Information Security Governance Expert

F. Hoffmann-La Roche AG

Madrid

Presencial

EUR 90.000 - 130.000

Jornada completa

14 días+
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca la empresa.

Supera los filtros ATS

Descripción de la vacante

Roche is seeking an Expert within the ISPA team to drive strategic security and privacy risk assessments for global engineering hubs, ensuring GenAI and cloud-native initiatives are Secure by Design and compliant with international standards.

You will translate legal mandates into technical controls, lead high-impact reviews, and collaborate across IT, legal and data protection to deliver audit-ready guidance.

Formación

  • 5–10 years in Information Security/GRC with risk assessments and DPIAs in global settings.
  • Ability to translate regulatory mandates into technical and organizational controls.
  • Experience with security architecture and modern technologies (GenAI, cloud-native).

Responsabilidades

  • Lead Security Expert Reviews for complex architectures, identifying residual risks.
  • Bridge IT, Legal, and Data Protection Officers to implement controls.
  • Develop security design patterns and baselines for GenAI and cloud-native ecosystems.
  • Utilize ServiceNow IRM to ensure traceability and audit-ready results.
  • Foster peer excellence and knowledge exchange within a global team.

Conocimientos

Security Architecture
Information Security & GRC
Regulatory Knowledge (GDPR, CCPA)
Communication & Stakeholder mgmt
ISO27001/NIST knowledge

Educación

Degree in Computer Science or Legal

Herramientas

ServiceNow IRM

Descripción del empleo

Position

As an Expert within the Information Security & Privacy Advisory (ISPA) team, you move beyond "checking boxes" to become a strategic partner for global Engineering hubs. You will lead high-impact security and privacy risk assessments, ensuring Roche's most ambitious digital projects—from GenAI to cloud-native platforms—are resilient, "Secure by Design," and compliant with global regulations.

The Team

The Information Security & Privacy Advisory (ISPA) team serves as the strategic bridge between IT, business, and legal functions at Roche. Our mission is to ensure that Roche's digital landscape—from cutting-edge GenAI platforms to global enterprise solutions—is secure by design and compliant with international standards. We act as a global center of excellence that translates complex regulatory requirements into actionable security architecture, providing the expert guidance necessary to navigate a rapidly evolving global risk landscape.

Key Responsibilities
  • High-Risk Advisory: Lead Security Expert Reviews (SER) for complex architectures, performing deep-dive technical and privacy evaluations to identify and mitigate residual risks.
  • Privacy: Bridge the gap between IT, Legal, and Data Protection Officers. Translate complex legal mandates (GDPR, CCPA etc.) into actionable technical and organizational controls.
  • Information Security: Contribute to Security Design Patterns and Technical Baselines for emerging technologies like Generative AI and Cloud-native ecosystems.
  • Risk Governance: Utilize ServiceNow IRM to ensure the integrity and traceability of security advisory, delivering data-driven, consistent, and audit-ready results.
  • Peer Excellence: Foster a "Four-Eye" quality culture through peer reviews and collective knowledge exchange within a global team of experts.
Who You Are

A proactive Expert & Influencer who brings deep industry experience to an established team. You have the confidence to lead initiatives independently while thriving in an environment of collective knowledge exchange.

Qualifications
  • Experience: 5–10 years in Information Security/GRC, with a proven track record in Information Risk Assessments and DPIAs in complex, global environments.
  • Technical Savvy: Deep understanding of Security Architecture and the ability to translate "Legal-speak" into "Engineering-speak."
  • Regulatory Mastery: Expert knowledge of international privacy frameworks (GDPR, CCPA, HIPAA, etc.) and security standards (ISO 27001, NIST).
  • System Proficiency: Experienced in using ServiceNow IRM to execute and document risk assessments, utilizing the platform to ensure consistent, high-quality, and transparent security guidance.
  • Education: Degree in Computer Science or Legal.
  • Certifications like CISSP, CISM, CRISC, CIPP/E, CIPM or ISO27001 Lead Auditor are highly valued.
  • Communication: Exceptional stakeholder management skills with the ability to drive consensus across a global organization.
Who we are

A healthier future drives us to innovate. Together, more than 100'000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life‑changing healthcare solutions that make a global impact. Let's build a healthier future, together.

Roche is an Equal Opportunity Employer. We believe it's urgent to deliver medical solutions right now – even as we develop innovations for the future. We are passionate about transforming patients' lives. We are courageous in both decision and action. And we believe that good business means a better world. That is why we come to work each day. We commit ourselves to scientific rigor, unassailable ethics, and access to medical innovations for all. We do this today to build a better tomorrow. We are proud of who we are, what we do, and how we do it. We are many, working as one across functions, across companies, and across the world. We are Roche.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Risk & Governance Intern
Risk & Governance Intern

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 11.000 - 15.000
AI and Automation Engineer-Information Security Governance
AI and Automation Engineer-Information Security Governance

Roche • Madrid

Presencial
EUR 70.000 - 95.000
IT Strategic Risk & Audit Manager
IT Strategic Risk & Audit Manager

Roche • Madrid

Presencial
EUR 80.000 - 100.000
Expert DevSecOps Engineer (Expert Software Development Security Engineer)
Expert DevSecOps Engineer (Expert Software Development Security Engineer)

Roche • Madrid

Presencial
EUR 70.000 - 110.000
Senior Enterprise Identity Management Expert
Senior Enterprise Identity Management Expert

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 90.000 - 120.000
Expert Security Engineer - Manufacturing Cybersecurity
Expert Security Engineer - Manufacturing Cybersecurity

F. Hoffmann-La Roche AG • Madrid

Híbrido
EUR 95.000 - 130.000
Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche • Madrid

Presencial
EUR 70.000 - 110.000
Cybersecurity Analyst - RDT Security Platforms
Cybersecurity Analyst - RDT Security Platforms

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 85.000
Strategy & Insights Intern
Strategy & Insights Intern

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 12.000 - 17.000
Senior Identity And Access Management Engineer - Cloud Environment
Senior Identity And Access Management Engineer - Cloud Environment

Roche • Madrid

Presencial
EUR 50.000 - 70.000