Experteer Overview In this role you will manage the end-to-end security risk lifecycle to protect critical information and systems. You will bridge technical security engineering with executive risk posture across global environments and third-party ecosystems. You will address evolving threats, drive continuous compliance, and contribute to resilient operations in a life sciences context. You will work with cross-functional teams to safeguard manufacturing, OT, and cloud assets, delivering measurable risk reduction. This is an opportunity to shape security governance at Roche and support healthcare solutions worldwide.Compensaciones / Incentivos
- Support security risk assessments and audits using NIST CSF and ISO 27001 to identify vulnerabilities in systems, cloud services, and emerging tech
- Execute security, privacy, and quality evaluations of global vendors; track remediation and data sovereignty and breach notifications
- Support internal and external security audits and guide remediation efforts
- Design and implement automated tools for real-time monitoring of security controls and overall compliance
- Evaluate security posture of OT and Manufacturing environments to ensure high availability and protection against industrial threatsResponsabilidades
- 3+ years in a Security Risk, Audit, or Compliance role within a global enterprise, with Hybrid-Cloud and OT/IoT experience
- Active CISSP, CISM or CISA preferred; CRISC or ISO 27001 LeadAuditor a plus
- Knowledge of ISO 27001, NIST CSF; GDPR or HIPAA; familiarity with health authority regulations and ITIL/SDLC concepts
- Experience translating controls into automated, data-driven monitoring (Continuous Controls Monitoring, ITGC) and supporting complex assessments
- Strong communication and stakeholder management to facilitate meetings and independent reportingRequisitos principales
-
📌 Security Risk And Audit Specialist - Rdt Information Security (Madrid)
🏢 Roche
📍 Madrid