IT GRC Expert - RDT Quality, Risk & Compliance
This role focuses on designing and implementing comprehensive IT resilience, risk management, and compliance strategies aligned with Roche’s business objectives. The Analyst leads complex risk assessments, develops audit and continuity programs, and acts as an advisor to senior stakeholders on critical incident response and enterprise-wide risk solutions.
Key Responsibilities
- Develop and refine enterprise‑wide risk management, compliance, and continuity strategies to enhance global recovery plans.
- Lead the response to critical IT risk, audit, and continuity events, establishing best practices for handling disruptions.
- Conduct post‑incident reviews and deep‑dives to identify systemic failures and implement continuous improvement frameworks.
- Manage high‑level stakeholder relationships, acting as strategic advisor to align risk policies with evolving business needs.
- Provide strategic insights based on industry best practices to keep compliance frameworks world‑class.
- Oversee scalability of IT resilience solutions, integrating complex policies with existing enterprise systems.
- Evaluate and select advanced tools for enterprise management to future‑proof technical resilience.
- Facilitate advanced training sessions for cross‑functional teams on BCM best practices and problem‑solving techniques.
Qualifications
- Extensive experience architecting enterprise‑wide IT resilience and risk management strategies at a strategic level.
- Expertise in life sciences regulations (GxP, SOX, HIPAA) and computer systems validation (CSV).
- In‑depth knowledge of IT General Controls (ITGC) and frameworks such as SOC2, ISO 27001, NIS2, and DORA.
- Technical proficiency in AWS and Azure environments, particularly shared responsibility models and cloud‑native DR orchestration.
- Track record establishing governance guardrails for emerging technologies (Generative AI, RPA, SaaS).
- Skilled in secure SDLC and DevOps stacks (Jira, Jenkins, Bitbucket) and implementing Compliance‑as‑Code.
- Bachelor’s or Master’s degree in IT or Cybersecurity, plus at least one active credential: CISA, CRISC, CISM, CISSP, or ISO 22301.
Benefits
- Salary: 19 000 – 35 400 PLN gross (based on employment contract) with an annual bonus tied to performance.
- Dedicated training budget for certifications, conferences, and career development.
- Recharge Fridays – two Fridays off per quarter.
- Take Time Program – up to three months of leave for personal use.
- Vacation subsidy and flex‑location options allowing work from various global locations for a period of time.
- Additional paid leave for charity activities (up to two weeks).
- Private healthcare (LuxMed), group life insurance (UNUM), and Multisport membership.
- Stock share purchase options and yearly company laptop and car allocations.
Equal Opportunity Statement
Roche is an Equal Opportunity Employer and encourages applications from all qualified individuals regardless of background.