> Markdown version of [/jobs/ext/1654200-information-security-governance-expert](https://www.wearedevelopers.com/jobs/ext/1654200-information-security-governance-expert). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Governance Expert - **Company:** Roche - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Cloud Engineering, Cyber Security, Cloud Platform System, Generative AI, Information Technology, Data Analytics, Servicenow - **Published:** July 11, 2026 - **Apply:** https://dejobs.org/x/x/7B5996A016E14920BF934D41DF5A3D01/job/ ## About the Role * Experience: 5-10 years in Information Security/GRC, with a proven track record in Information Risk Assessments and DPIAs in complex, global environments. * Technical Savvy: Deep understanding of Security Architecture and the ability to translate "Legal-speak" into "Engineering-speak." * Regulatory Mastery: Expert knowledge of international privacy frameworks (GDPR, CCPA, HIPAA, etc.) and security standards (ISO 27001, NIST). * System Proficiency: Experienced in using ServiceNow IRM to execute and document risk assessments, utilizing the platform to ensure consistent, high-quality, and transparent security guidance. * Education: Degree in Computer Science or Legal. Certifications like CISSP, CISM, CRISC, CIPP/E, CIPM or ISO27001 Lead Auditor are highly valued. * Communication: Exceptional stakeholder management skills with the ability to drive consensus across a global organization. ## Description As an Expert within the Information Security & Privacy Advisory (ISPA) team, you move beyond "checking boxes" to become a strategic partner for global Engineering hubs. You will lead high-impact security and privacy risk assessments, ensuring Roche's most ambitious digital projects-from GenAI to cloud-native platforms-are resilient, "Secure by Design," and compliant with global regulations. The Team The Information Security & Privacy Advisory (ISPA) team serves as the strategic bridge between IT, business, and legal functions at Roche. Our mission is to ensure that Roche's digital landscape-from cutting-edge GenAI platforms to global enterprise solutions-is secure by design and compliant with international standards. We act as a global center of excellence that translates complex regulatory requirements into actionable security architecture, providing the expert guidance necessary to navigate a rapidly evolving global risk landscape., * High-Risk Advisory: Lead Security Expert Reviews (SER) for complex architectures, performing deep-dive technical and privacy evaluations to identify and mitigate residual risks. * Privacy: Bridge the gap between IT, Legal, and Data Protection Officers. Translate complex legal mandates (GDPR, CCPA etc.) into actionable technical and organizational controls. * Information Security: Contribute to Security Design Patterns and Technical Baselines for emerging technologies like Generative AI and Cloud-native ecosystems. * Risk Governance: Utilize ServiceNow IRM to ensure the integrity and traceability of security advisory, delivering data-driven, consistent, and audit-ready results. * Peer Excellence: Foster a "Four-Eye" quality culture through peer reviews and collective knowledge exchange within a global team of experts. Who You Are Our Ideal Mindset: A proactive Expert & Influencer who brings deep industry experience to an established team. You have the confidence to lead initiatives independently while thriving in an environment of collective knowledge exchange. ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Welcome to Switzerland](https://www.wearedevelopers.com/magazine/4-welcome-to-switzerland) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)