11 oct
|
F. Hoffmann-La Roche
|
Madrid
11 oct
F. Hoffmann-La Roche
Madrid
At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The Position As an Expert within Information Security & Privacy Advisory (ISPA), you move beyond "checking boxes" to become a high-impact partner for System Owners and global Engineering hubs. The ISPA team serves as the strategic bridge between IT, business, and legal functions at Roche. You will lead critical security and privacy risk assessments to operationalize "Security and Privacy-by-Design" principles, ensuring complex digital initiatives, from AI platforms to enterprise systems, remain resilient, secure, and compliant.
Key Responsibilities Expert Advisory & Risk Mitigation High-Risk Reviews: Execute Security Expert Reviews (SER) for complex, high-risk system landscapes, performing deep-dive technical and privacy evaluations.
Risk Control & Mitigation: Negotiate risk-mitigating control objectives with business and technical stakeholders;
ensure clear risk ownership and accountability.
Technical Baselines:
Collaborate on Security Design Patterns and Technical Baselines for emerging technologies, including Generative AI, Cloud-native security, and advanced data platforms.
Strategic Liaison & Regulatory Governance Data Privacy Partnership: Bridge IT, Legal, and Data Protection Officers (DPOs) to translate global legal requirements into technical and organizational controls.
ISMS Guidance: Advise business and IT owners on navigating Roche's Information Security Management System (ISMS) framework and external legal mandates.
Cross-Functional Support: Provide pragmatic guidance to strategic functions (e.G., R&D;, Commercial, P&C;) across global and local operational realities.
Agile Governance & Continuous Excellence Workflow Management: Utilize Integrated Risk Management (IRM) platforms (e.G., ServiceNow) to manage advisory queues with audit-ready consistency.
Peer Assurance: Maintain high standards through a "Four-Eye" peer review culture and shared knowledge exchange across global team members.
Process Innovation: Lead initiatives to streamline risk assessment workflows, identifying opportunities for automation and AI efficiencies.
Qualifications Experience 10+ years in IT security, Governance, Risk, and Compliance (GRC) within complex, general environments.
Proven track record conducting Information Risk Assessments, Data Protection Impact Assessments (DPIA), and Cross-Border Data
📌 Expert - Information Security & Privacy Governance (Madrid)
🏢 F. Hoffmann-La Roche
📍 Madrid