IT Strategic Risk & Audit Manager

F. Hoffmann-La Roche AG

Madrid

Presencial

EUR 80.000 - 120.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

F. Hoffmann-La Roche AG is looking for an IT Strategic Risk & Audit Manager in Madrid. This role involves guiding digital transformation while ensuring robust risk management practices. Applicants should have over 15 years of experience in IT risk and audit, ideally in regulated sectors like Pharma or Finance, and expertise in various risk frameworks and GxP principles.

The manager will drive strategic initiatives and manage complex compliance projects. The position requires strong leadership capabilities, excellent risk assessment skills, and familiarity with IT audits.

Formación

  • 15+ years of experience in IT Risk/Audit, preferably in Pharma, MedTech, or Finance.
  • Deep mastery of GxP and Data Integrity principles.
  • Expert knowledge of global risk frameworks and privacy regulations.

Responsabilidades

  • Define strategic vision for IT risk, audit, and compliance.
  • Lead complex projects and develop enterprise-wide policies.
  • Serve as liaison during Health Authority inspections.

Conocimientos

IT Risk/Audit experience
GxP Knowledge
Global Risk Frameworks
Cloud Security
Executive Influence
Decision-Making Skills

Educación

Relevant Certifications (CISA, CRISC, CISM, CISSP)

Descripción del empleo

IT Strategic Risk & Audit Manager

At Roche, you will play a pivotal role in ensuring that our digital evolution—from AI‑driven drug discovery to personalized healthcare apps—is built on a foundation of trust and resilience. You will act as a strategic partner to Digital Technology leaders, ensuring that risks are managed proactively and that our global digital strategy incorporates best practices in risk, audit, and compliance.

Responsibilities
  • Define the strategic vision for IT risk, audit, and compliance, and drive strategic initiatives for long‑term risk management success.
  • Initiate and lead large, complex projects with significant impact on the organization.
  • Lead the development of enterprise‑wide risk and compliance policies and advise on emerging trends and best practices.
  • Define and architect the global IT Enterprise Risk Management (ERM) framework (NIST, ISO 27001, COBIT), aligning long‑term digital strategy with Roche’s risk appetite.
  • Lead analysis of highly complex business and risk challenges with significant organizational impact, proactively identifying potential strategic issues.
  • Develop comprehensive risk management and compliance policies, implement proactive measures to avoid repeated issues, and lead initiatives to anticipate and mitigate future risks.
  • Contribute to framing strategic questions and facilitate strategic decision‑making at the executive level.
  • Identify and engage key stakeholders at the executive level and external partners, analyze enterprise‑wide stakeholder landscapes, and secure support and strategic alignment for risk‑related investments.
  • Navigate highly complex and politically sensitive landscapes, act as an organizational trust builder, and provide expert counsel on critical strategic decisions.
  • Lead the full lifecycle of complex IT audits and continuous monitoring programs across infrastructure and applications, ensuring global regulatory compliance and proactively identifying systemic issues.
  • Serve as the primary IT liaison during complex Health Authority inspections (FDA, EMA, etc.), lead “Front‑Room/Back‑Room” operations, coach SMEs in regulatory interview techniques, and ensure rapid delivery of high‑quality evidence.
  • Systematically audit and enforce the “Digital Thread” to ensure all health‑regulated data remains Attributable, Legible, Contemporaneous, Original, and Accurate, maintaining data integrity.
  • Partner with IT owners to develop robust remediation CAPAs and innovate risk‑management approaches, driving lasting, transformative impact across the global organization.
Qualifications
  • 15+ years of experience in IT Risk/Audit, preferably within a global, highly regulated industry (Pharma, MedTech, or Finance).
  • Deep mastery of GxP (GLP, GCP, GMP), CSV (Computer System Validation), and Data Integrity principles (ALCOA+).
  • Expert knowledge of global risk frameworks (NIST, ISO 27001, COBIT) and privacy regulations (GDPR, HIPAA).
  • Strong understanding of modern technology stacks, including Cloud Security (AWS/Azure), AI/ML governance, and Agile/DevSecOps methodologies.
  • Demonstrated experience presenting to and influencing Executive Leadership (C‑suite) and Board‑level stakeholders.
  • Proven ability to navigate a complex, global matrixed environment and steer senior leadership toward risk‑aware decision‑making through technical credibility.
  • Drive a culture of shared accountability, ensuring compliance and risk management are viewed as strategic enablers.
Certifications

Mandatory possession of at least two of the following: CISA, CRISC, CISM, or CISSP.

Location

Primary location: Madrid.

Where pay transparency applies, compensation details are provided based on the primary posting location.

Equal Opportunity Employer

Roche is an Equal Opportunity Employer.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

IT Strategic Risk & Audit Manager
IT Strategic Risk & Audit Manager

Roche • Madrid

Presencial
EUR 80.000 - 100.000
Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 90.000
Global Strategic IT Risk & Audit Leader
Global Strategic IT Risk & Audit Leader

Roche • Madrid

Presencial
EUR 80.000 - 100.000
Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche • Madrid

Presencial
EUR 70.000 - 110.000
Cyber Security Compliance Intern
Cyber Security Compliance Intern

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 52.000 - 76.000
Information Security Governance Expert
Information Security Governance Expert

Roche • Madrid

Presencial
EUR 90.000 - 130.000
Information Security Governance Expert
Information Security Governance Expert

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 70.000 - 95.000
Strategic Security Risk & Audit Lead
Strategic Security Risk & Audit Lead

Roche • Madrid

Presencial
EUR 70.000 - 110.000
IT Project Manager - RDT Pharma R&D
IT Project Manager - RDT Pharma R&D

Roche • Madrid

Presencial
EUR 70.000 - 95.000
Global IT Risk & Audit Strategy Leader
Global IT Risk & Audit Strategy Leader

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 80.000 - 120.000