Expert Information Security & Privacy Governance
Job Summary
At Roche you can show up as yourself embraced for the unique qualities you bring. Our culture encourages personal expression open dialogue and genuine connections where you are valued accepted and respected for who you are allowing you to thrive both personally and professionally. This is how we aim to prevent stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche where every voice matters.
As an Expert within Information Security & Privacy Advisory (ISPA) you move beyond checking boxes to become a high-impact partner for System Owners and global Engineering hubs.
The ISPA team serves as the strategic bridge between IT business and legal functions at Roche. You will lead critical security and privacy risk assessments to operationalize Security and Privacy-by-Design principles ensuring complex digital initiatives from AI platforms to enterprise systems remain resilient secure and compliant.
1. Expert Advisory & Risk Mitigation
- High-Risk Reviews: Execute Security Expert Reviews (SER) for complex high-risk system landscapes performing deep-dive technical and privacy evaluations.
- Risk Control & Mitigation: Negotiate risk-mitigating control objectives with business and technical stakeholders; ensure clear risk ownership and accountability.
- Technical Baselines: Collaborate on Security Design Patterns and Technical Baselines for emerging technologies including Generative AI Cloud-native security and advanced data platforms.
- Data Privacy Partnership: Bridge IT Legal and Data Protection Officers (DPOs) to translate global legal requirements into technical and organizational controls.
- ISMS Guidance: Advise business and IT owners on navigating Roches Information Security Management System (ISMS) framework and external legal mandates.
- Cross-Functional Support: Provide pragmatic guidance to strategic functions (e.g. R&D Commercial P&C) across global and local operational realities.
- Workflow Management: Utilize Integrated Risk Management (IRM) platforms (e.g. ServiceNow) to manage advisory queues with audit-ready consistency.
- Peer Assurance: Maintain high standards through a Four-Eye peer review culture and shared knowledge exchange across global team members.
- Process Innovation: Lead initiatives to streamline risk assessment workflows identifying opportunities for automation and AI efficiencies.
- 10 years in IT security Governance Risk and Compliance (GRC) within complex global environments.
- Proven track record conducting Information Risk Assessments Data Protection Impact Assessments (DPIA) and Cross-Border Data Transfer reviews.
- Deep knowledge of international privacy frameworks (GDPR CCPA/CPRA) and regulatory alignment (e.g. DoJ: 28 CFR Part 202).
- Demonstrated experience providing pragmatic business-aligned security advice on high-value strategic projects across matrixed organizations.
- Security Frameworks: Strong command of Information Security Management frameworks (e.g. ISO 27001 NIST).
- Cloud & AI Security: Practical insight into cloud platforms (AWS GCP Azure) AI orchestration layers and Security/Privacy-by-Design principles.
- Technical Translation: Ability to translate complex legal and policy mandates into clear engineering requirements.
- Workflow Tools: Experience with Integrated Risk Management (IRM) systems (e.g. ServiceNow IRM) for workload tracking is a plus.
- Academic: Degree in Computer Science Law Information Technology or equivalent practical experience.
- Certifications: Highly valued: CISSP CISM CRISC AIGP or ISO 27001 Lead Auditor. Significant plus: CIPP/E or CIPM.
- Strategic Influence: Ability to build consensus across business legal and engineering teams by translating technical risks into clear business impact.
- Pragmatic Execution: Thrives in ambiguous complex environments; balances high-quality audit-scrutinized advisory with speed of delivery.
A healthier future drives us to innovate. Together more than 100000 employees across the globe are dedicated to advance science ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities foster creativity and keep our ambitions high so we can deliver life-changing healthcare solutions that make a global impact.
Lets build a healthier future together.
Roche is an Equal Opportunity Employer.
About Company
F. Hoffmann-La Roche AG is a Swiss multinational healthcare company that operates worldwide under two divisions: Pharmaceuticals and Diagnostics. Its holding company, Roche Holding AG, has bearer shares listed on the SIX Swiss Exchange. The company headquarters are located in Basel.