Information Security Governance Expert
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Experteer Overview As an Expert in Roche’s ISPA team, you act as a strategic partner for global Engineering hubs, leading high-impact security and privacy risk assessments to ensure digital initiatives are secure by design and compliant.You translate legal requirements into technical controls and contribute to secure design patterns for emerging tech like GenAI and cloud-native ecosystems.You play a key role in risk governance using data-driven, audit-ready approaches and foster knowledge sharing within a global expert community.This role offers meaningful impact across Roche’s digital landscape and global projects, tying security to the company’s mission of expanding healthcare access.Compensaciones / Beneficios * Lead Security Expert Reviews (SER) for complex architectures with deep technical and privacy evaluations to mitigate residual risk.* Bridge IT, Legal, and Data Protection Officers to translate mandates into actionable controls.* Contribute to Security Design Patterns and Technical Baselines for GenAI and Cloud-native ecosystems.* Use ServiceNow IRM to ensure integrity and audit-ready risk advisory outcomes.* Foster a Four-Eye quality culture through peer reviews and global knowledge exchange.Responsabilidades * 5-10 years in Information Security/GRC with proven experience in risk assessments and DPIAs in global environments.* Strong security architecture knowledge and ability to translate legal requirements into engineering terms.* Expertise in international privacy frameworks (GDPR, CCPA, HIPAA) and standards (ISO **, NIST). Experience with ServiceNow IRM to document and execute risk assessments.* Degree in Computer Science or Legal; professional certifications (CISSP, CISM, CRISC, CIPP/E, CIPM, ISO** Lead Auditor) valued. Exceptional stakeholder management and ability to drive consensus across a global organization.Requisitos principales *
Requirements
Responsabilidades * 5-10 years in Information Security/GRC with proven experience in risk assessments and DPIAs in global environments.
- Strong security architecture knowledge and ability to translate legal requirements into engineering terms.
- Expertise in international privacy frameworks (GDPR, CCPA, HIPAA) and standards (ISO *****, NIST).
- Experience with ServiceNow IRM to document and execute risk assessments.
- Degree in Computer Science or Legal; professional certifications (CISSP, CISM, CRISC, CIPP/E, CIPM, ISO***** Lead Auditor) valued.
- Exceptional stakeholder management and ability to drive consensus across a global organization.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best Companies to work for in London: Top 25 Companies in 2023
Welcome to Switzerland
Spanish Business Culture and Etiquette
Top-Paying Tech Jobs (with Salaries)