Audit Manager

Meraki Talent Ltd

Madrid

Presencial

EUR 140.000 - 200.000

Jornada completa

Hace 4 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Roche is seeking an IT Strategic Risk & Audit Manager to partner with Digital Technology leaders. You will steer enterprise risk across IT, audits, and compliance, ensuring regulatory alignment and proactive risk management in a global setting.

You will lead complex audits, advise executives, and guide Health Authority inspection readiness while upholding data integrity and overall digital trust within Roche’s global portfolio.

Formación

  • 15+ years of IT Risk/Audit experience in a global, highly regulated industry (Pharma, MedTech, or Finance).
  • Deep mastery of GxP (GLP, GCP, GMP), CSV (Computer System Validation), and Data Integrity principles (ALCOA+).
  • Expert knowledge of global risk frameworks (NIST, ISO 27001, COBIT) and privacy regulations (GDPR, HIPAA).
  • Certifications: mandatory possession of at least two of the following: CISA, CRISC, CISM, or CISSP.

Responsabilidades

  • Scope / (Content Leadership): Defines the strategic vision for IT risk, audit, and compliance, and drives strategic initiatives for long-term risk management success.
  • Strategic Risk Architecture & Vision: Define and architect the global IT Enterprise Risk Management (ERM) framework (NIST, ISO 27001, COBIT).
  • Accountability/Problem Solving: Leads analysis of highly complex business and risk challenges and develops risk management and compliance policies.
  • Stakeholder Management: Identifies and engages key stakeholders at executive level and external partners.
  • E2E Audit & Compliance Leadership: Lead full lifecycle of complex IT audits and continuous monitoring programs.
  • Inspection Command & Control: Serve as the primary IT liaison during Health Authority inspections (FDA, EMA).
  • Data Integrity & ALCOA+: Audit and enforce Digital Thread for health-regulated data integrity.
  • Global Stakeholder & Transformation Management: Navigate sensitive landscapes to lead enterprise-wide risk initiatives.

Conocimientos

IT Risk & Audit
GxP Compliance
ISO 27001
COBIT
NIST Framework
Executive Steering
Cloud Security
AI Governance
Regulatory Compliance

Descripción del empleo

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

At Roche, we believe every patient deserves a personalized healthcare solution. As the IT Strategic Risk & Audit Manager, you will play a pivotal role in ensuring that our digital evolution—from AI-driven drug discovery to personalized healthcare apps—is built on a foundation of trust and resilience. You will act as a strategic partner to Digital Technology leaders, ensuring that risks are managed proactively rather than reactively.

Job Responsibilities
  • Scope / (Content Leadership): Defines the strategic vision for IT risk, audit, and compliance, and drives strategic initiatives for long-term risk management success. Initiates and leads large, complex projects with a significant impact on the organization. Leads the development of enterprise-wide risk and compliance policies and advises on emerging trends and best practices.
  • Strategic Risk Architecture & Vision: Define and architect the global IT Enterprise Risk Management (ERM) framework (NIST, ISO 27001, COBIT), aligning long-term digital strategy with Roche's risk appetite to ensure "Compliance by Design" across complex, interconnected global portfolios.
  • Accountability/Problem Solving: Leads the analysis of highly complex business and risk challenges with significant organizational impact, proactively identifying potential strategic issues within your sphere of influence. Develops comprehensive risk management and compliance policies, implements proactive measures to avoid repeated issues, and leads initiatives to anticipate and mitigate future risks. Contributes to framing strategic questions and facilitates strategic decision-making at the executive level.
  • Stakeholder Management: Identifies and engages key stakeholders at the executive level and external partners, analyzing enterprise-wide stakeholder landscapes. Leads enterprise-wide risk, audit, and compliance initiatives, presenting them to executive leadership to secure support and strategic alignment for risk-related investments. Navigates highly complex and politically sensitive landscapes, acting as an organizational trust builder and providing expert counsel on critical strategic decisions.
  • E2E Audit & Compliance Leadership: Lead the full lifecycle of complex IT audits and continuous monitoring programs across infrastructure and applications, ensuring the organization meets global regulatory requirements while proactively identifying systemic issues to prevent recurrence.
  • Inspection Command & Control: Serve as the primary IT liaison during complex Health Authority inspections (FDA, EMA, etc.), leading "Front-Room/Back-Room" operations, coaching SMEs in regulatory interview techniques, and ensuring the rapid delivery of high-quality, validated evidence.
  • Data Integrity & ALCOA+ Systematically audit and enforce the "Digital Thread" to ensure all health-regulated data remains Attributable, Legible, Contemporaneous, Original, and Accurate, maintaining the integrity of life-saving digital health solutions.
  • Global Stakeholder & Transformation Management: Navigate sensitive landscapes to lead enterprise-wide risk initiatives, partnering with IT owners to develop robust remediation CAPAs and innovating risk management approaches to drive lasting, transformative impact across the global organization.
Qualifications
  • 15+ years of experience in IT Risk/Audit, preferably within a global, highly regulated industry (Pharma, MedTech, or Finance).
  • Deep mastery of GxP (GLP, GCP, GMP), CSV (Computer System Validation), and Data Integrity principles (ALCOA+).
  • Expert knowledge of global risk frameworks (NIST, ISO 27001, COBIT) and privacy regulations (GDPR, HIPAA).
  • Strong understanding of modern technology stacks, including Cloud Security (AWS/Azure), AI/ML governance, and Agile/DevSecOps methodologies.
  • Demonstrated experience presenting to and influencing Executive Leadership (C-suite) and Board-level stakeholders.
  • Proven ability to navigate a complex, global matrixed environment and steer senior leadership toward risk-aware decision-making through technical credibility.
  • Drives a culture of shared accountability, ensuring that compliance and risk management are viewed as strategic enablers rather than organizational hurdles.
  • Certifications: Mandatory possession of at least two of the following: CISA, CRISC, CISM, or CISSP.
Where pay applies

Where pay transparency applies, details are provided based on the primary posting location. For this role, the primary location is Madrid. If you are interested in additional locations where the role may be available, we will provide the relevant compensation details later in the hiring process.

Who we are

A healthier future drives us to innovate. Together, more than 100'000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Equal Opportunity Employer

Roche is an Equal Opportunity Employer.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

IT Strategic Risk & Audit Manager
IT Strategic Risk & Audit Manager

Roche • Madrid

Presencial
EUR 80.000 - 100.000
Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche • Madrid

Presencial
EUR 70.000 - 110.000
OSS Lead - RDT Quality, Risk & Compliance
OSS Lead - RDT Quality, Risk & Compliance

Roche • Madrid

Presencial
EUR 85.000 - 120.000
Data Security & Privacy Lead
Data Security & Privacy Lead

Roche • Madrid

Presencial
EUR 65.000 - 85.000
Data Governance & Data Management Specialist - RDT Performance and Insights
Data Governance & Data Management Specialist - RDT Performance and Insights

Roche • Madrid

Presencial
EUR 52.000 - 75.000
IT Software Engineer - RDT Engineering Excellence & Experience
IT Software Engineer - RDT Engineering Excellence & Experience

Roche • Madrid

Presencial
EUR 70.000 - 100.000
IT Project Manager - RDT Pharma R&D
IT Project Manager - RDT Pharma R&D

Roche • Madrid

Presencial
EUR 70.000 - 95.000
Senior Project Manager - RDT Data
Senior Project Manager - RDT Data

Roche • Madrid

Presencial
EUR 90.000 - 130.000
Project (R&D) Manager
Project (R&D) Manager

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 90.000 - 120.000
Senior Identity And Access Management Engineer - Cloud Environment
Senior Identity And Access Management Engineer - Cloud Environment

Roche • Madrid

Presencial
EUR 50.000 - 70.000