11 oct
|
Roche Holding
|
Madrid
11 oct
Roche Holding
Madrid
Chez Roche, vous pouvez être vous-même et être apprécié pour les qualités uniques que vous apportez. Notre culture encourage l'expression personnelle, le dialogue ouvert et les connexions authentiques, où vous êtes valorisé, accepté et respecté pour ce que vous êtes, vous permettant de prospérer tant personnellement que professionnellement. Voici comment nous visons à prévenir, arrêter et guérir les maladies et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Rejoignez Roche, où chaque voix compte.
La position
As an Expert within Information Security & Privacy Advisory (ISPA), you move beyond "checking boxes" to become a high-impact partner for System Owners and global Engineering hubs.
The ISPA team serves as the strategic bridge between IT, business, and legal functions at Roche. You will lead critical security and privacy risk assessments to operationalize "Security and Privacy-by-Design" principles, ensuring complex digital initiatives, from AI platforms to enterprise systems, remain resilient, secure, and compliant.
Key Responsibilities
1. Expert Advisory & Risk Mitigation
High-Risk Reviews: Execute Security Expert Reviews (SER) for complex, high-risk system landscapes, performing deep-dive technical and privacy evaluations.
Risk Control & Mitigation: Negotiate risk-mitigating control objectives with business and technical stakeholders;
ensure clear risk ownership and accountability.
Technical Baselines:
Collaborate on Security Design Patterns and Technical Baselines for emerging technologies, including Generative AI, Cloud-native security, and advanced data platforms.
2. Strategic Liaison & Regulatory Governance
Data Privacy Partnership: Bridge IT, Legal, and Data Protection Officers (DPOs) to translate global legal requirements into technical and organizational controls.
ISMS Guidance: Advise business and IT owners on navigating Roche's Information Security Management System (ISMS) framework and external legal mandates.
Cross-Functional Support: Provide pragmatic guidance to strategic functions (e.G., R&D;, Commercial, P&C;) across global and local operational realities.
3. Agile Governance & Continuous Excellence
Workflow Management: Utilize Integrated Risk Management (IRM) platforms (e.G., ServiceNow) to manage advisory queues with audit-ready consistency.
Peer Assurance: Maintain high standards through a "Four-Eye" peer review culture and shared knowledge exchange across global team members.
Process Innovation: Lead initiatives to streamline risk assessment workflows, identifying opportunities for automation and AI efficiencies.
Qualifications
Experience
10+ years in IT security, Governance, Risk, and Compliance (GRC) within complex, integral environments.
Proven track record conducting Information Risk Assessments, Data Protection Impact Assessments (DPIA), and Cross-Border Data
📌 Expert - Information Security & Privacy Governance (Madrid)
🏢 Roche Holding
📍 Madrid