At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.The Position As an Expert within Information Security & Privacy Advisory (ISPA), you move beyond "checking boxes" to become a high-impact partner for System Owners and integral Engineering hubs.The ISPA team serves as the strategic bridge between IT, business, and legal functions at Roche. You will lead critical security and privacy risk assessments to operationalize "Security and Privacy-by-Design" principles, ensuring complex digital initiatives, from AI platforms to enterprise systems, remain resilient, secure, and compliant.Key Responsibilities Expert Advisory & Risk MitigationHigh-Risk Reviews: Execute Security Expert Reviews (SER) for complex, high-risk system landscapes, performing deep-dive technical and privacy evaluationsRisk Control & Mitigation: Negotiate risk-mitigating control objectives with business and technical stakeholders; ensure clear risk ownership and accountabilityTechnical Baselines: Collaborate on Security Design Patterns and Technical Baselines for emerging technologies, including Generative AI, Cloud-native security, and advanced data platformsStrategic Liaison & Regulatory GovernanceData Privacy Partnership: Bridge IT, Legal, and Data Protection Officers (DPOs) to translate global legal requirements into technical and organizational controlsISMS Guidance:
Advise business and IT owners on navigating Roche's Information Security Management System (ISMS) framework and external legal mandatesCross-Functional Support: Provide pragmatic guidance to strategic functions (e.G., R&D;, Commercial, P&C;) across global and local operational realitiesAgile Governance & Continuous ExcellenceWorkflow Management: Utilize Integrated Risk Management (IRM) platforms (e.G., ServiceNow) to manage advisory queues with audit-ready consistencyPeer Assurance: Maintain high standards through a "Four-Eye" peer review culture and shared knowledge exchange across global team membersProcess Innovation: Lead initiatives to streamline risk assessment workflows, identifying opportunities for automation and AI efficienciesQualifications Experience 10+ years in IT security, Governance, Risk, and Compliance (GRC) within complex, global environmentsProven track record conducting Information Risk Assessments, Data Protection Impact Assessments (DPIA), and Cross-Border Data Transfer reviewsDeep knowledge of international privacy frameworks (GDPR, CCPA/CPRA) and regulatory alignment (e.G., DoJ: 28 CFR Part 202)Demonstrated experience providing pragmatic, business-aligned security advice on high-value, strategic projects across matrixed organizationsTechnical & Architectural Skills Security Frameworks:
Strong command of Information Security Management frameworks (e.G., ISO 27001, NIST)Cloud & AI Security: Practical insight into cloud platforms (AWS, GCP, Azure), AI orchestration layers, and Security/Privacy-by-Design principlesTechnical Translation: Ability to translate complex legal and policy mandates into clear engineering requirementsWorkflow Tools: Experience with Integrated Risk Management (IRM) systems (e.G., ServiceNow IRM) for workload tracking is a plusEducation & Certifications Academic: Degree in Computer Science, Law, Information Technology, or equivalent practical experienceCertifications: Highly valued: CISSP, CISM, CRISC, AIGP, or ISO 27001 Lead Auditor. Significant plus: CIPP/E or CIPMKey Competencies Strategic Influence: Ability to build consensus across business, legal, and engineering teams by translating technical risks into clear business impactPragmatic Execution: Thrives in ambiguous, complex environments; balances high-quality, audit-scrutinized advisory with speed of deliveryWho we are A healthier future drives us to innovate. Together, more than 100-000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.Let's build a healthier future, together.Roche is an Equal Opportunity Employer.#J-18808-Ljbffr
📌 Expert - Information Security & Privacy Governance (Madrid)
🏢 Roche
📍 Madrid