At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The Position
As an Information Security Governance Expert, you drive the integrity and resilience of Roche's Information Security Management System (ISMS). You are responsible for ensuring the organization maintains its yearly security certifications and remains compliant with evolving global regulations such as the US DOJ, NIS2 and RCE/CER, GMP Annex 11. You combine deep information security experience with sound regulatory knowledge and project management skills, to lead external audits & inspections and strategic security initiatives across the group. Your goal is to ensure that the security framework is not only compliant but also scalable and effective in protecting Roche's critical assets in a highly regulated environment. You have a proven track record of turning information security governance into a business enabler.
The Information Security & Privacy Governance team provides the framework for Roche to identify, assess, and mitigate information risks. The area is organized around three pillars:
Governance & ISMS: Maintaining Roche Global ISMS framework and certification (ISO/IEC 27001).
Regulatory Compliance: Ensuring adherence of Roche global ISMS to US DOJ/NIS2, RCE/CER, GMP Annex 11 and global healthcare/medical device regulations.
Audit & Assurance: Support Roche affiliates during external inspections, demonstrating their commitment to compliance.
Job Responsibilities
ISMS Strategy & Framework Management
Global ISMS Ownership
:
Own and maintain the Roche ISMS framework, ensuring full alignment with ISO/IEC 27001:2022 and integration with other quality management systems.
Continual Improvement:
Drive the ISMS "Plan-Do-Check-Act" (PDCA) cycle to ensure the framework evolves with the threat landscape and business needs, maintaining successful yearly certification continuity.
Policy Governance: Define and maintain enterprise-level security policies, standards, directives and procedures, ensuring they are fit-for-purpose, actionable and measurable.
Risk Monitoring:
Monitor the global risk landscape to identify adaptations required to the governance framework.
Regulatory & Compliance Orchestration
Regulatory Translation: Integrate complex global requirements (NIS2, HIPAA, US DOJ) into Roche Global ISMS.
Product & Services: Collaborate with product teams to ensure "Security by Design" integration into their culture, skillset, processes and projects.
Control Mapping:
Maintain a unified control framework that maps internal Roche controls to multiple external regulatory requirements to validate coverage of the Roche Global ISMS.
Consulting:
Act as a consultant to Roche affiliates, guiding them toward compliance with regional or functional security directives.
Audit & Inspection Support
External Audit & Inspection Support:
Support legal entities of the Roche Group & functions during external audits and regulatory inspections.
Risks Treatment Oversight:
Coordinate remediation plans for audit and inspection findings and track progress to closure.
Third-Party Governance:
Oversee the security governance framework for critical supply chain partners and Cloud Service Providers.
Stakeholder & Change Management
Strategic Advisory:
Serve as a bridge between senior leadership, legal, privacy and quality to communicate information security risks and maturity milestones.
Culture & Awareness:
Support the Information Security networks by providing high-level governance guidance and strategic direction.
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact. Let’s build a healthier future, together. Roche is an Equal Opportunity Employer.