Information Security Governance Expert

Roche
Madrid, Spain
26 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Cloud Engineering Cyber Security Information Technology Data Analytics Servicenow

Job description

Experteer Overview As an Expert in Roche’s ISPA team, you act as a strategic partner for global Engineering hubs, leading high-impact security and privacy risk assessments to ensure digital initiatives are secure by design and compliant.You translate legal requirements into technical controls and contribute to secure design patterns for emerging tech like GenAI and cloud-native ecosystems.You play a key role in risk governance using data-driven, audit-ready approaches and foster knowledge sharing within a global expert community.This role offers meaningful impact across Roche’s digital landscape and global projects, tying security to the company’s mission of expanding healthcare access.Compensaciones / Beneficios * Lead Security Expert Reviews (SER) for complex architectures with deep technical and privacy evaluations to mitigate residual risk.* Bridge IT, Legal, and Data Protection Officers to translate mandates into actionable controls.* Contribute to Security Design Patterns and Technical Baselines for GenAI and Cloud-native ecosystems.* Use ServiceNow IRM to ensure integrity and audit-ready risk advisory outcomes.* Foster a Four-Eye quality culture through peer reviews and global knowledge exchange.Responsabilidades * 5-10 years in Information Security/GRC with proven experience in risk assessments and DPIAs in global environments.* Strong security architecture knowledge and ability to translate legal requirements into engineering terms.* Expertise in international privacy frameworks (GDPR, CCPA, HIPAA) and standards (ISO **, NIST). Experience with ServiceNow IRM to document and execute risk assessments.* Degree in Computer Science or Legal; professional certifications (CISSP, CISM, CRISC, CIPP/E, CIPM, ISO** Lead Auditor) valued. Exceptional stakeholder management and ability to drive consensus across a global organization.Requisitos principales *

Requirements

Responsabilidades * 5-10 years in Information Security/GRC with proven experience in risk assessments and DPIAs in global environments.

  • Strong security architecture knowledge and ability to translate legal requirements into engineering terms.
  • Expertise in international privacy frameworks (GDPR, CCPA, HIPAA) and standards (ISO *****, NIST).
  • Experience with ServiceNow IRM to document and execute risk assessments.
  • Degree in Computer Science or Legal; professional certifications (CISSP, CISM, CRISC, CIPP/E, CIPM, ISO***** Lead Auditor) valued.
  • Exceptional stakeholder management and ability to drive consensus across a global organization.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

1:32 min

Structuring platforms for new services and data analytics

Nevelina Aleksandrova · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

1:10 min

Introduction to Microsoft Fabric and data agents

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all