Security Risk and Audit Specialist - RDT Information Security

F. Hoffmann-La Roche AG

Madrid

Presencial

EUR 60.000 - 90.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Roche is seeking an IT Security Risk & Audit Specialist to oversee end-to-end security risk lifecycle, bridging engineering and executive risk posture to protect global systems and vendors.

The role covers risk assessments, third‑party evaluations, audit support, and continuous monitoring, with emphasis on OT/IoT security and regulatory alignment. A dynamic, global enterprise environment offers exposure to hybrid-cloud and healthcare industry standards.

Formación

  • Bachelor’s degree in Cybersecurity, Computer Science, or related field; Master’s preferred.
  • 3+ years in security risk, audit or compliance in a global enterprise.
  • Experience with hybrid-cloud and OT/IoT environments is required or preferred.

Responsabilidades

  • Support security risk assessments and audits using NIST CSF and ISO 27001.
  • Evaluate third‑party cyber risk with focus on supply‑chain integrity and breach readiness.
  • Assist internal/external audits and remediation guidance.
  • Design automated monitoring to measure control effectiveness in real time.
  • Assess security posture of OT/manufacturing environments for availability and protection.

Conocimientos

Security risk management
Audit & compliance
ISO 27001
NIST CSF
GDPR/HIPAA privacy
OT/IoT security
Cloud security (hybrid)

Educación

Bachelor’s degree in Cybersecurity/CS
Master’s degree preferred

Herramientas

ITIL

Descripción del empleo

Position Job Description

At Roche, protecting our critical information assets and systems is foundational to delivering life‑changing medicines. As the IT Security Risk & Audit Specialist, you will manage and coordinate the end‑to‑end security risk lifecycle, bridging the gap between technical security engineering and executive risk posture to ensure our global systems and third‑party ecosystems remain resilient against evolving threats.

Responsibilities
  • Risk Assessment: Support comprehensive security risk assessments and audits using frameworks such as NIST CSF and ISO 27001 to identify vulnerabilities in systems, cloud services, and emerging technologies.
  • Third‑Party Cyber Risk Management: Execute security, privacy, and quality evaluations of global vendors, focusing on supply‑chain integrity, data sovereignty, and breach notification capabilities; follow up with vendors on open findings and remediation status.
  • Audit Assurance: Support internal and external security audits and provide guidance on remediation findings.
  • Continuous Compliance Monitoring: Design and implement automated tools to monitor the effectiveness of security controls in real‑time, moving the organization toward data‑driven monitoring and monitoring compliance on critical systems and vendors.
  • OT & Manufacturing Protection: Support the evaluation of the security posture of manufacturing and operational technology (OT) environments to ensure high availability and protection against industrial cyber threats.
Qualifications
  • Education / Experience: Bachelor’s degree in Cybersecurity, Computer Science, or a related technical field (Master’s preferred). 3+ years in a dedicated Security Risk, Audit, or Compliance role within a global enterprise, specifically handling hybrid‑cloud and OT/IoT environments.
  • Certifications: Active CISSP, CISM, or CISA highly preferred; CRISC or ISO 27001 Lead Auditor certifications are a significant plus.
  • Technical Skills: Knowledge of security standards (ISO 27001, NIST CSF), data protection and privacy regulations such as GDPR or HIPAA; familiarity with health authority regulations, systems financial controls, software development lifecycle, computer systems validation, infrastructure qualification, and ITIL processes.
  • Audit & Control Automation: Experience in translating manual security controls into automated, data‑driven monitoring requirements (Continuous Controls Monitoring, ITGC).
  • Analytical & Project Management: Strong ability to support complex assessments and drive the optimization of risk monitoring tools.
  • Additional Qualifications: Strong communication and relationship‑building skills to manage stakeholder expectations, facilitate meetings, and act as an independent communicator; continuous improvement mindset with the capability to apply analytical and logical reasoning to challenge assumptions and identify discrepancies.

Roche is an Equal Opportunity Employer. We believe it’s urgent to deliver medical solutions right now – even as we develop innovations for the future. We are passionate about transforming patients’ lives. We are courageous in both decision and action. And we believe that good business means a better world. That is why we come to work each day.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche • Madrid

Presencial
EUR 70.000 - 110.000
Strategic Security Risk & Audit Lead
Strategic Security Risk & Audit Lead

Roche • Madrid

Presencial
EUR 70.000 - 110.000
IT Strategic Risk & Audit Manager
IT Strategic Risk & Audit Manager

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 80.000 - 120.000
IT Strategic Risk & Audit Manager
IT Strategic Risk & Audit Manager

Roche • Madrid

Presencial
EUR 80.000 - 100.000
Cyber Security Risk & Audit Lead
Cyber Security Risk & Audit Lead

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 90.000
Cyber Security Compliance Intern
Cyber Security Compliance Intern

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 52.000 - 76.000
Data Security & Privacy Lead
Data Security & Privacy Lead

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 45.000 - 60.000
Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche Holding AG • Madrid

Presencial
EUR 55.000 - 85.000
Cybersecurity Analyst –IAM ID Verification & External Collaborators
Cybersecurity Analyst –IAM ID Verification & External Collaborators

Roche • Madrid

Presencial
EUR 40.000 - 60.000
Cybersecurity Analyst
Cybersecurity Analyst

Roche • Madrid

Presencial
EUR 55.000 - 85.000