Experteer Overview
Experiencia, cualificaciones y habilidades interpersonales, ¿tiene todo lo necesario para triunfar en esta oportunidad? Descúbralo a continuación.
In this role you will own and evolve Roche’s ISMS to sustain certification and meet evolving global regulations. You will lead audits, align security with business needs, and enable scalable protection of critical assets in a highly regulated environment. You’ll work across senior leadership, legal, privacy and quality to advance governance, risk, and compliance. This position offers the chance to shape security strategy while applying GenAI governance in healthcare IT.
Compensaciones / Ventajas
• Own and maintain the Roche ISMS framework (ISO/IEC 27001:2022) and ensure alignment with quality systems
• Drive the PDCA cycle to sustain certification and adapt to threats and business needs
• Define and maintain enterprise-level security policies, standards, and procedures
• Monitor global risk landscape and adjust governance accordingly
• Translate global regulatory requirements (NIS2, HIPAA, US DOJ) into the ISMS
• Collaborate with product teams to embed Security by Design
• Maintain a unified control framework mapping Roche controls to external regulations
• Advise affiliates on regulatory compliance and lead external audits/inspections
• Oversee third-party governance (critical suppliers and Cloud Providers)
• Coordinate remediation plans from audit findings and ensure closure
• Serve as strategic advisor to leadership on security risks and maturity milestones
• Promote governance and awareness across Information Security networks
Responsabilidades
• 7+ years in Information Security Governance, ISMS management, or IT Audit leadership in a global, regulated industry
• Proven track record of leading ISO 27001 certification cycles and managing regulatory inspections
• Deep understanding of NIS2, GxP xqbhyrx (Annex 11), and GDPR
• Bachelor in Information Technology or related field; professional ISO 27001 Lead Auditor/Implementer (required)
• CISM, CISA, or CRISC (highly preferred)
• Experience with system validation and GxP in a regulated IT environment
• Strong ability to map international regulations into internal controls
• Proficiency with governance platforms (e.g., ServiceNow IRM/GRC)
• Experience with training tools (LMS Cornerstone, QMS Veeva) is advantageous
• Capacity to lead cross-functional initiatives across a global organization
Requisitos principales
•
📌 Information Security Governance Expert (Madrid)
🏢 Roche
📍 Madrid