01 ago
|
F. Hoffmann-La Roche
|
Madrid
01 ago
F. Hoffmann-La Roche
Madrid
IT Strategic Risk & Audit Manager At Roche, you will play a pivotal role in ensuring that our digital evolution—from AI‑driven drug discovery to personalized healthcare apps—is built on a foundation of trust and resilience. You will act as a strategic partner to Digital Technology leaders, ensuring that risks are managed proactively and that our global digital strategy incorporates best practices in risk, audit, and compliance. Responsibilities Define the strategic vision for IT risk, audit, and compliance, and drive strategic initiatives for long‑term risk management success. Initiate and lead large, complex projects with significant impact on the organization. Lead the development of enterprise‑wide risk and compliance policies and advise on emerging trends and best practices. Define and architect the global IT Enterprise Risk Management (ERM) framework (NIST, ISO 27001, COBIT), aligning long‑term digital strategy with Roche’s risk appetite. Lead analysis of highly complex business and risk challenges with significant organizational impact, proactively identifying potential strategic issues. Develop comprehensive risk management and compliance policies, implement proactive measures to avoid repeated issues, and lead initiatives to anticipate and mitigate future risks. Contribute to framing strategic questions and facilitate strategic decision‑making at the executive level. Identify and engage key stakeholders at the executive level and external partners, analyze enterprise‑wide stakeholder landscapes, and secure support and strategic alignment for risk‑related investments. Navigate highly complex and politically sensitive landscapes, act as an organizational trust builder, and provide expert counsel on critical strategic decisions. Lead the full lifecycle of complex IT audits and continuous monitoring programs across infrastructure and applications,
ensuring general regulatory compliance and proactively identifying systemic issues. Serve as the primary IT liaison during complex Health Authority inspections (FDA, EMA, etc.), lead “Front‑Room/Back‑Room” operations, coach SMEs in regulatory interview techniques, and ensure rapid delivery of high‑quality evidence. Systematically audit and enforce the “Digital Thread” to ensure all health‑regulated data remains Attributable, Legible, Contemporaneous, Original, and Accurate, maintaining data integrity. Partner with IT owners to develop robust remediation CAPAs and innovate risk‑management approaches, driving lasting, transformative impact across the global organization. Qualifications 15+ years of experience in IT Risk/Audit, preferably within a global, highly regulated industry (Pharma, Med Tech, or Finance). Deep mastery of Gx P (GLP, GCP, GMP), CSV (Computer System Validation), and Data Integrity principles (ALCOA+). Expert knowledge of global risk frameworks (NIST, ISO 27001, COBIT) and privacy regulations (GDPR, HIPAA). Strong understanding of modern technology stacks, including Cloud Security (AWS/Azure), AI/ML governance, and Agile/Dev Sec Ops methodologies. Demonstrated experience presenting to and influencing Executive Leadership (C‑suite) and Board‑level stakeholders. Proven ability to navigate a complex, global matrixed environment and steer senior leadership toward risk‑aware decision‑making through technical credibility. Drive a culture of shared accountability, ensuring compliance and risk management are viewed as strategic enablers. Certifications Mandatory possession of at least two of the following: CISA, CRISC, CISM, or CISSP. Location Primary location: Madrid. Where pay transparency applies, compensation details are provided based on the primary posting location. Equal Opportunity Employer Roche is an Equal Opportunity Employer. #J-18808-Ljbffr
📌 It Strategic Risk & Audit Manager (Madrid)
🏢 F. Hoffmann-La Roche
📍 Madrid