Integrated Risk Management (IRM) platforms (e.g., ServiceNow) to manage advisory queues with audit-ready consistency.
- Peer Assurance: Maintain high standards through a "Four-Eye" peer review culture and shared knowledge exchange across global team members.
- Process Innovation: Lead initiatives to streamline risk assessment workflows, identifying opportunities for automation and AI efficiencies.
Qualifications
Experience
- 10+ years in IT security, Governance, Risk, and Compliance (GRC) within complex, global environments.
- Proven track record conducting Information Risk Assessments, Data Protection Impact Assessments (DPIA), and Cross-Border Data Transfer reviews.
- Deep knowledge of international privacy frameworks (GDPR, CCPA/CPRA) and regulatory alignment (e.g., DoJ: 28 CFR Part 202).
- Demonstrated experience providing pragmatic, business-aligned security advice on high-value, strategic projects across matrixed organizations.
Technical & Architectural Skills
- Security Frameworks: Strong command of Information Security Management frameworks (e.g., ISO 27001, NIST).
- Cloud & AI Security: Practical insight into cloud platforms (AWS, GCP, Azure), AI orchestration layers, and Security/Privacy-by-Design principles.
- Technical Translation: Ability to translate complex legal and policy mandates into clear engineering requirements.
- Workflow Tools: Experience with Integrated Risk Management (IRM) systems (e.g., ServiceNow IRM) for workload tracking is a plus.
Education & Certifications
- Academic: Degree in Computer Science, Law, Information Technology, or equivalent practical experience.
- Certifications: Highly valued: CISSP, CISM, CRISC, AIGP, or ISO 27001 Lead Auditor. Significant plus: CIPP/E or CIPM.
Key Competencies
- Strategic Influence: Ability to build consensus across business, legal, and engineering teams by translating technical risks into clear business impact.
- Pragmatic Execution: Thrives in ambiguous, complex environments; balances high-quality, audit-scrutinized advisory with speed of delivery.
Quienes somos
Alcanzar un futuro más saludable es lo que nos impulsa a innovar. Juntos, más de 100.000 empleados en todo el mundo están dedicados a avanzar en la ciencia, asegurando que todos tengan acceso a la atención sanitaria hoy y para las futuras generaciones. Nuestros esfuerzos resultan en más de 26 millones de personas tratadas con nuestros medicamentos y más de 30 mil millones de pruebas realizadas con nuestros productos de Diagnósticos. Nos damos apoyo mutuamente para explorar nuevas posibilidades, fomentar la creatividad y mantener altas nuestras ambiciones, para poder ofrecer soluciones sanitarias que cambian la vida e impactan a nivel global.
Construyamos juntos un futuro más saludable.
Roche es una empresa que ofrece igualdad de oportunidades.