Expert - Information Security & Privacy Governance

F. Hoffmann-La Roche AG

Madrid

Presencial

EUR 90.000 - 120.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Transforma esta oferta en una entrevista — un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

Roche is seeking an Expert within Information Security & Privacy Advisory (ISPA) to act as a high-impact partner for System Owners and global hubs, driving Security and Privacy-by-Design across AI platforms, cloud-native security and enterprise systems.

You will lead risk assessments, guide ISMS implementation, and translate complex regulatory requirements into actionable controls, collaborating with IT, Legal and DPOs to protect Roche's data and operations worldwide.

Formación

  • 10+ years in IT security, governance, risk and compliance (GRC).
  • Experience conducting Information Risk Assessments and DPIAs.
  • Deep knowledge of GDPR, CCPA/CPRA and cross-border data transfer reviews.
  • Proven ability to translate technical risks into business-impact guidance.

Responsabilidades

  • Provide expert advisory and risk mitigation for complex systems.
  • Lead high-risk reviews and define risk-owning controls with stakeholders.
  • Bridge IT, Legal and DPOs to implement privacy-by-design measures.
  • Advise on ISMS governance and regulatory alignment across global teams.

Conocimientos

GRC
Risk assessment
Privacy by design
GDPR/CCPA
ISMS guidance
Stakeholder mgmt

Educación

Degree in CS, Law or IT

Herramientas

ServiceNow IRM
ISO 27001

Descripción del empleo

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

As an Expert within Information Security & Privacy Advisory (ISPA), you move beyond "checking boxes" to become a high-impact partner for System Owners and global Engineering hubs. The ISPA team serves as the strategic bridge between IT, business, and legal functions at Roche. You will lead critical security and privacy risk assessments to operationalize "Security and Privacy-by-Design" principles, ensuring complex digital initiatives, from AI platforms to enterprise systems, remain resilient, secure, and compliant.

Key Responsibilities
  • Expert Advisory & Risk Mitigation
    • High-Risk Reviews: Execute Security Expert Reviews (SER) for complex, high-risk system landscapes, performing deep-dive technical and privacy evaluations.
    • Risk Control & Mitigation: Negotiate risk-mitigating control objectives with business and technical stakeholders; ensure clear risk ownership and accountability.
    • Technical Baselines: Collaborate on Security Design Patterns and Technical Baselines for emerging technologies, including Generative AI, Cloud-native security, and advanced data platforms.
  • Strategic Liaison & Regulatory Governance
    • Data Privacy Partnership: Bridge IT, Legal, and Data Protection Officers (DPOs) to translate global legal requirements into technical and organizational controls.
    • ISMS Guidance: Advise business and IT owners on navigating Roche's Information Security Management System (ISMS) framework and external legal mandates.
    • Cross-Functional Support: Provide pragmatic guidance to strategic functions (e.g., R&D, Commercial, P&C) across global and local operational realities.
  • Agile Governance & Continuous Excellence
    • Workflow Management: Utilize Integrated Risk Management (IRM) platforms (e.g., ServiceNow) to manage advisory queues with audit-ready consistency.
    • Peer Assurance: Maintain high standards through a "Four-Eye" peer review culture and shared knowledge exchange across global team members.
    • Process Innovation: Lead initiatives to streamline risk assessment workflows, identifying opportunities for automation and AI efficiencies.
Qualifications Experience
  • 10+ years in IT security, Governance, Risk, and Compliance (GRC) within complex, global environments.
  • Proven track record conducting Information Risk Assessments, Data Protection Impact Assessments (DPIA), and Cross-Border Data Transfer reviews.
  • Deep knowledge of international privacy frameworks (GDPR, CCPA/CPRA) and regulatory alignment (e.g., DoJ: 28 CFR Part 202).
  • Demonstrated experience providing pragmatic, business-aligned security advice on high-value, strategic projects across matrixed organizations.
Technical & Architectural Skills
  • Security Frameworks: Strong command of Information Security Management frameworks (e.g., ISO 27001, NIST).
  • Cloud & AI Security: Practical insight into cloud platforms (AWS, GCP, Azure), AI orchestration layers, and Security/Privacy-by-Design principles.
  • Technical Translation: Ability to translate complex legal and policy mandates into clear engineering requirements.
  • Workflow Tools: Experience with Integrated Risk Management (IRM) systems (e.g., ServiceNow IRM) for workload tracking is a plus.
Education & Certifications
  • Academic: Degree in Computer Science, Law, Information Technology, or equivalent practical experience.
  • Certifications: Highly valued: CISSP, CISM, CRISC, AIGP, or ISO 27001 Lead Auditor. Significant plus: CIPP/E or CIPM.
Key Competencies
  • Strategic Influence: Ability to build consensus across business, legal, and engineering teams by translating technical risks into clear business impact.
  • Pragmatic Execution: Thrives in ambiguous, complex environments; balances high-quality, audit-scrutinized advisory with speed of delivery.
Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact. Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer. We believe it’s urgent to deliver medical solutions right now – even as we develop innovations for the future. We are passionate about transforming patients’ lives. We are courageous in both decision and action. And we believe that good business means a better world. That is why we come to work each day. We commit ourselves to scientific rigor, unassailable ethics, and access to medical innovations for all. We do this today to build a better tomorrow. We are proud of who we are, what we do, and how we do it. We are many, working as one across functions, across companies, and across the world. We are Roche.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Information Security Governance Expert
Information Security Governance Expert

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 90.000 - 130.000
Risk & Governance Intern
Risk & Governance Intern

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 11.000 - 15.000
Expert - Information Security & Privacy Governance
Expert - Information Security & Privacy Governance

Roche Holding AG • Madrid

Presencial
EUR 120.000 - 160.000
IT Strategic Risk & Audit Manager
IT Strategic Risk & Audit Manager

Roche • Madrid

Presencial
EUR 80.000 - 100.000
Expert Security Engineer - Manufacturing Cybersecurity
Expert Security Engineer - Manufacturing Cybersecurity

F. Hoffmann-La Roche AG • Madrid

Híbrido
EUR 95.000 - 130.000
Expert DevSecOps Engineer (Expert Software Development Security Engineer)
Expert DevSecOps Engineer (Expert Software Development Security Engineer)

Roche • Madrid

Presencial
EUR 70.000 - 110.000
Strategy & Insights Intern
Strategy & Insights Intern

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 12.000 - 17.000
Cybersecurity Analyst - RDT Security Platforms
Cybersecurity Analyst - RDT Security Platforms

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 85.000
Audit Manager - RDT Quality, Risk & Compliance
Audit Manager - RDT Quality, Risk & Compliance

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 90.000 - 130.000
Data Program and Performance Lead - PTO
Data Program and Performance Lead - PTO

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 120.000 - 160.000
Equal Opportunity Employer