Experteer Overview
Por favor, asegúrese de leer atentamente los siguientes detalles antes de enviar cualquier solicitud.
In this role you will partner with Digital Technology leaders to shape and govern IT risk, audit, and compliance for Roche’s digital evolution. You will move beyond checklists to anticipate regulatory shifts, technology changes, and risk in areas like AI and cloud. You will drive enterprise-wide risk frameworks and advise executive leaders on strategic risk decisions. This position offers a chance to impact patient outcomes by ensuring trustworthy, compliant digital health solutions.
Compensaciones / Beneficios
• Define the strategic vision for IT risk, audit, and compliance and drive long-term risk management initiatives
• Lead the development of enterprise-wide risk and compliance policies and advise on emerging trends
• Architect the general IT ERM framework (NIST, ISO 27001, COBIT) aligning with Roche’s risk appetite
• Analyze complex business and risk challenges; implement proactive measures to avoid issues and enable strategic decisions
• Engage executive stakeholders and external partners to secure strategic alignment for risk investments
• Oversee end-to-end IT audits and continuous monitoring across infrastructure and applications
• Serve as IT liaison during Health Authority inspections (FDA, EMA), guiding interview techniques and delivering validated evidence
• Audit data integrity and enforce Digital Thread to ensure health-regulated data is attributable, legible, contemporaneous, original, and accurate
• Navigate global, matrixed environments to drive remediation actions and transform risk management approaches
Responsabilidades
• 15+ years in IT risk/audit, preferably in global, highly regulated industries (Pharma, MedTech, or Finance)
• Deep mastery of GxP (GLP, GCP, GMP), xqbhyrx CSV, and Data Integrity (ALCOA+)
• Expert knowledge of risk frameworks (NIST, ISO 27001, COBIT) and privacy regulations (GDPR, HIPAA)
• Strong understanding of Cloud Security (AWS/Azure), AI/ML governance, and Agile/DevSecOps
• Proven ability to present to and influence C-suite and Board-level stakeholders
• Ability to navigate complex, global matrixed environments and drive risk-aware decisions
• Promotes shared accountability for compliance and risk as strategic enablers
• Certifications: at least two of CISA, CRISC, CISM, or CISSP
Requisitos principales
•
📌 IT Strategic Risk & Audit Manager (Madrid)
🏢 Roche
📍 Madrid