IT Strategic Risk & Audit Manager

Roche

Warszawa

On-site

PLN 524,000 - 742,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Roche is seeking an IT Strategic Risk & Audit Manager to drive the strategic vision for IT risk, audit, and compliance across global platforms. You will partner with Digital Technology leaders to align risk, privacy, and regulatory requirements with Roche’s digital evolution, including AI-driven initiatives and cloud architecture.

You will lead enterprise risk programs, advise on regulatory trends, and facilitate executive decisions while ensuring high-quality, compliant evidence for health

Qualifications

  • Deep knowledge of global risk frameworks (NIST, ISO 27001, COBIT) and privacy regulations (GDPR, HIPAA).
  • Experience presenting to C-suite and boards; influencing senior leadership.

Responsibilities

  • Define strategic IT risk, audit, and compliance vision and drive long-term initiatives.
  • Lead enterprise-wide risk and compliance policies and advisory on trends and best practices.
  • Coordinate IT risk governance during inspections (FDA, EMA) and ensure timely evidence delivery.
  • Oversee end-to-end audits and continuous monitoring across infrastructure and applications.

Skills

GxP / regulatory
Cloud Security
AI / ML governance
Executive communication
IT risk & audit strategy

Job description

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

At Roche, we believe every patient deserves a personalized healthcare solution. As the IT Strategic Risk & Audit Manager, you will play a pivotal role in ensuring that our digital evolution—from AI-driven drug discovery to personalized healthcare apps is built on a foundation of trust and resilience. You will act as a strategic partner to Digital Technology leaders, ensuring that risks are managed proactively rather than reactively.

This role moves beyond tactical "checkbox" auditing to focus on strategic foresight—anticipating shifts in the threat landscape, regulatory environment, and emerging technologies (like AI and Cloud architecture)

Job Responsibilities

Scope / (Content Leadership): Defines the strategic vision for IT risk, audit, and compliance, and drives strategic initiatives for long-term risk management success. Initiates and leads large, complex projects with a significant impact on the organization. Leads the development of enterprise-wide risk and compliance policies and advises on emerging trends and best practices.

  • Strategic Risk Architecture & Vision: Define and architect the global IT Enterprise Risk Management (ERM) framework (NIST, ISO 27001, COBIT), aligning long-term digital strategy with Roche’s risk appetite to ensure "Compliance by Design" across complex, interconnected global portfolios.

  • Accountability/Problem Solving: Leads the analysis of highly complex business and risk challenges with significant organizational impact, proactively identifying potential strategic issues within your sphere of influence. Develops comprehensive risk management and compliance policies, implements proactive measures to avoid repeated issues, and leads initiatives to anticipate and mitigate future risks. Contributes to framing strategic questions and facilitates strategic decision-making at the executive level.

  • Stakeholder Management: Identifies and engages key stakeholders at the executive level and external partners, analyzing enterprise-wide stakeholder landscapes. Leads enterprise-wide risk, audit, and compliance initiatives, presenting them to executive leadership to secure support and strategic alignment for risk-related investments. Navigates highly complex and politically sensitive landscapes, acting as an organizational trust builder and providing expert counsel on critical strategic decisions.

  • E2E Audit & Compliance Leadership: Lead the full lifecycle of complex IT audits and continuous monitoring programs across infrastructure and applications, ensuring the organization meets global regulatory requirements while proactively identifying systemic issues to prevent recurrence.

  • Inspection Command & Control: Serve as the primary IT liaison during complex Health Authority inspections (FDA, EMA, etc.), leading "Front-Room/Back-Room" operations, coaching SMEs in regulatory interview techniques, and ensuring the rapid delivery of high-quality, validated evidence.

  • Data Integrity & ALCOA+ Systematically audit and enforce the "Digital Thread" to ensure all health-regulated data remains Attributable, Legible, Contemporaneous, Original, and Accurate, maintaining the integrity of life-saving digital health solutions.

  • Global Stakeholder & Transformation Management: Navigate sensitive landscapes to lead enterprise-wide risk initiatives, partnering with IT owners to develop robust remediation CAPAs and innovating risk management approaches to drive lasting, transformative impact across the global organization.

Qualifications

Education / Experience

  • 15+ years of experience in IT Risk/Audit, preferably within a global, highly regulated industry (Pharma, MedTech, or Finance).

  • Deep mastery of GxP (GLP, GCP, GMP), CSV (Computer System Validation), and Data Integrity principles (ALCOA+).

  • Expert knowledge of global risk frameworks (NIST, ISO 27001, COBIT) and privacy regulations (GDPR, HIPAA).

  • Strong understanding of modern technology stacks, including Cloud Security (AWS/Azure), AI/ML governance, and Agile/DevSecOps methodologies.

  • Demonstrated experience presenting to and influencing Executive Leadership (C-suite) and Board-level stakeholders.

  • Proven ability to navigate a complex, global matrixed environment and steer senior leadership toward risk-aware decision-making through technical credibility.

  • Drives a culture of shared accountability, ensuring that compliance and risk management are viewed as strategic enablers rather than organizational hurdles.

  • Certifications: Mandatory possession of at least two of the following: CISA, CRISC, CISM, or CISSP.

#RDT2026

Where pay transparency applies, details are provided based on the primary posting location. For this role, the primary location is Madrid. If you are interested in additional locations where the role may be available, we will provide the relevant compensation details later in the hiring process.

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

OSS Lead - RDT Quality, Risk & Compliance
OSS Lead - RDT Quality, Risk & Compliance

Roche • Warszawa

On-site
PLN 390,000 - 650,000
Data Governance & Data Management Specialist - RDT Performance and Insights
Data Governance & Data Management Specialist - RDT Performance and Insights

Roche • Warszawa

On-site
PLN 180,000 - 240,000
Data Governance & Data Management Specialist - RDT Performance and Insights
Data Governance & Data Management Specialist - RDT Performance and Insights

Roche • Poznań

On-site
PLN 303,000 - 411,000
Network Technical Lead - Digital Health Solutions (IVD & MD)
Network Technical Lead - Digital Health Solutions (IVD & MD)

F. Hoffmann-La Roche AG • Warszawa

On-site
PLN 180,000 - 240,000
Annual bonus
Private healthcare
Group life insurance
+3
Network Technical Lead - Digital Health Solutions (IVD & MD)
Network Technical Lead - Digital Health Solutions (IVD & MD)

Roche Holding AG • Warszawa

On-site
PLN 240,000 - 320,000
Annual bonus
Private healthcare (LuxMed)
Group life insurance
+7
Team Lead Engineering Primary Data Analysis, Aggregation and Reporting
Team Lead Engineering Primary Data Analysis, Aggregation and Reporting

Roche • Warszawa

On-site
PLN 23,000 - 43,000
Company car or car allowance
Dedicated training budget
Recharge Fridays (2 Fridays off per -)
+8
Network Technical Lead - Digital Health Solutions (IVD & MD)
Network Technical Lead - Digital Health Solutions (IVD & MD)

Roche • Warszawa

On-site
PLN 300,000 - 460,000
Annual bonus
Healthcare & life insurance
Training & languages
+6
Head of Product HI Enterprise Cloud
Head of Product HI Enterprise Cloud

Roche • Poznań

On-site
PLN 603,000 - 818,000
R&D Solution Architect - Medical Affairs
R&D Solution Architect - Medical Affairs

F. Hoffmann-La Roche AG • Warszawa

On-site
PLN 14,000 - 26,000
Annual bonus
Training budget
Recharge Fridays
+7
Business Operations Analyst - RDT Group Functions
Business Operations Analyst - RDT Group Functions

Roche • Warszawa

On-site
PLN 170,000 - 316,000